# How to Search for Strings, Symbols, and Imports Within the dyld_shared_cache

> Easily search for strings, symbols, and imports within the dyld_shared_cache using the ipsw CLI. Discover how to parse cache headers and scan Mach-O load commands effectively.

- Repository: [blacktop/ipsw](https://github.com/blacktop/ipsw)
- Tags: how-to-guide
- Published: 2026-02-26

---

**The `ipsw` CLI provides dedicated subcommands to search for strings, symbols, and imports within a `dyld_shared_cache` by parsing the cache header, walking image sections, and scanning Mach-O load commands.**

The `blacktop/ipsw` repository offers a comprehensive toolkit for analyzing Apple’s `dyld_shared_cache` (DSC), the single file that contains most system libraries on macOS and iOS. Whether you are reverse‑engineering, debugging, or performing forensic analysis, you can efficiently search for strings, symbols, and imports using the Go‑based CLI and its underlying library functions.

## Understanding the dyld_shared_cache Structure

Before executing searches, `ipsw` parses the cache into an in‑memory representation. The core logic resides in [`pkg/dyld/file.go`](https://github.com/blacktop/ipsw/blob/main/pkg/dyld/file.go), where `dyld.Open(path)` performs the following steps:

1. Opens the cache file and validates the magic header and UUID.
2. Reads mapping tables and image metadata.
3. For dyld‑4 caches, walks sub‑caches to build a unified view.

The returned `*dyld.File` structure contains:
- `Images` – a slice of `*CacheImage` representing each Mach‑O binary in the cache.
- `AddressToSymbol` – a map of virtual addresses to symbol names, populated on demand.
- `IsDyld4` – a boolean flag indicating whether the cache uses the newer dyld‑4 format.

## Searching for Strings in the DSC

The `ipsw dsc str` command provides two modes for searching strings: fast byte‑wise matching and slower regex filtering. Both methods are implemented in [`internal/commands/dsc/dsc.go`](https://github.com/blacktop/ipsw/blob/main/internal/commands/dsc/dsc.go) and exposed via [`cmd/ipsw/cmd/dyld/dyld_str.go`](https://github.com/blacktop/ipsw/blob/main/cmd/ipsw/cmd/dyld/dyld_str.go).

### Fast Byte-Wise String Search

For literal string matches, use positional arguments. This method scans the `__TEXT,__cstring` section (or any section with the `S_STRING` flag) of every image and performs a `bytes.Contains` check.

```bash
ipsw dsc str /path/to/dyld_shared_cache AppleMobileFileRelay

```

Internally, `StrSearchCmd` calls `dscCmd.GetStrings(f, searchStrings...)`, which returns a slice of `String` structs containing the virtual address, the string content, and the originating image name.

### Regex Pattern Matching

When you need pattern matching, use the `--pattern` flag. This executes the same section walk but applies `regexp.MatchString` to filter results.

```bash
ipsw dsc str /path/to/dyld_shared_cache --pattern '^com\.apple\..*Service$'

```

Because regex evaluation is slower than byte comparison, this mode is recommended for targeted searches rather than broad scans.

## Looking Up Symbols

Symbol resolution is handled by the `ipsw dsc symaddr` command, implemented in [`cmd/ipsw/cmd/dyld/dyld_symaddr.go`](https://github.com/blacktop/ipsw/blob/main/cmd/ipsw/cmd/dyld/dyld_symaddr.go). The tool can resolve symbols from the local symbol table, the export trie (in dyld‑4 caches), or a provided JSON list.

### Single Symbol Lookup

To find the address of a specific symbol within a particular library, use the `-i` flag to restrict the search to a single image:

```bash
ipsw dsc symaddr /path/to/dyld_shared_cache -i libsystem_malloc.dylib _malloc

```

The command calls `f.Image("libsystem_malloc.dylib")` to retrieve the `*CacheImage`, then invokes `image.GetSymbol("_malloc")`. This method reads the image’s symbol table or export trie and returns a `Symbol` struct containing the virtual address and binding type.

### Bulk Symbol Resolution from JSON

For batch processing, provide a JSON file containing an array of symbol objects:

```json
[
  {"symbol": "_malloc"},
  {"symbol": "_free"},
  {"symbol": "_objc_msgSend"}
]

```

```bash
ipsw dsc symaddr /path/to/dyld_shared_cache --in symbols.json --output results.json

```

`SymAddrCmd` reads the input JSON, calls `dscCmd.GetSymbols(f, symbols...)`, and writes the resolved addresses to the output file. This helper iterates through the provided names, checking `f.GetExportedSymbols` for global exports or falling back to per‑image `GetSymbol` calls for local symbols.

## Finding Imports and Dependencies

To determine which libraries depend on a specific dylib, use the `ipsw dsc imports` command. This is implemented in [`cmd/ipsw/cmd/dyld/dyld_imports.go`](https://github.com/blacktop/ipsw/blob/main/cmd/ipsw/cmd/dyld/dyld_imports.go) and relies on `dscCmd.GetDylibsThatImport` in [`internal/commands/dsc/dsc.go`](https://github.com/blacktop/ipsw/blob/main/internal/commands/dsc/dsc.go).

