Command Palette

Search for a command to run...

Regular Expression Search Guide

Harness the power of regular expressions for advanced pattern matching and precise data discovery on LeakZero. Regular expressions represent the pinnacle of pattern matching technology, offering unparalleled precision and flexibility in data discovery operations.

Regular expression searches are available to subscribers with advanced search capabilities and provide exponentially more powerful pattern matching than wildcard searches.

What are Regular Expressions?

Regular expressions are a formal language for describing search patterns using a standardized syntax. Originally developed in theoretical computer science and popularized by Unix systems, regex has become the gold standard for pattern matching across cybersecurity, data analysis, and software development industries.

In the context of breach investigation, regular expressions enable you to:

  • Define precise character sequences and variations
  • Specify complex structural patterns in email addresses and usernames
  • Implement conditional matching logic
  • Extract specific data segments from larger datasets
  • Validate and identify formatted data types (phone numbers, credit cards, etc.)

Fundamental Regex Components

Character Classes
Character classes define sets of characters that can match a single position in your pattern.

Basic Character Classes:

.
- Matches any single character except newline
\d
- Matches any digit (0-9)
\w
- Matches any word character (letters, digits, underscore)
\s
- Matches any whitespace character

Custom Character Classes:

[abc]
- Matches exactly one of: a, b, or c
[a-z]
- Matches any lowercase letter
[0-9]
- Matches any digit
[^abc]
- Matches any character except a, b, or c
Quantifiers
Quantifiers specify how many times a character or group should be matched.

Precise Quantifiers:

{n}
- Exactly n occurrences
{n,m}
- Between n and m occurrences
{n,}
- At least n occurrences

Common Quantifiers:

*
- Zero or more occurrences
+
- One or more occurrences
?
- Zero or one occurrence (optional)
Anchors
Anchors specify position within the text being searched.
^
- Beginning of line
$
- End of line
\b
- Word boundary
\B
- Non-word boundary
Groups and Capturing
Groups allow you to treat multiple characters as a single unit and capture matched content.
(pattern)
- Capturing group
(?:pattern)
- Non-capturing group
(pattern1|pattern2)
- Alternation (OR logic)

Advanced Regex Patterns for Breach Investigation

Email Address Pattern Matching

Standard Email Validation:

^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$

Corporate Email Patterns:

^[a-zA-Z]+\.[a-zA-Z]+@company\.com$

Matches: [email protected]

Administrative Account Detection:

^(admin|administrator|root|sysadmin).*@.*$

Service Account Identification:

^(no-?reply|support|service|system).*@.*$
Username Pattern Analysis

Alphanumeric with Numbers:

^[a-zA-Z]+\d{1,4}$

Matches: user123, admin1, test99

Corporate Username Standards:

^[a-z]{1,2}\.[a-z]+\d*$

Matches: j.doe, a.smith123, m.johnson

Temporary Account Patterns:

^(temp|tmp|test).*\d{4}$

Matches: temp2023, test_user2024

Domain Analysis Patterns

Subdomain Extraction:

@([a-z0-9-]+\.)*target\.com$

Top-Level Domain Variations:

@company\.(com|org|net|edu|gov)$

Free Email Provider Detection:

@(gmail|yahoo|hotmail|outlook|aol)\.com$

Strategic Regex Applications

Executive Protection Patterns

C-Suite Email Detection:

^(ceo|cto|cfo|coo|president|founder).*@.*$

Executive Name Variations:

^(john|j)\.?(doe|d).*@.*$

Board Member Identification:

^(board|director|chairman).*@.*$
Technical Infrastructure Analysis

System Administrator Accounts:

^(sysadmin|system|admin|root|administrator)(\.|_|-)?.*@.*$

Development Environment Detection:

@(dev|staging|test|qa|beta)\..*$

Backup System Identification:

^(backup|archive|mirror|sync).*@.*$
Compliance and Regulatory Patterns

GDPR-Relevant Personal Data:

^[a-zA-Z]+([-.]?[a-zA-Z]+)*@(eu\.|.*\.eu)$

HIPAA Healthcare Domains:

@.*\.(health|medical|hospital|clinic)\..*$

Financial Services Detection:

@.*(bank|financial|credit|investment).*\.(com|org)$
Threat Intelligence Correlation

APT Campaign Patterns:

^[a-z]{3,8}\d{2,4}@[a-z0-9-]+\.(tk|ml|ga|cf)$

Botnet Command Structure:

^(c2|cmd|control|bot)\d*@.*$

Phishing Infrastructure:

@[a-z0-9-]*?(secure|verify|update|confirm)[a-z0-9-]*?\.(com|net|org)$

Performance Optimization for Regex

Efficient Pattern Design

Optimized vs. Inefficient Patterns:

Catastrophic Backtracking Risk:
^(a+)+b$
Optimized Alternative:
^a+b$
Excessive Alternation:
^(admin|administrator|root|sysadmin|superuser|su|wheel).*@.*$
Character Class Optimization:
^(admin|root|su)(istrator|user|peruser)?.*@.*$

Best Practices:

  • Anchor Patterns: Use ^ and $ to prevent unnecessary backtracking
  • Specific Quantifiers: Use {n,m} instead of * when possible
  • Non-Capturing Groups: Use (?:...) when you don't need to capture content
  • Atomic Groups: Use (?>...) to prevent backtracking where appropriate

Common Regex Patterns for Cybersecurity

Data Classification Patterns

Credit Card Numbers:

\b(?:\d{4}[-\s]?){3}\d{4}\b

Social Security Numbers:

\b\d{3}-?\d{2}-?\d{4}\b

Phone Numbers:

\b(?:\+?1[-.\s]?)?\(?[0-9]{3}\)?[-.\s]?[0-9]{3}[-.\s]?[0-9]{4}\b

IP Addresses:

\b(?:[0-9]{1,3}\.){3}[0-9]{1,3}\b
Malware and IOC Detection

Suspicious File Extensions:

\.(exe|scr|bat|com|pif|vbs|js|jar|zip|rar)$

Command and Control Domains:

[a-z0-9]{10,20}\.(tk|ml|ga|cf|cc)

Base64 Encoded Strings:

[A-Za-z0-9+/]{20,}={0,2}

DNS Tunneling Detection:

[a-f0-9]{32,}\.[a-z0-9-]+\.com

Advanced Techniques

Lookahead and Lookbehind Assertions

Positive Lookahead (?=...):

admin(?=@company\.com)

Matches "admin" only if followed by "@company.com"

Negative Lookahead (?!...):

user(?!123)

Matches "user" only if NOT followed by "123"

Positive Lookbehind (?<=...):

(?<=admin)@company\.com

Matches "@company.com" only if preceded by "admin"

Negative Lookbehind (?<!...):

(?<!test)@company\.com

Matches "@company.com" only if NOT preceded by "test"

Conditional Patterns

If-Then-Else Logic:

(admin)?(?(1)istrator|user)@.*

Matches either "administrator@..." or "user@..."

Complex Conditional Matching:

^(?:(dev|test)\.)?([a-z]+)(?:\.(?(1)local|prod))?@company\.com$

Further Reading and Resources

Foundational Resources
  • "Mastering Regular Expressions" by Jeffrey Friedl: The definitive guide to regex theory and practice
  • Mozilla Developer Network (MDN): Comprehensive regex documentation and examples
  • Regular-Expressions.info: Extensive tutorials and reference materials
  • RegexOne Interactive Tutorial: Hands-on learning platform
Security-Specific Resources
  • SANS Digital Forensics: Regex applications in incident response
  • NIST Special Publication 800-86: Guide to integrating forensic techniques
  • MITRE ATT&CK: Reconnaissance and collection technique documentation
  • OWASP Testing Guide: Security testing with pattern matching
Security Consideration
Regular expressions can be vulnerable to ReDoS (Regular Expression Denial of Service) attacks. Always validate pattern complexity and implement appropriate timeouts in production environments.
Next Steps
Having mastered regular expressions, expand your LeakZero expertise with these advanced topics.
Pro Tip
Start with simple patterns and progressively add complexity. Every expert regex practitioner began with basic character matching and evolved their skills through practical application. LeakZero's regex implementation includes helpful error messages and suggestions to guide your learning journey.
Documentation - LeakZero | LeakZero