file
Overview
file classifies files by inspecting content magic (and optionally the filesystem type), not just the name extension. Use it on unknown downloads, mystery binaries, compressed blobs, and scripts without a reliable extension.
It reads magic patterns from a database (e.g. /usr/share/misc/magic). Classification is heuristic — good for ops triage, not a security sandbox.
Syntax
file [options] file...
file - # read stdinCommon Options
| Option | Description |
|---|---|
-b, --brief |
Don’t prefix filename |
-i, --mime |
MIME type output |
-I |
MIME with encoding (some versions) |
-z |
Look inside compressed files |
-L |
Follow symlinks |
-s |
Allow special/block files |
-k |
Keep going; don’t stop at first match |
-f listfile |
Read filenames from listfile |
-e test |
Exclude a test (e.g. soft, tokens) |
-h |
Don’t follow symlinks (default often) |
Examples with Explanations
Basic classification
file /bin/ls
file /etc/hosts
file mystery.bin
file photo.jpg note.txt archive.tar.gzBrief and MIME
file -b mystery.bin
file -i photo.jpg
# photo.jpg: image/jpeg; charset=binary
file -bi photo.jpgInside compressed data
file -z backup.tar.gz
file -z something.xzSymlinks
file /usr/bin/python3
file -L /usr/bin/python3Scripts and interpreters
file bootstrap.sh
# may report: Bourne-Again shell script, ASCII text executable
head -1 bootstrap.sh # shebang checkStdin
head -c 256 blob | file -
curl -fsSL https://example.com/file | file -Batch unknown directory
file *
find . -type f -print0 | xargs -0 file | grep -i 'executable\|ELF'Guard uploads / pipelines
mime=$(file -bi "$upload" | cut -d';' -f1)
case $mime in
image/jpeg|image/png) echo ok ;;
*) echo "rejected: $mime" >&2; exit 1 ;;
esacELF deep dive (after file)
file /usr/local/bin/app
readelf -h /usr/local/bin/app
ldd /usr/local/bin/appNotes / Pitfalls
- Extensions lie;
filecan too — polyglots and crafted headers fool magic. - Text encodings may be guessed; don’t treat as authoritative Unicode detection.
- Very large files:
fileonly needs the beginning — still be careful with special devices. - Without
-s, behavior on device nodes is limited. - Magic DB age depends on package
libmagic/fileupdates.
2026-relevant notes
- Container distroless images may omit
file; copy samples to a debug image. - For security scanning, use dedicated malware/YARA tooling beyond
file. - MIME output pairs well with web and S3 content-type checks in shell tooling.
Additional Resources
man file- libmagic / file(1) docs