### Identifying Dylibs That Import a Specific Library

```bash
ipsw dsc imports /path/to/dyld_shared_cache libobjc.A.dylib

```

The command performs the following steps:
1. Opens the DSC and resolves the target image via `f.Image("libobjc.A.dylib")`.
2. Calls `dscCmd.GetDylibsThatImport(f, image.Name)`, which iterates over every `*CacheImage`.
3. For each image, it loads the underlying `macho.File` and calls `ImportedLibraries()` to retrieve the list of linked libraries.
4. Results are categorized into two buckets:
   - **DSC**: Other images within the shared cache that import the target.
   - **Apps**: Binaries located in the embedded filesystem DMG (when using the `--ipsw` flag to analyze a full IPSW archive).

The CLI prints a formatted list showing which components depend on the specified library, useful for understanding dependency chains and attack surfaces.

## Core Implementation Details

The search functionality is built on a layered architecture that separates CLI concerns from core logic:

| Component | File Path | Key Functions |
|-----------|-----------|---------------|
| **DSC Parser** | [`pkg/dyld/file.go`](https://github.com/blacktop/ipsw/blob/main/pkg/dyld/file.go) | `dyld.Open()`, `File`, `CacheImage`, `AddressToSymbol` |
| **Search Helpers** | [`internal/commands/dsc/dsc.go`](https://github.com/blacktop/ipsw/blob/main/internal/commands/dsc/dsc.go) | `GetStrings()`, `GetStringsRegex()`, `GetDylibsThatImport()`, `GetSymbols()` |
| **String CLI** | [`cmd/ipsw/cmd/dyld/dyld_str.go`](https://github.com/blacktop/ipsw/blob/main/cmd/ipsw/cmd/dyld/dyld_str.go) | `StrSearchCmd` |
| **Symbol CLI** | [`cmd/ipsw/cmd/dyld/dyld_symaddr.go`](https://github.com/blacktop/ipsw/blob/main/cmd/ipsw/cmd/dyld/dyld_symaddr.go) | `SymAddrCmd` |
| **Import CLI** | [`cmd/ipsw/cmd/dyld/dyld_imports.go`](https://github.com/blacktop/ipsw/blob/main/cmd/ipsw/cmd/dyld/dyld_imports.go) | `dyldImportsCmd` |

All helpers receive a pre‑parsed `*dyld.File`, ensuring that virtual address translation and image metadata are readily available without redundant I/O.

## Summary

- **Open the cache** with `dyld.Open()` to obtain a parsed `*dyld.File` containing images and mappings.
- **Search strings** using `ipsw dsc str` for fast literal matches or `ipsw dsc str --pattern` for regex filtering against `__cstring` sections.
- **Resolve symbols** via `ipsw dsc symaddr` for single lookups or bulk JSON processing, leveraging local symbol tables and dyld‑4 export tries.
- **Trace imports** with `ipsw dsc imports` to discover which cache images or embedded apps link against a specific dylib.
- **Reference implementation** files include [`pkg/dyld/file.go`](https://github.com/blacktop/ipsw/blob/main/pkg/dyld/file.go) for parsing and [`internal/commands/dsc/dsc.go`](https://github.com/blacktop/ipsw/blob/main/internal/commands/dsc/dsc.go) for search logic.

## Frequently Asked Questions

### What is the difference between byte-wise and regex string searching in ipsw?

**Byte-wise searching** uses `bytes.Contains` to scan `__TEXT,__cstring` sections for exact literal matches, making it significantly faster for straightforward lookups. **Regex searching** applies `regexp.MatchString` after extracting candidate strings, offering pattern matching capabilities at the cost of performance. Use byte-wise for speed and regex for complex patterns like `^com\.apple\..*Service$`.

### How does ipsw resolve symbols in dyld4 caches compared to older formats?

In **dyld4 caches**, `ipsw` walks the **export trie** structure via `image.GetSymbol()`, which provides a compact, sorted list of exported symbols. For **older caches**, the tool falls back to the **local symbol table** (LC_SYMTAB) stored within each image. The `IsDyld4` flag on the `File` struct determines which resolution path is taken, ensuring compatibility across iOS/macOS versions.

### Can I export the search results to JSON for further processing?

Yes, the `symaddr` command supports JSON output via the `--output` flag when performing bulk lookups. You provide an input JSON file containing symbol names with `--in`, and `ipsw` writes a JSON array of resolved addresses including virtual addresses, image names, and symbol types. This facilitates integration with automated analysis pipelines or custom forensic tools.

### Why does the imports command show both DSC and Apps categories?

The `imports` command categorizes results into **DSC** (images within the shared cache itself) and **Apps** (binaries located in the embedded filesystem DMG). When you analyze a full IPSW archive using the `--ipsw` flag, `ipsw` mounts the filesystem and scans application binaries that link against the cache, revealing dependencies outside the DSC. This dual view helps security researchers understand both system library interdependencies and third-party app linkage.