How to Search for Strings, Symbols, and Imports Within the dyld_shared_cache

The ipsw CLI provides dedicated subcommands to search for strings, symbols, and imports within a dyld_shared_cache by parsing the cache header, walking image sections, and scanning Mach-O load commands.

The blacktop/ipsw repository offers a comprehensive toolkit for analyzing Apple’s dyld_shared_cache (DSC), the single file that contains most system libraries on macOS and iOS. Whether you are reverse‑engineering, debugging, or performing forensic analysis, you can efficiently search for strings, symbols, and imports using the Go‑based CLI and its underlying library functions.

Understanding the dyld_shared_cache Structure

Before executing searches, ipsw parses the cache into an in‑memory representation. The core logic resides in pkg/dyld/file.go, where dyld.Open(path) performs the following steps:

  1. Opens the cache file and validates the magic header and UUID.
  2. Reads mapping tables and image metadata.
  3. For dyld‑4 caches, walks sub‑caches to build a unified view.

The returned *dyld.File structure contains:

  • Images – a slice of *CacheImage representing each Mach‑O binary in the cache.
  • AddressToSymbol – a map of virtual addresses to symbol names, populated on demand.
  • IsDyld4 – a boolean flag indicating whether the cache uses the newer dyld‑4 format.

Searching for Strings in the DSC

The ipsw dsc str command provides two modes for searching strings: fast byte‑wise matching and slower regex filtering. Both methods are implemented in internal/commands/dsc/dsc.go and exposed via cmd/ipsw/cmd/dyld/dyld_str.go.

For literal string matches, use positional arguments. This method scans the __TEXT,__cstring section (or any section with the S_STRING flag) of every image and performs a bytes.Contains check.

ipsw dsc str /path/to/dyld_shared_cache AppleMobileFileRelay

Internally, StrSearchCmd calls dscCmd.GetStrings(f, searchStrings...), which returns a slice of String structs containing the virtual address, the string content, and the originating image name.

Regex Pattern Matching

When you need pattern matching, use the --pattern flag. This executes the same section walk but applies regexp.MatchString to filter results.

ipsw dsc str /path/to/dyld_shared_cache --pattern '^com\.apple\..*Service$'

Because regex evaluation is slower than byte comparison, this mode is recommended for targeted searches rather than broad scans.

Looking Up Symbols

Symbol resolution is handled by the ipsw dsc symaddr command, implemented in cmd/ipsw/cmd/dyld/dyld_symaddr.go. The tool can resolve symbols from the local symbol table, the export trie (in dyld‑4 caches), or a provided JSON list.

Single Symbol Lookup

To find the address of a specific symbol within a particular library, use the -i flag to restrict the search to a single image:

ipsw dsc symaddr /path/to/dyld_shared_cache -i libsystem_malloc.dylib _malloc

The command calls f.Image("libsystem_malloc.dylib") to retrieve the *CacheImage, then invokes image.GetSymbol("_malloc"). This method reads the image’s symbol table or export trie and returns a Symbol struct containing the virtual address and binding type.

Bulk Symbol Resolution from JSON

For batch processing, provide a JSON file containing an array of symbol objects:

[
  {"symbol": "_malloc"},
  {"symbol": "_free"},
  {"symbol": "_objc_msgSend"}
]
ipsw dsc symaddr /path/to/dyld_shared_cache --in symbols.json --output results.json

SymAddrCmd reads the input JSON, calls dscCmd.GetSymbols(f, symbols...), and writes the resolved addresses to the output file. This helper iterates through the provided names, checking f.GetExportedSymbols for global exports or falling back to per‑image GetSymbol calls for local symbols.

Finding Imports and Dependencies

To determine which libraries depend on a specific dylib, use the ipsw dsc imports command. This is implemented in cmd/ipsw/cmd/dyld/dyld_imports.go and relies on dscCmd.GetDylibsThatImport in internal/commands/dsc/dsc.go.

Identifying Dylibs That Import a Specific Library

ipsw dsc imports /path/to/dyld_shared_cache libobjc.A.dylib

The command performs the following steps:

  1. Opens the DSC and resolves the target image via f.Image("libobjc.A.dylib").
  2. Calls dscCmd.GetDylibsThatImport(f, image.Name), which iterates over every *CacheImage.
  3. For each image, it loads the underlying macho.File and calls ImportedLibraries() to retrieve the list of linked libraries.
  4. Results are categorized into two buckets:
    • DSC: Other images within the shared cache that import the target.
    • Apps: Binaries located in the embedded filesystem DMG (when using the --ipsw flag to analyze a full IPSW archive).

The CLI prints a formatted list showing which components depend on the specified library, useful for understanding dependency chains and attack surfaces.

Core Implementation Details

The search functionality is built on a layered architecture that separates CLI concerns from core logic:

Component File Path Key Functions
DSC Parser pkg/dyld/file.go dyld.Open(), File, CacheImage, AddressToSymbol
Search Helpers internal/commands/dsc/dsc.go GetStrings(), GetStringsRegex(), GetDylibsThatImport(), GetSymbols()
String CLI cmd/ipsw/cmd/dyld/dyld_str.go StrSearchCmd
Symbol CLI cmd/ipsw/cmd/dyld/dyld_symaddr.go SymAddrCmd
Import CLI cmd/ipsw/cmd/dyld/dyld_imports.go dyldImportsCmd

All helpers receive a pre‑parsed *dyld.File, ensuring that virtual address translation and image metadata are readily available without redundant I/O.

Summary

  • Open the cache with dyld.Open() to obtain a parsed *dyld.File containing images and mappings.
  • Search strings using ipsw dsc str for fast literal matches or ipsw dsc str --pattern for regex filtering against __cstring sections.
  • Resolve symbols via ipsw dsc symaddr for single lookups or bulk JSON processing, leveraging local symbol tables and dyld‑4 export tries.
  • Trace imports with ipsw dsc imports to discover which cache images or embedded apps link against a specific dylib.
  • Reference implementation files include pkg/dyld/file.go for parsing and internal/commands/dsc/dsc.go for search logic.

Frequently Asked Questions

What is the difference between byte-wise and regex string searching in ipsw?

Byte-wise searching uses bytes.Contains to scan __TEXT,__cstring sections for exact literal matches, making it significantly faster for straightforward lookups. Regex searching applies regexp.MatchString after extracting candidate strings, offering pattern matching capabilities at the cost of performance. Use byte-wise for speed and regex for complex patterns like ^com\.apple\..*Service$.

How does ipsw resolve symbols in dyld4 caches compared to older formats?

In dyld4 caches, ipsw walks the export trie structure via image.GetSymbol(), which provides a compact, sorted list of exported symbols. For older caches, the tool falls back to the local symbol table (LC_SYMTAB) stored within each image. The IsDyld4 flag on the File struct determines which resolution path is taken, ensuring compatibility across iOS/macOS versions.

Can I export the search results to JSON for further processing?

Yes, the symaddr command supports JSON output via the --output flag when performing bulk lookups. You provide an input JSON file containing symbol names with --in, and ipsw writes a JSON array of resolved addresses including virtual addresses, image names, and symbol types. This facilitates integration with automated analysis pipelines or custom forensic tools.

Why does the imports command show both DSC and Apps categories?

The imports command categorizes results into DSC (images within the shared cache itself) and Apps (binaries located in the embedded filesystem DMG). When you analyze a full IPSW archive using the --ipsw flag, ipsw mounts the filesystem and scans application binaries that link against the cache, revealing dependencies outside the DSC. This dual view helps security researchers understand both system library interdependencies and third-party app linkage.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →