Tools / Regex Tester
Regex Tester
Write a regular expression, paste a test string, and see every match highlighted in real time. Toggle flags, use named capture groups, and pick from common CTF patterns like the picoCTF flag format or hex strings.
Quick patterns
Enter a pattern and test string to see matches highlighted.
Regular expressions in CTF challenges
Regex appears in CTFs in two contexts: challenges that ask you to supply a matching string (like MatchTheRegex), and challenges where you use regex yourself to extract flag patterns from large blobs of output.
When a challenge asks for a string that satisfies a regex, inspect the page source or server response to find the hidden pattern, then construct a matching input. Common requirements include a minimum length, specific character classes, or anchors that force the string to start or end a certain way.
When you need to extract a flag from output (e.g., strings from a binary), picoCTF\{[^}]+\} captures any flag-format string. The quick-pattern buttons above include this and other useful patterns.
Challenges solved with this tool: picoCTF 2023 - MatchTheRegex.
Understanding regex flag behavior is important when constructing or escaping patterns. The global (g) flag makes the engine find all matches rather than stopping at the first. The case-insensitive (i) flag lets you match without worrying about letter case. The dotall (s) flag makes . match newline characters, which is essential when a flag spans multiple lines in a multi-line output dump.
Named capture groups ((?<name>...)) are helpful for extracting structured data from challenge output. For instance, (?<flag>picoCTF{[^}]+}) lets you reference the captured flag as groups.flag in code, making scripted extraction clean and readable.
When regex is used as a filter in a web challenge (e.g., to block SQL injection keywords), look for gaps in the pattern. Common bypasses include using different character cases when the i flag is absent, inserting comments (/**/ in SQL), or splitting the blocked keyword across an encoding boundary. Test your bypass string against the server's actual regex here to confirm it slips through before submitting.
Challenges where it helps
- ABSOLUTE NANOpicoCTF 2026 · General Skills · Medium
- KSECRETSpicoCTF 2026 · General Skills · Medium
- Password ProfilerpicoCTF 2026 · General Skills · Easy
- Piece by PiecepicoCTF 2026 · General Skills · Easy
- SUDO MAKE ME A SANDWICHpicoCTF 2026 · General Skills · Easy
- UndopicoCTF 2026 · General Skills · Easy
- Event-ViewingpicoCTF 2025 · Forensics · Medium
- head-dumppicoCTF 2025 · Web Exploitation · Easy
- secure-email-servicepicoCTF 2025 · Web Exploitation · Hard
- YaraRules0x100picoCTF 2025 · General Skills · Medium
- BookmarkletpicoCTF 2024 · Web Exploitation · Easy
- elementspicoCTF 2024 · Web Exploitation · Hard
Browse the full challenge library for 45 more.
Guides that use this tool
- Race Conditions and TOCTOU for CTF: Winning the Window Between Check and UseHow to find, widen and win race conditions in CTF: symlink TOCTOU on SUID binaries, limit-overrun bugs in web apps, signal races, and mempool front-running.
- sqlmap for CTF: Every Flag That Matters, and What to Do When It Finds NothingA practical sqlmap workflow for CTF: request files, level and risk, technique selection, tamper scripts, second-order injection, and the failure checklist.
- WebAssembly Reversing for CTF: Reading WAT and Recovering Flags from .wasmFind the .wasm a page loads, disassemble it to WAT with wabt, read the stack machine, pull constants out of the data section, and debug it live in DevTools.
- Windows Forensics for CTF: Event Logs, Registry Hives, BitLocker, and SMBWork Windows artifacts from Linux: parse .evtx event logs, read registry hives offline, crack and mount BitLocker volumes, enumerate SMB shares, write YARA rules.
- Setting Up a CTF Environment: WSL, Linux, Docker, and the Core ToolkitBuild a CTF machine that works: choosing WSL2, a VM, or native Linux, the toolkit worth installing per category, Python setup, and safe binary handling.
- The picoCTF General Skills Roadmap: The Category Everything Else Rests OnGeneral Skills roadmap for picoCTF: a tiered path through the shell, file inspection, encodings, scripting, remote services, git, and permissions.
Tools that pair with this one
- Strings ExtractorPull printable text from any binary, library, or image. ASCII and UTF-16 detection, configurable minimum length, flag-like highlight, no command line needed.
- URL Encoder / DecoderEncode and decode URL-encoded (percent-encoded) strings. Useful for web exploitation challenges involving query parameters, form data, and HTTP headers.
- SQL Injection Payload GeneratorGenerate SQL injection payloads for auth bypass, UNION extraction, blind SQLi, NoSQL operator injection, and sqlmap commands. Supports MySQL, PostgreSQL, SQLite, and MSSQL.
- Timestamp ConverterConvert Unix timestamps (seconds or milliseconds), hex timestamps, and date strings to every common format.
Or browse all 40 CTF tools.