50 Linux Commands for Cybersecurity Beginners
Linux is one of the most useful operating systems to learn when entering cybersecurity.
Security professionals frequently work with Linux servers, security tools, command-line utilities, containers, cloud systems, logs and virtual machines.
However, beginners often face the same problem:
You do not need to memorize hundreds of commands at the beginning.
A practical starting point is to understand a smaller set of commands for:
- Files and directories
- Users and permissions
- Processes
- Networking
- Logs
- System information
- SSH
- Text processing
- Troubleshooting
This guide covers 50 useful Linux commands for cybersecurity beginners, with simple examples and explanations.
Important: Use security-related commands only on systems you own or systems where you have explicit authorization to test.
Why Linux Is Important in Cybersecurity
Linux provides a powerful command-line environment and is widely used across servers, development systems, cloud infrastructure and security tooling.
Learning Linux helps you become comfortable with:
- Command-line interfaces
- Filesystems
- Permissions
- Processes
- Network connections
- Services
- Logs
- Automation
Security distributions such as Kali Linux and security tools running on standard Linux distributions can make use of many of the same underlying command-line concepts.
Linux Command Structure
Most Linux commands follow a basic structure:
command [options] [arguments]
For example:
ls -lah /home
Here:
- ls = command
- -lah = options
- /home = argument/path
1. pwd — Show Current Directory
pwd means print working directory.
It tells you where you are currently located in the filesystem.
pwd
Example output:
/home/user
This command is useful when working in multiple directories.
2. ls — List Files
The ls command displays files and directories.
ls
Useful options:
ls -l ls -a ls -lh ls -lah
-l shows detailed information.
-a includes hidden files.
-h makes sizes easier to read.
3. cd — Change Directory
Use cd to move between directories.
cd /var/log
Go to the parent directory:
cd ..
Return to your home directory:
cd ~
4. mkdir — Create a Directory
Create a new directory:
mkdir security-lab
Create nested directories:
mkdir -p security/network/logs
5. touch — Create a File
touch can create an empty file.
touch notes.txt
It is also commonly used to update file timestamps.
6. cp — Copy Files
Copy a file:
cp notes.txt backup.txt
Copy a directory recursively:
cp -r lab lab-backup
7. mv — Move or Rename Files
Rename a file:
mv old.txt new.txt
Move a file:
mv report.txt reports/
8. rm — Remove Files
Remove a file:
rm test.txt
Remove an empty directory:
rmdir old-folder
Be extremely careful with rm. Files removed from the command line may not go to a recycle bin.
9. cat — Display File Contents
Use cat to display the contents of a file.
cat notes.txt
It is useful for quickly inspecting configuration files and small log files.
10. less — Read Large Files
For larger files, less is generally more convenient.
less /var/log/syslog
You can move through the file and search within it without loading the entire file into a simple terminal display.
11. head — Show the Beginning of a File
head notes.txt
Show the first 20 lines:
head -n 20 notes.txt
12. tail — Show the End of a File
tail notes.txt
One particularly useful feature is following a growing log:
tail -f application.log
This can be useful for watching new log entries in a controlled environment.
13. grep — Search Text
grep is one of the most useful commands for log analysis.
Example:
grep "error" application.log
Case-insensitive search:
grep -i "failed" application.log
Recursive search:
grep -r "password" /var/log/
Be careful when searching sensitive directories and understand permissions before accessing security-related files.
14. find — Search for Files
Find files by name:
find /home/user -name "*.log"
Find directories:
find /home/user -type d
find is useful for system administration and investigating where files are stored.
15. file — Identify a File Type
Linux does not depend only on file extensions to identify files.
Use:
file suspicious.bin
The command examines the file and reports the type it detects.
16. wc — Count Lines, Words and Bytes
wc notes.txt
Count lines:
wc -l notes.txt
This can be helpful when analyzing log or data files.
17. sort — Sort Text
sort users.txt
Sort in reverse:
sort -r users.txt
18. uniq — Remove Repeated Adjacent Lines
sort ips.txt | uniq
Count repeated lines:
sort ips.txt | uniq -c
This can be useful when summarizing repeated entries in data.
19. cut — Extract Parts of Text
Example:
cut -d: -f1 /etc/passwd
This extracts the first field from the colon-separated file.
20. awk — Process Structured Text
awk is a powerful text-processing language.
Simple example:
awk '{print $1}' access.log
This prints the first whitespace-separated field from each line.
