APEX Educational Institute

Linux Commands Every Cyber Security Beginner Should Know

The essential Linux commands for security work: navigating files, permissions, users, processes, reading logs, searching with grep and checking network connections, with security-focused examples.

Beginner | 4 min read | Updated

Most servers, cloud machines and security tools run on Linux. Whether you want to be a SOC analyst, a penetration tester or a cloud security engineer, you need to be comfortable in the Linux terminal. Practise these commands on your own virtual machine (Ubuntu or Kali Linux in VirtualBox) or a free cloud instance.

bash
pwd                 # where am I?
ls -la              # list all files, including hidden ones, with details
cd /var/log         # change directory
cd ~                # go to your home directory

Hidden files start with a dot (.bashrc, .ssh). Attackers often hide files this way, so always use ls -la during investigations.

Reading files

bash
cat file.txt        # print the whole file
less file.txt       # scroll through a large file (q to quit)
head -n 20 file.txt # first 20 lines
tail -n 50 file.txt # last 50 lines
tail -f /var/log/auth.log   # follow a log live

Searching: grep and find

bash
grep "Failed password" /var/log/auth.log
grep -i "error" app.log            # case-insensitive
grep -c "Failed password" /var/log/auth.log   # count matches
find / -name "*.sh" -mtime -1 2>/dev/null     # .sh files changed in the last day
find / -perm -4000 -type f 2>/dev/null        # SUID files (privilege escalation check)

2>/dev/null hides "permission denied" noise.

Find the IPs attacking SSH

bash
grep "Failed password" /var/log/auth.log \
  | grep -oE "([0-9]{1,3}\.){3}[0-9]{1,3}" \
  | sort | uniq -c | sort -rn | head

This pipeline extracts IP addresses from failed logins, counts them and shows the top offenders. It is a classic SOC triage task. (On RHEL-based systems the file is /var/log/secure; on systemd systems you can also use journalctl -u ssh.)

File permissions

bash
ls -l secret.txt
# -rw-r----- 1 ravi devs 120 Oct 7 10:00 secret.txt
PartMeaning
-Regular file (d = directory)
rw-Owner can read and write
r--Group can read
---Others have no access
bash
chmod 600 ~/.ssh/id_ed25519   # only the owner can read/write a private key
chmod 755 script.sh           # owner full, others read and execute
chown ravi:devs report.txt    # change owner and group

Numbers: read = 4, write = 2, execute = 1. chmod 777 (everyone can do everything) is almost always a security mistake.

Users and privileges

bash
whoami              # current user
id                  # user ID and groups
sudo -l             # what can I run as root?
cat /etc/passwd     # list of accounts
last                # recent logins

Unexpected accounts in /etc/passwd or unusual entries in last are red flags during an incident.

Processes and services

bash
ps aux                       # all running processes
ps aux | grep python
top                          # live CPU and memory usage (q to quit)
kill 1234                    # stop a process by PID
systemctl status ssh         # service status
systemctl list-units --type=service --state=running

Networking

bash
ip a                         # network interfaces and IP addresses
ss -tulpn                    # listening ports and the processes using them
ping -c 4 example.com        # connectivity
curl -I https://example.com  # HTTP response headers
dig example.com              # DNS lookup

ss -tulpn is one of the first commands to run on a suspicious server: an unknown process listening on an unusual port deserves investigation.

Hashes and integrity

bash
sha256sum downloaded-tool.tar.gz

Compare the output with the hash published by the vendor to confirm the file was not tampered with.

Quick reference

TaskCommand
Show hidden filesls -la
Follow a logtail -f /var/log/auth.log
Search textgrep -i "pattern" file
Find recent filesfind / -mtime -1
Listening portsss -tulpn
Permissionschmod, chown
Running processesps aux
File hashsha256sum file

Interview questions

  • What does `chmod 640` mean? Owner read/write, group read, others nothing.
  • What is a SUID bit? A permission that runs a file with its owner's privileges; misconfigured SUID binaries owned by root can allow privilege escalation.
  • How do you check which process is using port 8080? ss -tulpn | grep 8080 (or lsof -i :8080).

Next steps

Set up a Linux virtual machine and repeat every command here until it feels natural. Then study the OWASP Top 10, or learn SOC operations and ethical hacking in the Cyber Security + AI course.

Master it hands-on

Cyber Security

Cyber Security + AI

Networking, ethical hacking, web security, SOC and AI security.

16 weeks Beginner to Advanced
Online LiveRecorded Course

More Cyber Security tutorials