🔎 Forensic Examiner
The Swiss Army Knife for examining text files. Combining the most useful functionalities from (z)cat, (z)less, head, tail, grep, hexdump, sha256sum, sha1sum, md5sum, wc and jq into one performant standalone binary.

AS THIS IS A FORENSIC TOOL NO WRITE ACTIONS WILL BE PERFORMED
Install
$ make install
Usage
$ fx [-r] [-h | -t] [-n # | -c #] [-x | -e PATTERN] [-o FILE] [PATH ... | -]
Available options:
-r Raw output
-h Head limit
-t Tail limit
-n Lines count
-c Bytes count
-x Hexdump mode
-e Pattern value
-o Evidence file
Standard options:
--help Usage information
--version Version number
Examples
Reading all files in the current directory:
$ fx
Reading directly from stdin:
$ fx -
Reading gzip compressed files:
$ fx foo.gz bar.gz
Reading all .jsonl files in all subdirectories:
$ fx ./*/*.jsonl
Writing all lines containing John Doe of all files to stdout:
$ fx -r -e "John Doe"
Writing the first 3 lines of foo to bar:
$ fx -h -n 3 foo > bar
Writing the last 8 bytes of foo to bar in hex:
$ fx -t -c 8 -x foo > bar
Keyboard
General
| Shortcut |
Action |
| Esc |
Exit |
| F1 / Ctrl + l |
Less mode |
| F2 / Ctrl + g |
Grep mode |
| F3 / Ctrl + x |
Hex mode |
| F4 / Ctrl + Space |
Goto mode |
| F9 |
Show file(s) counts |
| F10 |
Show file(s) MD5 |
| F11 |
Show file(s) SHA1 |
| F12 |
Show file(s) SHA256 |
| Tab |
Load next file |
| Shift + Tab |
Load prev file |
| Shift + Up |
Scroll page up |
| Shift + Down |
Scroll page down |
| Shift + Left |
Scroll page left |
| Shift + Right |
Scroll page right |
| Ctrl + Shift + Up |
Scroll to start |
| Ctrl + Shift + Down |
Scroll to end |
| Ctrl + r |
Reload file |
| Ctrl + q |
Close file |
| Ctrl + t |
Cycle themes |
| Ctrl + f |
Toggle file follow |
| Ctrl + n |
Toggle line numbers |
| Ctrl + w |
Toggle wrap text |
| Ctrl + s |
Save as evidence |
| Ctrl + c |
Copy to clipboard |
Less Mode
| Shortcut |
Action |
| Space |
Scroll page down |
Grep Mode
| Shortcut |
Action |
| Enter |
Append filter |
| Backspace |
Delete filter |
| Alt + Up |
Prev input in history |
| Alt + Down |
Next input in history |
| Ctrl + v |
Paste as input |
| Any Key |
Filter content |
Config
Located under ~/.fxrc.
Theme = "Monokai"
Follow = true # Follow file
Line = true # Line numbers
Wrap = true # Wrap text
Environment
FX_THEME=Monokai
Themes
Monokai
Catppuccin-Latte
Catppuccin-Frappe
Catppuccin-Macchiato
Catppuccin-Mocha
Ansi
Matrix
Monochrome
Supported by codecentric opt time.