It becomes particularly useful for extracting and analyzing structured log data.
21. sed — Search and Transform Text
sed can perform text transformations.
Example:
sed 's/old/new/g' file.txt
Use caution when modifying important configuration files.
22. chmod — Change File Permissions
Linux permissions control who can read, write or execute files.
Example:
chmod 600 secret.txt
This permission setting is commonly used when a file should be accessible only to its owner.
Another example:
chmod +x script.sh
This adds execute permission.
23. chown — Change File Ownership
chown user:user file.txt
Ownership is an important part of Linux security.
24. id — Show User Identity
id
You can also inspect another user:
id username
This can show the user's UID, GID and group membership.
25. whoami — Show Current User
whoami
This is a simple but useful command when working across different accounts.
26. who — Show Logged-In Users
who
It provides information about current login sessions.
27. ps — View Processes
Processes are running programs.
Display processes for the current session:
ps
Show a broader process listing:
ps aux
This is useful for system administration and troubleshooting.
28. top — Monitor Processes
top
top provides a live view of processes and resource usage.
You may use it to investigate:
- CPU usage
- Memory usage
- Running processes
- Process IDs
29. kill — Send a Signal to a Process
You can send a signal to a process using its process ID.
kill 1234
Use process-control commands carefully, especially when working on production systems.
30. systemctl — Manage Services
On systems using systemd, systemctl is commonly used to inspect and manage services.
Check a service:
systemctl status ssh
Start a service:
sudo systemctl start ssh
The exact service name can vary between Linux distributions.
31. uname — System Information
uname -a
This can display information about the kernel and system.
32. hostname — Show System Hostname
hostname
The hostname identifies the system on a network.
33. uptime — Check System Uptime
uptime
It displays how long the system has been running and provides load information.
34. df — Check Disk Space
Use df to view filesystem disk usage.
df -h
This is helpful when a server runs out of storage.
35. du — Check Directory Size
du -sh *
This gives a quick view of how much space directories or files consume.
36. free — Check Memory Usage
free -h
This shows memory and swap information in human-readable form.
37. ip — Network Configuration
The ip command is one of the most useful modern Linux networking utilities.
Show network interfaces:
ip addr
Show routing information:
ip route
Show link information:
ip link
38. ss — View Network Connections
ss is useful for viewing sockets and network connections.
ss -tuln
This can help you understand which TCP and UDP ports are listening on the local system.
This is particularly useful when troubleshooting unexpected services.
39. ping — Test Basic Network Reachability
ping example.com
Ping uses ICMP echo mechanisms to test reachability when the destination and network permit it.
Not receiving a ping response does not automatically mean a host is offline because firewalls or network policies may block ICMP.
40. traceroute — Examine Network Paths
traceroute can help investigate the path packets take through networks.
traceroute example.com
Some Linux distributions may use related tools or require separate package installation.
41. dig — Query DNS
dig is extremely useful when learning DNS.
dig example.com
Query a specific record type:
dig example.com MX
This is useful for understanding DNS behavior in a controlled troubleshooting or administrative context.
42. nslookup — DNS Lookup
nslookup example.com
It provides DNS lookup information and is useful for basic network troubleshooting.
43. curl — Make HTTP Requests
curl is one of the most important command-line tools for developers and security learners.
Request a webpage:
curl https://example.com
Show response headers:
curl -I https://example.com
It can be useful for learning HTTP requests, headers and APIs.
44. wget — Download Resources
wget https://example.com/file.zip
Use it carefully and only download software or files from trusted sources.
45. ssh — Secure Remote Login
SSH is widely used for securely accessing remote Linux systems.
ssh username@server.example.com
Example with an IP address:
ssh user@192.168.1.20
SSH is an essential skill for server administration and cybersecurity.
46. scp — Securely Copy Files
scp can transfer files using SSH.
scp report.txt user@192.168.1.20:/home/user/
Modern environments may also use alternatives such as SFTP or other secure transfer mechanisms.
47. history — View Command History
history
You can search your shell history with:
history | grep ssh
This can be useful when reviewing what commands you recently executed.
48. man — Read the Manual
One of the best Linux habits is learning to use documentation.
For example:
man ls
Or:
man ip
Instead of memorizing everything, learn how to look up the correct syntax and options.
49. sudo — Run a Command With Elevated Privileges
sudo allows an authorized user to run commands with elevated privileges according to the system's configuration.
