ELF file signature
Magic number at the start of the file · .ELF
The Executable and Linkable Format is the standard for Linux and Unix binaries, shared libraries (.so) and core dumps. Every ELF file starts with 0x7F then the ASCII letters ELF.
What this magic number means
A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 7F 45 4C 46 (the text .ELF), it is an ELF file.
The fifth byte says 32-bit (01) or 64-bit (02) and the sixth says little-endian (01) or big-endian (02), so 7F 45 4C 46 02 01 is a 64-bit little-endian ELF.
What each byte of 7F 45 4C 46 means
Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.
| Byte offset | Hex | Decimal | ASCII |
|---|---|---|---|
| 0 | 7F | 127 | . |
| 1 | 45 | 69 | E |
| 2 | 4C | 76 | L |
| 3 | 46 | 70 | F |
Formats that use the 7F 45 4C 46 signature
No extension in our database is documented under this signature: the bytes belong to the ELF format itself, which usually appears as a wrapper around something else. Files that carry it are normally named SO, AXF, core.
How to check a file's signature
You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.
Linux & macOS
- xxd -l 16 example.so
- hexdump -C -n 16 example.so
- file example.so
Windows (PowerShell)
- Format-Hex -Path example.so -Count 16
Python
- open("example.so","rb").read(4).hex()
In your browser
- Drop the file into the WhatFileType identifier, which reads the signature without uploading it.
Frequently asked questions
What is the ELF file signature?
ELF files start with the hex bytes 7F 45 4C 46 (.ELF in ASCII). This magic number identifies the format regardless of the file's name or extension.
How do I check a file's magic number?
Open the file in a hex editor, or run a command such as xxd -l 16 example.so on Linux or macOS, or Format-Hex -Path example.so -Count 16 in Windows PowerShell, and read the first bytes.
Can a file fake the ELF signature?
Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine ELF file has these exact bytes; a file with the wrong bytes is not really ELF, whatever its name says.
Related signatures
Sources
Reuse this signature
This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.