Cheatsheet
Linux essentials
The commands that appear in almost every security workflow, with the flags that matter.
25 entries5 groupsRevised 12 Jan 2026
25/25
Where am I
- Network interfaces and addresses
ip -br addr - Routes
ip route - Listening sockets with owning process
ss -ltnp - All established connections
ss -tnp state established - DNS resolution actually in use
resolvectl status | head -20 - Kernel and release
uname -a && cat /etc/os-release
Processes
- Tree view
ps auxf | less - Newest first
ps -eo pid,ppid,etime,comm --sort=-etime | head -20 - What a PID has open
sudo ls -l /proc/<pid>/fdAlso: lsof -p <pid> - Live overview
top -o %CPU - Kill politely, then forcefully
kill -TERM <pid>; kill -KILL <pid>Give the graceful signal a moment first
Files and permissions
- Find by name
find /etc -name '*.conf' -maxdepth 2 - Newer than a reference file
find . -newer /etc/hostname -type f - Setuid/setgid binaries
find / -perm -4000 -o -perm -2000 2>/dev/nullReview, do not treat as findings by themselves - Change mode recursively on a copy
chmod -R u+rwX,go-rwx ./copy - Show effective ACLs
getfacl -p path/to/file
Text work
- Count matches per file
grep -rc 'error' logs/ - Only the match, de-duplicated
grep -ohE '([0-9]{1,3}\.){3}[0-9]{1,3}' file | sort -u - Fields 1 and 4 of a column file
awk '{print $1, $4}' out.txt - Top values of a column
cut -d' ' -f7 access.log | sort | uniq -c | sort -rn | head - Diff two directories quietly
diff -rq a/ b/ | head -40
Services and boot
- Status and recent log lines
systemctl status ssh --no-pager - Journal for one unit, since 1h
journalctl -u nginx --since -1h --no-pager | tail -50 - Enabled units at boot
systemctl list-unit-files --state enabled - Cron for the current user
crontab -l