Example:
sudo systemctl status ssh
Another example:
sudo apt update
Use elevated privileges carefully. A command executed with high privileges can make system-wide changes.
50. journalctl — Read systemd Logs
On systems using systemd, journalctl provides access to journal logs.
View recent entries:
journalctl
View recent entries from a particular service:
journalctl -u ssh
Follow new entries:
journalctl -f
Log analysis is an important skill in defensive cybersecurity and incident investigation.
Linux Commands Cheat Sheet
| Command | Purpose |
|---|---|
| pwd | Show current directory |
| ls | List files |
| cd | Change directory |
| mkdir | Create directory |
| touch | Create file |
| cp | Copy files |
| mv | Move/rename |
| rm | Remove files |
| cat | Display file |
| less | Read large files |
| head | Show beginning |
| tail | Show end/follow logs |
| grep | Search text |
| find | Find files |
| file | Identify file type |
| wc | Count text |
| sort | Sort text |
| uniq | Find repeated lines |
| cut | Extract fields |
| awk | Process text |
| sed | Transform text |
| chmod | Change permissions |
| chown | Change ownership |
| id | Show user/group IDs |
| whoami | Show current user |
| who | Show logged-in users |
| ps | View processes |
| top | Monitor processes |
| kill | Send process signal |
| systemctl | Manage services |
| uname | System information |
| hostname | Show hostname |
| uptime | Show uptime |
| df | Disk usage |
| du | Directory size |
| free | Memory usage |
| ip | Network configuration |
| ss | View sockets/connections |
| ping | Basic reachability test |
| traceroute | Trace network path |
| dig | DNS queries |
| nslookup | DNS lookup |
| curl | HTTP/API requests |
| wget | Download resources |
| ssh | Remote secure login |
| scp | Secure file transfer |
| history | Command history |
| man | Command documentation |
| sudo | Run authorized elevated commands |
| journalctl | Read systemd logs |
Useful Linux Command Combinations for Security Learning
Linux becomes much more powerful when commands are combined using pipes.
Find Repeated IP Addresses
cat access.log | awk '{print $1}' | sort | uniq -c | sort -nr
This example extracts the first field, counts occurrences and sorts them by frequency.
Find Errors in a Log
grep -i "error" application.log
Watch a Log in Real Time
tail -f application.log
Check Listening Network Ports
ss -tuln
Check a Website's HTTP Headers
curl -I https://example.com
These examples are useful for learning and troubleshooting your own systems or authorized environments.
Understanding Linux Permissions
One of the most important Linux security concepts is the permission model.
You may see output such as:
-rwxr-xr--
The permissions are divided into groups for:
- Owner
- Group
- Others
The basic permission types are:
- r = read
- w = write
- x = execute
Understanding these permissions is essential for secure Linux administration.
Understanding sudo
Many beginner security labs use commands that require administrative privileges.
For example:
sudo systemctl status ssh
Do not blindly add sudo to every command.
First understand:
- Why elevated privileges are required
- What the command will change
- What system it affects
- Whether the command is safe to execute
How These Commands Help in Cybersecurity
| Cybersecurity Task | Useful Commands |
|---|---|
| File investigation | ls, find, file, cat, less |
| Log analysis | grep, tail, head, awk, sed, journalctl |
| Network troubleshooting | ip, ss, ping, traceroute, dig, nslookup |
| System investigation | ps, top, uname, uptime, hostname |
| Access control | id, whoami, chmod, chown, sudo |
| Remote administration | ssh, scp |
| HTTP/API analysis | curl |
Beginner Linux Practice Lab
You can practice these commands without attacking real systems.
Create a small directory:
mkdir -p ~/cyber-lab/logs cd ~/cyber-lab
Create a sample log:
cat > logs/access.log <<EOF 192.168.1.10 login success 192.168.1.12 login failed 192.168.1.10 page request 192.168.1.12 login failed 192.168.1.15 login success EOF
Search for failed logins:
grep "failed" logs/access.log
Count the IP addresses:
awk '{print $1}' logs/access.log | sort | uniq -c
This kind of controlled exercise teaches command-line investigation without interacting with an external system.
Common Mistakes Linux Beginners Should Avoid
1. Running Commands Without Understanding Them
Do not copy commands from a random tutorial and execute them blindly.
2. Using sudo Unnecessarily
Administrative privileges increase the potential impact of mistakes.
3. Using rm Carelessly
Always verify the path before deleting files.
