50 Linux Commands for Cybersecurity Beginners: Complete Practical Guide

50 Linux Commands for Cybersecurity Beginners

Linux is one of the most useful operating systems to learn when entering cybersecurity.

Security professionals frequently work with Linux servers, security tools, command-line utilities, containers, cloud systems, logs and virtual machines.

However, beginners often face the same problem:

There are hundreds of Linux commands. Which ones should I learn first?

You do not need to memorize hundreds of commands at the beginning.

A practical starting point is to understand a smaller set of commands for:

  • Files and directories
  • Users and permissions
  • Processes
  • Networking
  • Logs
  • System information
  • SSH
  • Text processing
  • Troubleshooting

This guide covers 50 useful Linux commands for cybersecurity beginners, with simple examples and explanations.

Important: Use security-related commands only on systems you own or systems where you have explicit authorization to test.


Why Linux Is Important in Cybersecurity

Linux provides a powerful command-line environment and is widely used across servers, development systems, cloud infrastructure and security tooling.

Learning Linux helps you become comfortable with:

  • Command-line interfaces
  • Filesystems
  • Permissions
  • Processes
  • Network connections
  • Services
  • Logs
  • Automation

Security distributions such as Kali Linux and security tools running on standard Linux distributions can make use of many of the same underlying command-line concepts.


Linux Command Structure

Most Linux commands follow a basic structure:

command [options] [arguments]

For example:

ls -lah /home

Here:

  • ls = command
  • -lah = options
  • /home = argument/path

1. pwd — Show Current Directory

pwd means print working directory.

It tells you where you are currently located in the filesystem.

pwd

Example output:

/home/user

This command is useful when working in multiple directories.


2. ls — List Files

The ls command displays files and directories.

ls

Useful options:

ls -l
ls -a
ls -lh
ls -lah

-l shows detailed information.

-a includes hidden files.

-h makes sizes easier to read.


3. cd — Change Directory

Use cd to move between directories.

cd /var/log

Go to the parent directory:

cd ..

Return to your home directory:

cd ~

4. mkdir — Create a Directory

Create a new directory:

mkdir security-lab

Create nested directories:

mkdir -p security/network/logs

5. touch — Create a File

touch can create an empty file.

touch notes.txt

It is also commonly used to update file timestamps.


6. cp — Copy Files

Copy a file:

cp notes.txt backup.txt

Copy a directory recursively:

cp -r lab lab-backup

7. mv — Move or Rename Files

Rename a file:

mv old.txt new.txt

Move a file:

mv report.txt reports/

8. rm — Remove Files

Remove a file:

rm test.txt

Remove an empty directory:

rmdir old-folder

Be extremely careful with rm. Files removed from the command line may not go to a recycle bin.


9. cat — Display File Contents

Use cat to display the contents of a file.

cat notes.txt

It is useful for quickly inspecting configuration files and small log files.


10. less — Read Large Files

For larger files, less is generally more convenient.

less /var/log/syslog

You can move through the file and search within it without loading the entire file into a simple terminal display.


11. head — Show the Beginning of a File

head notes.txt

Show the first 20 lines:

head -n 20 notes.txt

12. tail — Show the End of a File

tail notes.txt

One particularly useful feature is following a growing log:

tail -f application.log

This can be useful for watching new log entries in a controlled environment.


13. grep — Search Text

grep is one of the most useful commands for log analysis.

Example:

grep "error" application.log

Case-insensitive search:

grep -i "failed" application.log

Recursive search:

grep -r "password" /var/log/

Be careful when searching sensitive directories and understand permissions before accessing security-related files.


14. find — Search for Files

Find files by name:

find /home/user -name "*.log"

Find directories:

find /home/user -type d

find is useful for system administration and investigating where files are stored.


15. file — Identify a File Type

Linux does not depend only on file extensions to identify files.

Use:

file suspicious.bin

The command examines the file and reports the type it detects.


16. wc — Count Lines, Words and Bytes

wc notes.txt

Count lines:

wc -l notes.txt

This can be helpful when analyzing log or data files.


17. sort — Sort Text

sort users.txt

Sort in reverse:

sort -r users.txt

18. uniq — Remove Repeated Adjacent Lines

sort ips.txt | uniq

Count repeated lines:

sort ips.txt | uniq -c

This can be useful when summarizing repeated entries in data.


