CUT COMMAND
cut extracts sections from each line of input. Works with fields (columns), characters, or bytes.
BASIC SYNTAX#
cut [OPTIONS] [FILE] cut -f FIELDS file # Extract fields cut -c CHARS file # Extract characters cut -b BYTES file # Extract bytes
FIELD EXTRACTION (-f)#
cut -f1 file # First field cut -f2 file # Second field cut -f1,3 file # Fields 1 and 3 cut -f1-3 file # Fields 1 through 3 cut -f2- file # Field 2 to end cut -f-3 file # Start to field 3 cut -f1,3-5,7 file # Mixed selection # Default delimiter is TAB # Specify delimiter with -d cut -d':' -f1 /etc/passwd # Colon delimiter cut -d',' -f2 data.csv # Comma (CSV) cut -d' ' -f1 file # Space cut -d$'\t' -f1 file # Explicit tab
CHARACTER EXTRACTION (-c)#
cut -c1 file # First character cut -c1-5 file # Characters 1-5 cut -c5- file # Character 5 to end cut -c-10 file # First 10 characters cut -c1,3,5 file # Characters 1, 3, 5 cut -c1-5,10-15 file # Ranges
BYTE EXTRACTION (-b)#
cut -b1 file # First byte cut -b1-10 file # Bytes 1-10 cut -b5- file # Byte 5 to end # For UTF-8, use -c not -b # -b counts bytes (may split multibyte chars) # -c counts characters (UTF-8 safe)
OPTIONS#
-d DELIM Field delimiter (default: TAB) -f FIELDS Select fields -c CHARS Select characters -b BYTES Select bytes -s Only lines with delimiter (skip others) --complement Invert selection --output-delimiter=STR Change output delimiter
COMMON EXAMPLES#
# Extract username from /etc/passwd cut -d':' -f1 /etc/passwd # Extract username and shell cut -d':' -f1,7 /etc/passwd # Extract from CSV cut -d',' -f2,4 data.csv # First 10 characters cut -c1-10 file # Remove first character cut -c2- file # Get file extensions ls | cut -d'.' -f2 # Extract IP from log cat access.log | cut -d' ' -f1
OUTPUT DELIMITER#
# Change output delimiter cut -d':' -f1,7 --output-delimiter=' ' /etc/passwd # john /bin/bash cut -d',' -f1-3 --output-delimiter=$'\t' data.csv
COMPLEMENT (INVERSE)#
# Everything EXCEPT field 2 cut -d':' -f2 --complement /etc/passwd # Everything except characters 1-5 cut -c1-5 --complement file
SUPPRESS LINES#
# Only show lines containing delimiter cut -d':' -f1 -s file # Without -s: lines without delimiter print as-is # With -s: lines without delimiter are suppressed
PIPING EXAMPLES#
# Get PIDs from ps ps aux | cut -c10-15 # Extract specific fields from command output df -h | cut -d' ' -f1 # Chain with other tools cat file | cut -d',' -f1 | sort | uniq # Extract from environment echo $PATH | cut -d':' -f1 # Get domain from URLs cat urls.txt | cut -d'/' -f3
PRACTICAL EXAMPLES#
# List all users cut -d':' -f1 /etc/passwd # Users with bash shell grep '/bin/bash' /etc/passwd | cut -d':' -f1 # Extract error codes from log grep ERROR app.log | cut -d'[' -f2 | cut -d']' -f1 # Get IP addresses cat access.log | cut -d' ' -f1 | sort | uniq -c # CSV to specific columns cut -d',' -f1,3,5 data.csv > subset.csv # Remove last field rev file | cut -d',' -f2- | rev # Extract filename from path echo "/path/to/file.txt" | rev | cut -d'/' -f1 | rev # Or: basename /path/to/file.txt # Fixed width data cut -c1-10,20-30,50-60 fixedwidth.txt # Tab-separated values cut -f1,3 data.tsv
COMPARISON WITH AWK#
# cut is simpler and faster for basic extraction
cut -d':' -f1 /etc/passwd
# awk is more powerful for complex operations
awk -F':' '{print $1}' /etc/passwd
# awk can do calculations, conditions
awk -F':' '$3 > 1000 {print $1}' /etc/passwd
# cut cannot:
# - Handle multiple delimiters
# - Do regex matching
# - Perform calculations
# - Conditional output
HANDLING SPACES#
# Multiple spaces as one delimiter - use awk or tr
# cut treats each space as delimiter
# Compress multiple spaces first
cat file | tr -s ' ' | cut -d' ' -f2
# Or use awk
awk '{print $2}' file
EDGE CASES#
# Empty fields echo "a,,c" | cut -d',' -f2 # Output: (empty) # Trailing delimiter echo "a,b,c," | cut -d',' -f4 # Output: (empty) # No delimiter in line echo "no comma here" | cut -d',' -f1 # Output: no comma here (entire line) # With -s flag echo "no comma here" | cut -d',' -f1 -s # Output: (nothing - line suppressed)
COMBINING WITH OTHER TOOLS#
# Sort by field cut -d',' -f3 data.csv | sort -n # Count unique values cut -d':' -f7 /etc/passwd | sort | uniq -c # Filter then cut grep "ERROR" log | cut -d' ' -f1,2 # Cut then filter cut -d':' -f1,3 /etc/passwd | grep "^root" # Multiple cuts echo "a:b:c:d:e" | cut -d':' -f1-3 | cut -d':' -f2
QUICK REFERENCE#
cut -f1 file First field (tab delimited) cut -f1,3 file Fields 1 and 3 cut -f1-3 file Fields 1 through 3 cut -f2- file Field 2 to end cut -d':' -f1 file Colon delimiter, field 1 cut -c1-10 file Characters 1-10 cut -c5- file Character 5 to end cut -d',' -f2 --output-delimiter=' ' Change output cut -f1 --complement Everything except field 1 cut -d':' -f1 -s Suppress lines without delimiter
CUT COMMAND CHEATSHEET
======================
Source: https://cheatsheet.johlem.net
cut extracts sections from each line of input.
