โ† All cheat sheets

STRACE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

strace traces system calls and signals.
Essential for debugging and understanding program behavior.

BASIC USAGE#

strace command                    # Trace command
strace -p PID                     # Attach to running process
strace -f command                 # Follow forks (child processes)
strace -o file.txt command        # Output to file

OUTPUT OPTIONS#

strace -o output.txt command      # Save to file
strace -o output.txt -ff command  # Separate file per process
strace -t command                 # Print timestamp
strace -tt command                # Microsecond timestamp
strace -T command                 # Show syscall duration
strace -r command                 # Relative timestamp
strace -c command                 # Statistics summary
strace -C command                 # Stats + regular output

FILTERING SYSTEM CALLS#

strace -e trace=open command      # Only 'open' syscalls
strace -e open command            # Shorthand
strace -e trace=read,write cmd    # Multiple syscalls
strace -e trace=file command      # File operations
strace -e trace=network cmd       # Network operations
strace -e trace=process cmd       # Process operations
strace -e trace=memory cmd        # Memory operations
strace -e trace=signal cmd        # Signal operations
strace -e trace=ipc cmd           # IPC operations
strace -e trace=desc cmd          # File descriptor operations

# Exclude syscalls
strace -e trace=\!open command    # All except 'open'

TRACE CATEGORIES#

file        open, stat, chmod, chown, etc.
process     fork, exec, wait, etc.
network     socket, connect, send, recv, etc.
signal      signal, sigaction, kill, etc.
ipc         msg*, sem*, shm*
desc        read, write, close, dup, etc.
memory      mmap, mprotect, brk, etc.
%file       Same as file
%process    Same as process
%network    Same as network

STRING AND SIZE OPTIONS#

strace -s 100 command             # String size (default: 32)
strace -s 1000 command            # Larger strings
strace -x command                 # Hex output for non-ASCII
strace -xx command                # Hex for all strings

FOLLOW OPTIONS#

strace -f command                 # Follow forks
strace -ff -o out command         # Separate file per PID
strace -F command                 # Follow vfork

ATTACHING TO PROCESSES#

strace -p 1234                    # Attach to PID
strace -p 1234 -p 5678            # Multiple PIDs
strace -p $(pgrep nginx)          # By process name
# Ctrl+C to detach

COMMON EXAMPLES#

# Debug program startup
strace ./program

# Find config files being read
strace -e open,openat ./program 2>&1 | grep -E '\.conf|\.cfg|\.ini'

# Find files program accesses
strace -e trace=file ./program 2>&1

# Network activity
strace -e trace=network ./program

# Why program is slow
strace -T ./program 2>&1 | sort -t= -k2 -n

# Count syscalls
strace -c ./program

# Debug library loading
strace -e trace=open ./program 2>&1 | grep '\.so'

# Find why program fails
strace -e trace=file ./failing_program

# Watch file access in real-time
strace -e trace=file -p $(pgrep apache2)

# Debug DNS issues
strace -e trace=network -s 1000 host example.com

SECURITY/FORENSICS#

# What files a process opens
strace -e open,openat -p PID

# Network connections
strace -e connect,socket -p PID

# What a script writes
strace -e write -s 1000 ./script.sh

# Check for suspicious behavior
strace -f -e trace=execve,connect,open ./suspicious

OUTPUT INTERPRETATION#

# Successful call
open("/etc/passwd", O_RDONLY) = 3

# Failed call
open("/nonexistent", O_RDONLY) = -1 ENOENT (No such file or directory)

# Common return values:
# = N      Success, N is return value (often file descriptor)
# = -1     Failure (check error code)
# = 0      Success or EOF

# Common errors:
# ENOENT   No such file or directory
# EACCES   Permission denied
# EEXIST   File exists
# EPERM    Operation not permitted
# EAGAIN   Resource temporarily unavailable
# EINTR    Interrupted system call

PERFORMANCE ANALYSIS#

# Time spent in syscalls
strace -c ./program
# Shows: % time, seconds, calls, errors, syscall

# Find slow syscalls
strace -T ./program 2>&1 | awk -F'[<>]' '{print $2, $0}' | sort -n

# Identify blocking calls
strace -T -e read,write,poll,select ./program

DEBUGGING SPECIFIC ISSUES#

# Why can't find library
strace -e open ./program 2>&1 | grep '\.so'

# Why permission denied
strace -e open,stat,access ./program 2>&1 | grep -i denied

# Why hanging
strace -p PID
# Look for blocking calls: read, poll, select, futex

# Why high CPU
strace -c -p PID
# Run for a while, Ctrl+C to see summary

# Debug shell script
strace -f -e execve /bin/bash script.sh

ALTERNATIVES#

ltrace          # Library call tracer
dtrace          # Dynamic tracing (Solaris, macOS)
perf trace      # Linux perf based tracing
bpftrace        # eBPF based tracing

USEFUL PATTERNS#

# All file opens
strace -e openat 2>&1 | grep -v ENOENT

# Writes to specific file
strace -e write -p PID 2>&1 | grep 'write(3,'  # fd 3

# Follow entire process tree
strace -ff -o /tmp/trace ./program
# Creates /tmp/trace.PID for each process

# Time analysis
strace -ttt -T -o trace.log ./program
# Then analyze with awk/grep

QUICK REFERENCE#

strace command              Basic trace
strace -p PID               Attach to process
strace -f command           Follow forks
strace -o file command      Output to file
strace -c command           Statistics only
strace -e open command      Filter syscalls
strace -e trace=file cmd    Category filter
strace -T command           Show time per call
strace -t command           Timestamps
strace -s 200 command       Longer strings