19. cut — Extract Parts of Text

Example:

cut -d: -f1 /etc/passwd

This extracts the first field from the colon-separated file.


20. awk — Process Structured Text

awk is a powerful text-processing language.

Simple example:

awk '{print $1}' access.log

This prints the first whitespace-separated field from each line.

It becomes particularly useful for extracting and analyzing structured log data.


21. sed — Search and Transform Text

sed can perform text transformations.

Example:

sed 's/old/new/g' file.txt

Use caution when modifying important configuration files.


22. chmod — Change File Permissions

Linux permissions control who can read, write or execute files.

Example:

chmod 600 secret.txt

This permission setting is commonly used when a file should be accessible only to its owner.

Another example:

chmod +x script.sh

This adds execute permission.


23. chown — Change File Ownership

chown user:user file.txt

Ownership is an important part of Linux security.


24. id — Show User Identity

id

You can also inspect another user:

id username

This can show the user's UID, GID and group membership.


25. whoami — Show Current User

whoami

This is a simple but useful command when working across different accounts.


26. who — Show Logged-In Users

who

It provides information about current login sessions.


27. ps — View Processes

Processes are running programs.

Display processes for the current session:

ps

Show a broader process listing:

ps aux

This is useful for system administration and troubleshooting.


28. top — Monitor Processes

top

top provides a live view of processes and resource usage.

You may use it to investigate:

  • CPU usage
  • Memory usage
  • Running processes
  • Process IDs

29. kill — Send a Signal to a Process

You can send a signal to a process using its process ID.

kill 1234

Use process-control commands carefully, especially when working on production systems.


30. systemctl — Manage Services

On systems using systemd, systemctl is commonly used to inspect and manage services.

Check a service:

systemctl status ssh

Start a service:

sudo systemctl start ssh

The exact service name can vary between Linux distributions.


31. uname — System Information

uname -a

This can display information about the kernel and system.


32. hostname — Show System Hostname

hostname

The hostname identifies the system on a network.


33. uptime — Check System Uptime

uptime

It displays how long the system has been running and provides load information.


34. df — Check Disk Space

Use df to view filesystem disk usage.

df -h

This is helpful when a server runs out of storage.


35. du — Check Directory Size

du -sh *

This gives a quick view of how much space directories or files consume.


36. free — Check Memory Usage

free -h

This shows memory and swap information in human-readable form.


37. ip — Network Configuration

The ip command is one of the most useful modern Linux networking utilities.

Show network interfaces:

ip addr

Show routing information:

ip route

Show link information:

ip link

38. ss — View Network Connections

ss is useful for viewing sockets and network connections.

ss -tuln

This can help you understand which TCP and UDP ports are listening on the local system.

This is particularly useful when troubleshooting unexpected services.


39. ping — Test Basic Network Reachability

ping example.com

Ping uses ICMP echo mechanisms to test reachability when the destination and network permit it.

Not receiving a ping response does not automatically mean a host is offline because firewalls or network policies may block ICMP.


40. traceroute — Examine Network Paths

traceroute can help investigate the path packets take through networks.

traceroute example.com

Some Linux distributions may use related tools or require separate package installation.


41. dig — Query DNS

dig is extremely useful when learning DNS.

dig example.com

Query a specific record type:

dig example.com MX

This is useful for understanding DNS behavior in a controlled troubleshooting or administrative context.


42. nslookup — DNS Lookup

nslookup example.com

It provides DNS lookup information and is useful for basic network troubleshooting.


43. curl — Make HTTP Requests

curl is one of the most important command-line tools for developers and security learners.

Request a webpage:

curl https://example.com

Show response headers:

curl -I https://example.com

It can be useful for learning HTTP requests, headers and APIs.


44. wget — Download Resources

wget https://example.com/file.zip

Use it carefully and only download software or files from trusted sources.


45. ssh — Secure Remote Login

SSH is widely used for securely accessing remote Linux systems.

ssh username@server.example.com

Example with an IP address:

ssh user@192.168.1.20

SSH is an essential skill for server administration and cybersecurity.


46. scp — Securely Copy Files

scp can transfer files using SSH.

scp report.txt user@192.168.1.20:/home/user/

Modern environments may also use alternatives such as SFTP or other secure transfer mechanisms.


47. history — View Command History

history

You can search your shell history with:

history | grep ssh

This can be useful when reviewing what commands you recently executed.


48. man — Read the Manual

One of the best Linux habits is learning to use documentation.

For example:

man ls

Or:

man ip

Instead of memorizing everything, learn how to look up the correct syntax and options.


49. sudo — Run a Command With Elevated Privileges

sudo allows an authorized user to run commands with elevated privileges according to the system's configuration.

Example:

sudo systemctl status ssh

Another example:

sudo apt update

Use elevated privileges carefully. A command executed with high privileges can make system-wide changes.


50. journalctl — Read systemd Logs

On systems using systemd, journalctl provides access to journal logs.

View recent entries:

journalctl

View recent entries from a particular service:

journalctl -u ssh

Follow new entries:

journalctl -f

Log analysis is an important skill in defensive cybersecurity and incident investigation.


Linux Commands Cheat Sheet

Command Purpose
pwdShow current directory
lsList files
cdChange directory
mkdirCreate directory
touchCreate file
cpCopy files
mvMove/rename
rmRemove files
catDisplay file
lessRead large files
headShow beginning
tailShow end/follow logs
grepSearch text
findFind files
fileIdentify file type
wcCount text
sortSort text
uniqFind repeated lines
cutExtract fields
awkProcess text
sedTransform text
chmodChange permissions
chownChange ownership
idShow user/group IDs
whoamiShow current user
whoShow logged-in users
psView processes
topMonitor processes
killSend process signal
systemctlManage services
unameSystem information
hostnameShow hostname
uptimeShow uptime
dfDisk usage
duDirectory size
freeMemory usage
ipNetwork configuration
ssView sockets/connections
pingBasic reachability test
tracerouteTrace network path
digDNS queries
nslookupDNS lookup
curlHTTP/API requests
wgetDownload resources
sshRemote secure login
scpSecure file transfer
historyCommand history
manCommand documentation
sudoRun authorized elevated commands
journalctlRead systemd logs

Useful Linux Command Combinations for Security Learning

Linux becomes much more powerful when commands are combined using pipes.

Find Repeated IP Addresses

cat access.log | awk '{print $1}' | sort | uniq -c | sort -nr

This example extracts the first field, counts occurrences and sorts them by frequency.

Find Errors in a Log

grep -i "error" application.log

Watch a Log in Real Time

tail -f application.log

Check Listening Network Ports

ss -tuln

Check a Website's HTTP Headers

curl -I https://example.com

These examples are useful for learning and troubleshooting your own systems or authorized environments.


Understanding Linux Permissions

One of the most important Linux security concepts is the permission model.

You may see output such as:

-rwxr-xr--

The permissions are divided into groups for:

  • Owner
  • Group
  • Others

The basic permission types are:

  • r = read
  • w = write
  • x = execute

Understanding these permissions is essential for secure Linux administration.


Understanding sudo

Many beginner security labs use commands that require administrative privileges.

For example:

sudo systemctl status ssh

Do not blindly add sudo to every command.

First understand:

  • Why elevated privileges are required
  • What the command will change
  • What system it affects
  • Whether the command is safe to execute

How These Commands Help in Cybersecurity

Cybersecurity Task Useful Commands
File investigation ls, find, file, cat, less
Log analysis grep, tail, head, awk, sed, journalctl
Network troubleshooting ip, ss, ping, traceroute, dig, nslookup
System investigation ps, top, uname, uptime, hostname
Access control id, whoami, chmod, chown, sudo
Remote administration ssh, scp
HTTP/API analysis curl

Beginner Linux Practice Lab

You can practice these commands without attacking real systems.

Create a small directory:

mkdir -p ~/cyber-lab/logs
cd ~/cyber-lab

Create a sample log:

cat > logs/access.log <<EOF
192.168.1.10 login success
192.168.1.12 login failed
192.168.1.10 page request
192.168.1.12 login failed
192.168.1.15 login success
EOF

Search for failed logins:

grep "failed" logs/access.log

Count the IP addresses:

awk '{print $1}' logs/access.log | sort | uniq -c

This kind of controlled exercise teaches command-line investigation without interacting with an external system.


Common Mistakes Linux Beginners Should Avoid

1. Running Commands Without Understanding Them

Do not copy commands from a random tutorial and execute them blindly.

