Regex Fundamentals
A foundational reference for regex syntax, with emphasis on practical application in digital forensics, log analysis, and tooling like Burp Suite.
1. Literal vs. Metacharacters
- Most characters match themselves:
malware,192.168 - Metacharacters have special meaning:
. \ ^ $ * + ? { } [ ] | ( )
2. Character Classes
| Pattern | Matches |
|---|---|
. |
Any single character (except newline) |
\d |
Any digit (0-9) |
\w |
Word char: [a-zA-Z0-9_] |
\s |
Whitespace (space, tab, newline) |
[a-f] |
Any character in range a-f |
[^0-9] |
Anything except a digit |
3. Anchors
Anchors match positions, not characters:
| Pattern | Matches |
|---|---|
^ |
Start of string/line |
$ |
End of string/line |
\b |
Word boundary (transition between \w and \W) |
Key insight: \b requires one side of the position to be a word character ([a-zA-Z0-9_]) and the other to be a non-word character (or start/end of string). It checks both sides, not just the prefix.
Examples:
- \b123 matches admin123 but not admin123
- 123\b matches 123! but not 123user
- \b123\b matches 123 but not admin123user
This prevents false positives when matching embedded strings in hex dumps, logs, or memory artifacts.
4. Quantifiers
| Pattern | Meaning |
|---|---|
* |
0 or more |
+ |
1 or more |
? |
0 or 1 (optional) |
{3} |
Exactly 3 |
{2,4} |
2 to 4 |
{3,} |
3 or more |
5. Groups and Alternation
( ... )— Capturing group (extracts the matched text)(?: ... )— Non-capturing group (logic without extraction)\|— Alternation (OR):jpg\|png\|gif
6. Escaping
Match literal metacharacters with backslash:
- \. — literal dot
- \\ — literal backslash
- \( — literal parenthesis
Practical Examples
MAC Address (Forensic Log Parsing)
\b([0-9A-Fa-f]{2}[:-]){5}[0-9A-Fa-f]{2}\b
- The
\banchors prevent matching embedded hex inside larger blobs likedeadbeef0011223344.
IPv4 (Crude)
\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}
- Better version with
\bto avoid matching inside longer numbers.
Related concepts: Core Principles of Forensic Science (Individuality, Exchange Principle), The 5 Principles of Digital Forensics, Burp Suite