CLI tool
mandiant/stringsifter avatar
mandiant/stringsifter

StringSifter: Machine Learning String Ranking for Malware Analysis

A machine learning tool that ranks strings based on their relevance for malware analysis.

764 stars125 forksPythonApache-2.0

At a glance

What is it?
StringSifter is an Apache-licensed Python tool from Mandiant that automatically ranks strings extracted from malware binaries by their relevance to analysis. It uses a LightGBM gradient-boosted model trained on real malware samples to cut the time analysts spend triaging irrelevant output from the strings command.
Who is it for?
StringSifter suits malware analysts who work with raw binaries and spend significant time filtering through irrelevant string output. It is the wrong tool if you need training code or labeled data, since neither is currently published.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 68 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The Triage Problem StringSifter Addresses

Running GNU strings on a malware binary produces hundreds or thousands of extracted strings: file paths, registry keys, error messages, command-and-control domains, and large amounts of noise from compiler artifacts and padding. A human analyst scanning that output manually looks for the meaningful subset, which takes time and introduces the risk of missing something in a long list.

StringSifter sits in the analysis pipeline as a filter. It reads the output of strings (or its own included `flarestrings` command) and returns the same strings sorted by a machine-learned relevance score. Strings that tend to appear in malicious contexts come first. The analyst sees the most likely indicators at the top without modifying the underlying binary or committing to a specific hypothesis upfront.

The tool was developed by Mandiant Data Science Research and Applied Research, and a technical blog post and DerbyCon talk are linked from the README for background on how it was built and what results Mandiant observed in practice.

How the Ranking Model Works: LightGBM and Weak Supervision

StringSifter uses Gradient Boosted Decision Trees through the LightGBM library with a learning-to-rank objective. The README explains that the model was trained on strings output from malware binaries in the first EMBER dataset, which was published by Endgame. Ordinal labels were generated using weak supervision procedures rather than manual annotation, which made it practical to label at scale without per-string human review.

FastText word embeddings are listed as a dependency (`fasttext-wheel ~= 0.9.2`), indicating that string representations involve character-level or subword features in addition to the gradient-boosted ranking step. The model file is included in the installed package; running `pip install stringsifter` gives you a ready-to-use model without training anything yourself.

The README notes explicitly that neither labeled data nor training code is currently published, though it acknowledges the team may reconsider this. The model is a black box from the user's perspective: you can run it, but you cannot retrain it on your own dataset without reimplementing the training pipeline from scratch.

Installing StringSifter and Running an Analysis

Installation requires Python 3.9 or newer:

sh
pip install stringsifter

This installs two commands: `flarestrings`, which mimics GNU binutils strings, and `rank_strings`, which accepts piped input. A basic analysis pipes the two together:

sh
flarestrings <my_sample> | rank_strings

To filter out short strings before ranking (8 characters or longer in this example):

sh
flarestrings -n 8 <my_sample> | rank_strings

The `rank_strings` command outputs ranked strings to standard output. Useful options include `--scores` to include the numeric relevance score alongside each string, `--limit` to cap output at the top N results, and `--min-score` to filter out strings below a threshold score.

For development installation from source, the project uses Poetry:

sh
git clone https://github.com/mandiant/stringsifter.git
cd stringsifter
poetry install --with dev

The project version string is `3.20230711`, indicating the current release was cut in July 2023. The packaging moved to a pyproject.toml/poetry setup, with a requirements.txt also included for environments that use pip directly.

Batch Processing, Score Filtering, and Integration with FLOSS

For workflows analyzing more than one sample, `rank_strings` supports batch mode through the `--batch (-b)` option, which takes a folder of strings output files as input. In batch mode, ranked results are written to files named `<input_file>.ranked_strings` rather than to standard output, so each sample gets its own ranked output file. This is the pattern for integrating StringSifter into a pipeline that processes a malware corpus.

StringSifter can also consume output from FLOSS, the FireEye Labs Obfuscated Strings Solver, which extracts obfuscated strings that standard strings misses. FLOSS reveals strings that were encoded, packed, or built on the stack at runtime. Piping FLOSS output through rank_strings applies the same ranking to the richer string set. The README notes that FLOSS requires Python 2 while StringSifter requires Python 3, so when using both together the caller must use a Python 2 virtual environment for FLOSS and a Python 3 environment for StringSifter.

The `--min-len` option in `flarestrings` helps reduce noise before ranking. The default minimum length is 4 characters, which captures the same range as GNU strings. Raising the floor cuts low-information fragments before they consume ranking capacity.

Running StringSifter in Docker

For analysts who prefer not to install Python dependencies directly, a Dockerfile is included. Build the image from the repository root:

sh
docker build -t stringsifter -f docker/Dockerfile .

The containerized commands can be used in pipelines:

sh
cat <my_sample> | docker run -i stringsifter flarestrings | docker run -i stringsifter rank_strings

To run an interactive session with access to a sample directory, mount the local directory and start a shell:

sh
docker run -v <my_malware>:/samples -it stringsifter

Inside the container, the workflow is the same as on a local install. The Docker path is useful for running StringSifter on a system where Python version management would be problematic, or for including it in an automated analysis container alongside other tools.

StringSifter Versus PEStudio and Its Scope Boundary

PEStudio is a Windows GUI application for static analysis of PE files. It shows extracted strings alongside imports, exports, indicators, entropy values, and certificate data in a single interface. PEStudio does not rank strings by malware relevance: it presents them sorted by type (ASCII, Unicode, length) and highlights those that match a known indicators database, but the sorting is not ML-driven.

StringSifter does one thing: rank strings by predicted malware relevance. It has no GUI, no file format parsing, no import analysis, and no static features beyond the strings themselves. The two tools serve different moments in analysis. PEStudio is a broad static overview. StringSifter is a focused filter applied after strings are extracted.

A meaningful limitation of StringSifter is the fixed training distribution. The model was trained on malware binaries from the EMBER dataset, which is weighted toward Windows PE samples. Analysts working with Linux ELF malware, mobile binaries, or script-based threats may find the relevance model less accurate for those sample types, since the learned patterns reflect Windows PE malware characteristics.

Editorial conclusion

StringSifter suits malware analysts who work with raw binaries and spend significant time filtering through irrelevant string output. It is the wrong tool if you need training code or labeled data, since neither is currently published. Before using it in a real workflow, verify that the pre-trained model's focus on Windows PE malware from the EMBER dataset matches the types of samples you analyze. The Apache-2.0 license permits use in commercial security tooling. The last push to the repository was on 2026-07-24.

Frequently asked questions

How does StringSifter rank strings, and what model does it use?

StringSifter uses a Gradient Boosted Decision Trees model via LightGBM with a learning-to-rank objective. The model was trained on strings from malware binaries in the EMBER dataset using weak supervision to generate ordinal labels. The trained model is included in the pip package.

Can StringSifter process a folder of malware samples in batch mode?

Yes. Use the `--batch` flag with a folder path: `rank_strings --batch <folder>`. In batch mode, ranked output for each sample is written to a separate file named `<input_file>.ranked_strings` rather than to standard output.

Is the training code or labeled dataset for StringSifter available?

No. The README states that neither labeled data nor training code is currently available, though the team notes it may reconsider this in future releases. The pre-trained model is bundled in the package and is the only model available.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. mandiant/stringsifter on GitHub
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/mandiant-stringsifter.svg)](https://hysenlabs.com/projects/mandiant-stringsifter)