2. Using sudo Unnecessarily

Administrative privileges increase the potential impact of mistakes.

3. Using rm Carelessly

Always verify the path before deleting files.

4. Ignoring File Permissions

Incorrect permissions can expose sensitive information or enable unintended changes.

5. Learning Only Offensive Tools

Linux knowledge is equally valuable for administration, monitoring and defense.

6. Memorizing Instead of Understanding

Knowing what a command does is more valuable than memorizing a long list of syntax options.


How to Memorize Linux Commands

Do not try to memorize all 50 commands in one day.

Group them by purpose.

Files:
ls cd pwd mkdir cp mv rm

Text:
cat less head tail grep awk sed

Processes:
ps top kill

Network:
ip ss ping dig curl

Security:
chmod chown id whoami sudo

Logs:
journalctl tail grep

Remote:
ssh scp

Practice the commands repeatedly until they become familiar.


A 7-Day Linux Command Practice Plan

Day Topics
Day 1pwd, ls, cd, mkdir, touch
Day 2cp, mv, rm, cat, less, head, tail
Day 3grep, find, file, wc, sort, uniq, cut
Day 4chmod, chown, id, whoami, sudo
Day 5ps, top, kill, systemctl, uname, df, du, free
Day 6ip, ss, ping, traceroute, dig, nslookup, curl
Day 7ssh, scp, history, man, journalctl + revision

Linux Commands vs Cybersecurity Tools

There is an important distinction between learning Linux and learning security tools.

Commands such as:

ip
ss
grep
ps
journalctl

are general Linux utilities.

Tools such as specialized vulnerability scanners, web security platforms and penetration-testing frameworks are separate security applications.

A strong cybersecurity learner should understand both the operating system and the specialized tools.


What Should You Learn After These Commands?

Once you are comfortable with these commands, continue with:

  • Linux filesystem structure
  • Users and groups
  • Permissions
  • Processes
  • Services
  • System logs
  • Bash scripting
  • Networking
  • SSH security
  • Web servers
  • Security monitoring

Then move toward cybersecurity-specific tools and controlled labs.


Frequently Asked Questions

1. Do I need Linux for cybersecurity?

Not every cybersecurity role requires deep Linux knowledge, but Linux is highly useful across many security, infrastructure and technical roles.

2. Should I use Kali Linux to learn Linux?

You can, but you do not need Kali Linux to learn basic Linux administration. A beginner can learn many concepts on a general-purpose Linux distribution and later use security-focused environments for specialized practice.

3. How many Linux commands should a beginner memorize?

There is no required number. Focus on understanding a useful core set and learn to use man pages and documentation when you need additional options.

4. Which Linux command is most important for cybersecurity?

There is no single most important command. Commands such as grep, find, ps, ss, ip, journalctl, chmod and curl are particularly useful in different security and troubleshooting situations.

5. Is command-line knowledge better than a graphical interface?

Both have their uses. Command-line knowledge gives you powerful control, automation and visibility, particularly on remote servers.

6. Can these commands be used on Windows?

Windows has different native commands, but Linux tools can also be used through environments such as WSL or virtual machines.

7. Is sudo dangerous?

sudo itself is an administrative mechanism. The risk comes from what an elevated command is allowed to do. Always understand commands before running them with elevated privileges.

8. Why is grep important in cybersecurity?

grep can quickly search text for patterns, making it useful for analyzing logs, configuration files and other text-based data.

9. Is SSH secure?

SSH is designed for secure remote administration, but its security still depends on proper configuration, strong authentication and good system security practices.

10. Can I practice cybersecurity commands on public websites?

Do not test systems simply because they are publicly accessible. Practice against your own systems, intentionally vulnerable applications, training labs or systems where you have explicit authorization.


Final Thoughts

Learning Linux is one of the best technical foundations you can build for cybersecurity.

You do not need to become a Linux administrator overnight.

Start with:

Files → Permissions → Processes → Networking → Logs → Remote Access → Automation

Then practice those concepts in a safe lab.

The goal is not to memorize 50 commands just for the sake of memorization.

The real goal is to reach a point where you can open a terminal, investigate a system, understand what you are seeing and use the appropriate command to answer a technical question.

That ability will make the cybersecurity topics that come later much easier to understand.


Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact article URLs after the corresponding CodeWithAV posts are published.


Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.