Analyzes firmware and extracts embedded filesystems for security analysis.
Install
mkdir -p .claude/skills/ffind && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4279" && unzip -o skill.zip -d .claude/skills/ffind && rm skill.zipInstalls to .claude/skills/ffind
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems. Use when you need to analyze firmware files, identify file types, or extract ext2/3/4 or F2FS filesystems.Key capabilities
- →Analyze files and directories
- →Identify file types within images
- →Extract ext2/3/4 filesystems
- →Extract F2FS filesystems
- →Output analysis in text or JSON format
- →Analyze firmware and IoT device images
How it works
The tool analyzes specified file paths, identifies file types, and can extract embedded ext2/3/4 or F2FS filesystems, providing output in human-readable or machine-readable formats.
Inputs & outputs
When to use ffind
- →Analyze firmware for hidden artifacts
- →Extract ext4 filesystem from a binary
- →Identify file types in an IoT image
- →Security analysis of device firmware
About this skill
Ffind - Advanced File Finder with Extraction
You are helping the user find and analyze files with advanced type detection and optional filesystem extraction capabilities using the ffind tool.
Tool Overview
Ffind analyzes files and directories, identifies file types, and can extract filesystems (ext2/3/4, F2FS) for deeper analysis. It's designed for firmware and IoT device analysis.
Instructions
When the user asks to analyze files, find specific file types, or extract filesystems:
-
Understand the target:
- Ask what path(s) they want to analyze
- Determine if they want to extract filesystems or just analyze
- Ask if they want all file types or just artifact types
-
Execute the analysis:
- Use the ffind command from the iothackbot bin directory
- Basic usage:
ffind <path> [<path2> ...] - To extract filesystems:
ffind <path> -e - Custom extraction directory:
ffind <path> -e -d /path/to/output - Show all file types:
ffind <path> -a - Verbose output:
ffind <path> -v
-
Output formats:
--format text(default): Human-readable colored output with type summaries--format json: Machine-readable JSON--format quiet: Minimal output
-
Extraction capabilities:
- Supports ext2/ext3/ext4 filesystems (requires e2fsprogs)
- Supports F2FS filesystems (requires f2fs-tools)
- Requires sudo privileges for extraction
- Default extraction location:
/tmp/ffind_<timestamp>
Examples
Analyze a firmware file to see file types:
ffind /path/to/firmware.bin
Extract all filesystems from a firmware image:
sudo ffind /path/to/firmware.bin -e
Analyze multiple files and show all types:
ffind /path/to/file1.bin /path/to/file2.bin -a
Extract to a custom directory:
sudo ffind /path/to/firmware.bin -e -d /tmp/my-extraction
Important Notes
- Name collision: The Sleuth Kit also ships a
ffind(it finds file names for a given inode and takes a disk image plus an inode number). Ifwhich ffindpoints at/usr/bin/ffindor/usr/local/bin/ffind, the iothackbot flags below (-e,-d <dir>,-a,--format) will be misread by the wrong binary. Confirm withffind --help(the iothackbot tool shows--extract/--format); if it showsimage inodeusage, invoke the iothackbot tool by its full path in the repobin/directory instead. - Extraction requires root/sudo privileges
- Requires external tools: e2fsprogs, f2fs-tools, util-linux
- Identifies "artifact" file types relevant to security analysis by default
- Use
-aflag to see all file types including common formats
When not to use it
- →When the Sleuth Kit's ffind is intended
- →When external tools like e2fsprogs or f2fs-tools are not available
Prerequisites
Limitations
- →Extraction requires root/sudo privileges
- →Requires external tools like e2fsprogs and f2fs-tools
- →Name collision with The Sleuth Kit's ffind tool
How it compares
This tool offers specialized file type detection and filesystem extraction capabilities for firmware and IoT analysis, unlike generic file finders.
Compared to similar skills
ffind side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| ffind (this skill) | 1 | 2mo | Review | Advanced |
| reverse-engineering-tools | 73 | 4mo | No flags | Advanced |
| ghidra | 16 | 7mo | Review | Advanced |
| firmware-analyst | 9 | 4mo | Review | Advanced |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by BrownFineSecurity
View all by BrownFineSecurity →You might also like
reverse-engineering-tools
gmh5225
Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.
ghidra
mitsuhiko
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.
firmware-analyst
sickn33
Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers. Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research.
memory-forensics
wshobson
Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.
binary-analysis-patterns
wshobson
Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.
security-scanning-tools
davila7
This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies.