Regex Fundamentals

A foundational reference for regex syntax, with emphasis on practical application in digital forensics, log analysis, and tooling like Burp Suite.

1. Literal vs. Metacharacters

  • Most characters match themselves: malware, 192.168
  • Metacharacters have special meaning: . \ ^ $ * + ? { } [ ] | ( )

2. Character Classes

Pattern Matches
. Any single character (except newline)
\d Any digit (0-9)
\w Word char: [a-zA-Z0-9_]
\s Whitespace (space, tab, newline)
[a-f] Any character in range a-f
[^0-9] Anything except a digit

3. Anchors

Anchors match positions, not characters:

Pattern Matches
^ Start of string/line
$ End of string/line
\b Word boundary (transition between \w and \W)

Key insight: \b requires one side of the position to be a word character ([a-zA-Z0-9_]) and the other to be a non-word character (or start/end of string). It checks both sides, not just the prefix.

Examples:
- \b123 matches admin123 but not admin123
- 123\b matches 123! but not 123user
- \b123\b matches 123 but not admin123user

This prevents false positives when matching embedded strings in hex dumps, logs, or memory artifacts.

4. Quantifiers

Pattern Meaning
* 0 or more
+ 1 or more
? 0 or 1 (optional)
{3} Exactly 3
{2,4} 2 to 4
{3,} 3 or more

5. Groups and Alternation

  • ( ... ) — Capturing group (extracts the matched text)
  • (?: ... ) — Non-capturing group (logic without extraction)
  • \| — Alternation (OR): jpg\|png\|gif

6. Escaping

Match literal metacharacters with backslash:
- \. — literal dot
- \\ — literal backslash
- \( — literal parenthesis

Practical Examples

MAC Address (Forensic Log Parsing)

\b([0-9A-Fa-f]{2}[:-]){5}[0-9A-Fa-f]{2}\b
  • The \b anchors prevent matching embedded hex inside larger blobs like deadbeef0011223344.

IPv4 (Crude)

\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}
  • Better version with \b to avoid matching inside longer numbers.

Related concepts: Core Principles of Forensic Science (Individuality, Exchange Principle), The 5 Principles of Digital Forensics, Burp Suite