4. Ignoring File Permissions
Incorrect permissions can expose sensitive information or enable unintended changes.
5. Learning Only Offensive Tools
Linux knowledge is equally valuable for administration, monitoring and defense.
6. Memorizing Instead of Understanding
Knowing what a command does is more valuable than memorizing a long list of syntax options.
How to Memorize Linux Commands
Do not try to memorize all 50 commands in one day.
Group them by purpose.
Files: ls cd pwd mkdir cp mv rm Text: cat less head tail grep awk sed Processes: ps top kill Network: ip ss ping dig curl Security: chmod chown id whoami sudo Logs: journalctl tail grep Remote: ssh scp
Practice the commands repeatedly until they become familiar.
A 7-Day Linux Command Practice Plan
| Day | Topics |
|---|---|
| Day 1 | pwd, ls, cd, mkdir, touch |
| Day 2 | cp, mv, rm, cat, less, head, tail |
| Day 3 | grep, find, file, wc, sort, uniq, cut |
| Day 4 | chmod, chown, id, whoami, sudo |
| Day 5 | ps, top, kill, systemctl, uname, df, du, free |
| Day 6 | ip, ss, ping, traceroute, dig, nslookup, curl |
| Day 7 | ssh, scp, history, man, journalctl + revision |
Linux Commands vs Cybersecurity Tools
There is an important distinction between learning Linux and learning security tools.
Commands such as:
ip ss grep ps journalctl
are general Linux utilities.
Tools such as specialized vulnerability scanners, web security platforms and penetration-testing frameworks are separate security applications.
A strong cybersecurity learner should understand both the operating system and the specialized tools.
What Should You Learn After These Commands?
Once you are comfortable with these commands, continue with:
- Linux filesystem structure
- Users and groups
- Permissions
- Processes
- Services
- System logs
- Bash scripting
- Networking
- SSH security
- Web servers
- Security monitoring
Then move toward cybersecurity-specific tools and controlled labs.
Frequently Asked Questions
1. Do I need Linux for cybersecurity?
Not every cybersecurity role requires deep Linux knowledge, but Linux is highly useful across many security, infrastructure and technical roles.
2. Should I use Kali Linux to learn Linux?
You can, but you do not need Kali Linux to learn basic Linux administration. A beginner can learn many concepts on a general-purpose Linux distribution and later use security-focused environments for specialized practice.
3. How many Linux commands should a beginner memorize?
There is no required number. Focus on understanding a useful core set and learn to use man pages and documentation when you need additional options.
4. Which Linux command is most important for cybersecurity?
There is no single most important command. Commands such as grep, find, ps, ss, ip, journalctl, chmod and curl are particularly useful in different security and troubleshooting situations.
5. Is command-line knowledge better than a graphical interface?
Both have their uses. Command-line knowledge gives you powerful control, automation and visibility, particularly on remote servers.
6. Can these commands be used on Windows?
Windows has different native commands, but Linux tools can also be used through environments such as WSL or virtual machines.
7. Is sudo dangerous?
sudo itself is an administrative mechanism. The risk comes from what an elevated command is allowed to do. Always understand commands before running them with elevated privileges.
8. Why is grep important in cybersecurity?
grep can quickly search text for patterns, making it useful for analyzing logs, configuration files and other text-based data.
9. Is SSH secure?
SSH is designed for secure remote administration, but its security still depends on proper configuration, strong authentication and good system security practices.
10. Can I practice cybersecurity commands on public websites?
Do not test systems simply because they are publicly accessible. Practice against your own systems, intentionally vulnerable applications, training labs or systems where you have explicit authorization.
Final Thoughts
Learning Linux is one of the best technical foundations you can build for cybersecurity.
You do not need to become a Linux administrator overnight.
Start with:
Then practice those concepts in a safe lab.
The goal is not to memorize 50 commands just for the sake of memorization.
The real goal is to reach a point where you can open a terminal, investigate a system, understand what you are seeing and use the appropriate command to answer a technical question.
That ability will make the cybersecurity topics that come later much easier to understand.
Recommended Reading on CodeWithAV
- Cybersecurity Roadmap for Beginners
- What Is Ethical Hacking?
- What Is Penetration Testing?
- 50 Linux Commands for Cybersecurity Beginners
- What Is a Firewall?
Tip: Replace the homepage URLs above with the exact article URLs after the corresponding CodeWithAV posts are published.
Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.