Most servers, cloud machines and security tools run on Linux. Whether you want to be a SOC analyst, a penetration tester or a cloud security engineer, you need to be comfortable in the Linux terminal. Practise these commands on your own virtual machine (Ubuntu or Kali Linux in VirtualBox) or a free cloud instance.
Navigating the file system
pwd # where am I?
ls -la # list all files, including hidden ones, with details
cd /var/log # change directory
cd ~ # go to your home directoryHidden files start with a dot (.bashrc, .ssh). Attackers often hide files this way, so always use ls -la during investigations.
Reading files
cat file.txt # print the whole file
less file.txt # scroll through a large file (q to quit)
head -n 20 file.txt # first 20 lines
tail -n 50 file.txt # last 50 lines
tail -f /var/log/auth.log # follow a log liveSearching: grep and find
grep "Failed password" /var/log/auth.log
grep -i "error" app.log # case-insensitive
grep -c "Failed password" /var/log/auth.log # count matches
find / -name "*.sh" -mtime -1 2>/dev/null # .sh files changed in the last day
find / -perm -4000 -type f 2>/dev/null # SUID files (privilege escalation check)2>/dev/null hides "permission denied" noise.
Find the IPs attacking SSH
grep "Failed password" /var/log/auth.log \
| grep -oE "([0-9]{1,3}\.){3}[0-9]{1,3}" \
| sort | uniq -c | sort -rn | headThis pipeline extracts IP addresses from failed logins, counts them and shows the top offenders. It is a classic SOC triage task. (On RHEL-based systems the file is /var/log/secure; on systemd systems you can also use journalctl -u ssh.)
File permissions
ls -l secret.txt
# -rw-r----- 1 ravi devs 120 Oct 7 10:00 secret.txt| Part | Meaning |
|---|---|
- | Regular file (d = directory) |
rw- | Owner can read and write |
r-- | Group can read |
--- | Others have no access |
chmod 600 ~/.ssh/id_ed25519 # only the owner can read/write a private key
chmod 755 script.sh # owner full, others read and execute
chown ravi:devs report.txt # change owner and groupNumbers: read = 4, write = 2, execute = 1. chmod 777 (everyone can do everything) is almost always a security mistake.
Users and privileges
whoami # current user
id # user ID and groups
sudo -l # what can I run as root?
cat /etc/passwd # list of accounts
last # recent loginsUnexpected accounts in /etc/passwd or unusual entries in last are red flags during an incident.
Processes and services
ps aux # all running processes
ps aux | grep python
top # live CPU and memory usage (q to quit)
kill 1234 # stop a process by PID
systemctl status ssh # service status
systemctl list-units --type=service --state=runningNetworking
ip a # network interfaces and IP addresses
ss -tulpn # listening ports and the processes using them
ping -c 4 example.com # connectivity
curl -I https://example.com # HTTP response headers
dig example.com # DNS lookupss -tulpn is one of the first commands to run on a suspicious server: an unknown process listening on an unusual port deserves investigation.
Hashes and integrity
sha256sum downloaded-tool.tar.gzCompare the output with the hash published by the vendor to confirm the file was not tampered with.
Quick reference
| Task | Command |
|---|---|
| Show hidden files | ls -la |
| Follow a log | tail -f /var/log/auth.log |
| Search text | grep -i "pattern" file |
| Find recent files | find / -mtime -1 |
| Listening ports | ss -tulpn |
| Permissions | chmod, chown |
| Running processes | ps aux |
| File hash | sha256sum file |
Interview questions
- What does `chmod 640` mean? Owner read/write, group read, others nothing.
- What is a SUID bit? A permission that runs a file with its owner's privileges; misconfigured SUID binaries owned by root can allow privilege escalation.
- How do you check which process is using port 8080?
ss -tulpn | grep 8080(orlsof -i :8080).
Next steps
Set up a Linux virtual machine and repeat every command here until it feels natural. Then study the OWASP Top 10, or learn SOC operations and ethical hacking in the Cyber Security + AI course.
