hexdump

Display raw binary data in human-readable hexadecimal formats. When abstractions are gone, bytes remain.

Category: Development / Binary Analysis Bytes Binary Forensics Low-level

What it does

hexdump displays the raw contents of files or streams as hexadecimal values, often alongside ASCII representations. It’s used to inspect binary formats, file headers, protocol captures, and corrupted data.

How it works (mechanical)

hexdump reads bytes sequentially and formats them according to predefined or custom output templates. It does not interpret structure or meaning — it simply renders byte values.

  • Reads data as raw bytes
  • Formats output via templates
  • Supports endian-aware groupings
  • Works on files or standard input

10 Practical Examples

# 1) Basic hex + ASCII view
hexdump -C myfile.bin
# 2) View the first 64 bytes of a file
hexdump -C myfile.bin | head -n 4
# 3) Inspect an executable header
hexdump -C /bin/ls | head
# 4) Show bytes as 16-bit words
hexdump -x myfile.bin
# 5) Show bytes as 32-bit words
hexdump -X myfile.bin
# 6) Compare two files at byte level
diff <(hexdump -C file1) <(hexdump -C file2)
# 7) Inspect network capture payloads
tcpdump -r capture.pcap -w - | hexdump -C
# 8) Examine disk or partition metadata (dangerous if writing)
sudo hexdump -C /dev/sda | head
# 9) Debug binary file corruption
hexdump -C corrupted.bin | less
# 10) Pipe structured output into analysis tools
hexdump -v -e '1/1 "%02x "' myfile.bin

Notes & Gotchas

  • -C is the most commonly useful format.
  • Output is literal bytes — no structure implied.
  • Be careful reading from block devices.
  • For editing, pair with tools like xxd.
  • Endianness matters when interpreting multi-byte values.

Historical Context

Hex dump tools date back to early Unix debugging practices, allowing engineers to inspect memory and files directly when higher-level tools failed or didn’t exist.

Modern Equivalent / Related Tools

  • xxd — vim-associated hex viewer/editor
  • od — octal/hex dump utility
  • strings — printable content extraction
  • readelf — structural ELF inspection
  • binwalk — firmware and binary analysis