
Ffind
- 36 installs
- 805 repo stars
- Updated June 1, 2026
- brownfinesecurity/iothackbot
ffind is a Claude skill that drives the ffind tool to detect file types and extract embedded ext2/3/4 or F2FS filesystems from firmware and IoT images.
About
This skill drives the ffind tool to analyze files with advanced type detection and extract embedded filesystems from firmware. A developer uses it to identify file types in a firmware image and extract ext2/3/4 or F2FS filesystems for deeper analysis. It is designed for firmware and IoT device reverse engineering.
- Detects file types and identifies security-relevant artifacts in firmware
- Extracts ext2/3/4 and F2FS filesystems from firmware images
- Built for firmware and IoT device analysis
Ffind by the numbers
- 36 all-time installs (skills.sh)
- Ranked #1,455 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Jul 31, 2026 (Skillselion catalog sync)
ffind capabilities & compatibility
- Capabilities
- file type detection · filesystem extraction · firmware analysis
- Use cases
- security audit
- Platforms
- Linux
- Pricing
- Free
What ffind says it does
Ffind analyzes files and directories, identifies file types, and can extract filesystems (ext2/3/4, F2FS) for deeper analysis. It's designed for firmware and IoT device analysis.
Supports ext2/ext3/ext4 filesystems (requires e2fsprogs)
Identifies "artifact" file types relevant to security analysis by default
npx skills add https://github.com/brownfinesecurity/iothackbot --skill ffindAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 36 |
|---|---|
| repo stars | ★ 805 |
| Last updated | June 1, 2026 |
| Repository | brownfinesecurity/iothackbot ↗ |
What it does
Identify file types in a firmware image and extract embedded ext or F2FS filesystems for security analysis.
Who is it for?
Analyzing firmware files, identifying file types, and extracting ext2/3/4 or F2FS filesystems.
When should I use this skill?
You need to analyze firmware files, identify file types, or extract ext2/3/4 or F2FS filesystems.
What you get
A file-type inventory and extracted ext/F2FS filesystem contents from a firmware image.
Files
Ffind - Advanced File Finder with Extraction
You are helping the user find and analyze files with advanced type detection and optional filesystem extraction capabilities using the ffind tool.
Tool Overview
Ffind analyzes files and directories, identifies file types, and can extract filesystems (ext2/3/4, F2FS) for deeper analysis. It's designed for firmware and IoT device analysis.
Instructions
When the user asks to analyze files, find specific file types, or extract filesystems:
1. Understand the target:
- Ask what path(s) they want to analyze
- Determine if they want to extract filesystems or just analyze
- Ask if they want all file types or just artifact types
2. Execute the analysis:
- Use the ffind command from the iothackbot bin directory
- Basic usage:
ffind <path> [<path2> ...] - To extract filesystems:
ffind <path> -e - Custom extraction directory:
ffind <path> -e -d /path/to/output - Show all file types:
ffind <path> -a - Verbose output:
ffind <path> -v
3. Output formats:
--format text(default): Human-readable colored output with type summaries--format json: Machine-readable JSON--format quiet: Minimal output
4. Extraction capabilities:
- Supports ext2/ext3/ext4 filesystems (requires e2fsprogs)
- Supports F2FS filesystems (requires f2fs-tools)
- Requires sudo privileges for extraction
- Default extraction location:
/tmp/ffind_<timestamp>
Examples
Analyze a firmware file to see file types:
ffind /path/to/firmware.binExtract all filesystems from a firmware image:
sudo ffind /path/to/firmware.bin -eAnalyze multiple files and show all types:
ffind /path/to/file1.bin /path/to/file2.bin -aExtract to a custom directory:
sudo ffind /path/to/firmware.bin -e -d /tmp/my-extractionImportant Notes
- Name collision: The Sleuth Kit also ships a
ffind(it finds file names for a given inode and takes a disk image plus an inode number). Ifwhich ffindpoints at/usr/bin/ffindor/usr/local/bin/ffind, the iothackbot flags below (-e,-d <dir>,-a,--format) will be misread by the wrong binary. Confirm withffind --help(the iothackbot tool shows--extract/--format); if it showsimage inodeusage, invoke the iothackbot tool by its full path in the repobin/directory instead. - Extraction requires root/sudo privileges
- Requires external tools: e2fsprogs, f2fs-tools, util-linux
- Identifies "artifact" file types relevant to security analysis by default
- Use
-aflag to see all file types including common formats
Related skills
FAQ
How is this different from Sleuth Kit's ffind?
The Sleuth Kit also ships a ffind that finds file names for a given inode; if which ffind points there, invoke the iothackbot tool by its full path in the repo bin directory instead.
Which filesystems can it extract?
It supports ext2/ext3/ext4 (requires e2fsprogs) and F2FS (requires f2fs-tools), and extraction requires sudo privileges.