Cheatsheet
Bash
Scripting patterns that make security tooling output safe to handle.
15 entries4 groupsRevised 8 Jan 2026
15/15
Safety settings
Put these at the top of any script that touches real files.
- Fail on errors and unset variables
set -euo pipefail - Stop on a pipeline that fails partway
set -o pipefail - Prevent globbing surprises
IFS=$'\n'Use with `while read -r line` - Cleanup on exit
trap 'rm -rf "$tmp"' EXIT
Loops and pipelines
- Read a file line by line
while IFS= read -r line; do echo "$line"; done < hosts.txt - Loop over IPs from a scan
grep -oE '([0-9]{1,3}\.){3}[0-9]{1,3}' out.gnmap | sort -u | while read -r ip; do echo "$ip"; done - Parallel with a limit
xargs -a hosts.txt -P 4 -n 1 -I{} sh -c 'echo {}' - Progress-free output for pipes
cmd 2>/dev/null | tee -a run.logKeep stderr in a log, not in the pipe
Quoting and expansion
- Command substitution
ts=$(date -u +%Y%m%dT%H%M%SZ) - Default value when empty
target="${TARGET:-192.0.2.10}" - Substring and length
echo "${host:0:8}" - Never word-split a list
for f in "${files[@]}"; do :; done
Debugging
- Trace execution
bash -x ./script.sh - Syntax check only
bash -n ./script.sh - See what a command resolves to
type -a nmap; command -v ffuf