Works with fields (columns), characters, or bytes.
BASIC SYNTAX
------------
cut [OPTIONS] [FILE]
cut -f FIELDS file # Extract fields
cut -c CHARS file # Extract characters
cut -b BYTES file # Extract bytes
FIELD EXTRACTION (-f)
---------------------
cut -f1 file # First field
cut -f2 file # Second field
cut -f1,3 file # Fields 1 and 3
cut -f1-3 file # Fields 1 through 3
cut -f2- file # Field 2 to end
cut -f-3 file # Start to field 3
cut -f1,3-5,7 file # Mixed selection
# Default delimiter is TAB
# Specify delimiter with -d
cut -d':' -f1 /etc/passwd # Colon delimiter
cut -d',' -f2 data.csv # Comma (CSV)
cut -d' ' -f1 file # Space
cut -d$'\t' -f1 file # Explicit tab
CHARACTER EXTRACTION (-c)
-------------------------
cut -c1 file # First character
cut -c1-5 file # Characters 1-5
cut -c5- file # Character 5 to end
cut -c-10 file # First 10 characters
cut -c1,3,5 file # Characters 1, 3, 5
cut -c1-5,10-15 file # Ranges
BYTE EXTRACTION (-b)
--------------------
cut -b1 file # First byte
cut -b1-10 file # Bytes 1-10
cut -b5- file # Byte 5 to end
# For UTF-8, use -c not -b
# -b counts bytes (may split multibyte chars)
# -c counts characters (UTF-8 safe)
OPTIONS
-------
-d DELIM Field delimiter (default: TAB)
-f FIELDS Select fields
-c CHARS Select characters
-b BYTES Select bytes
-s Only lines with delimiter (skip others)
--complement Invert selection
--output-delimiter=STR Change output delimiter
COMMON EXAMPLES
---------------
# Extract username from /etc/passwd
cut -d':' -f1 /etc/passwd
# Extract username and shell
cut -d':' -f1,7 /etc/passwd
# Extract from CSV
cut -d',' -f2,4 data.csv
# First 10 characters
cut -c1-10 file
# Remove first character
cut -c2- file
# Get file extensions
ls | cut -d'.' -f2
# Extract IP from log
cat access.log | cut -d' ' -f1
OUTPUT DELIMITER
----------------
# Change output delimiter
cut -d':' -f1,7 --output-delimiter=' ' /etc/passwd
# john /bin/bash
cut -d',' -f1-3 --output-delimiter=$'\t' data.csv
COMPLEMENT (INVERSE)
--------------------
# Everything EXCEPT field 2
cut -d':' -f2 --complement /etc/passwd
# Everything except characters 1-5
cut -c1-5 --complement file
SUPPRESS LINES
--------------
# Only show lines containing delimiter
cut -d':' -f1 -s file
# Without -s: lines without delimiter print as-is
# With -s: lines without delimiter are suppressed
PIPING EXAMPLES
---------------
# Get PIDs from ps
ps aux | cut -c10-15
# Extract specific fields from command output
df -h | cut -d' ' -f1
# Chain with other tools
cat file | cut -d',' -f1 | sort | uniq
# Extract from environment
echo $PATH | cut -d':' -f1
# Get domain from URLs
cat urls.txt | cut -d'/' -f3
PRACTICAL EXAMPLES
------------------
# List all users
cut -d':' -f1 /etc/passwd
# Users with bash shell
grep '/bin/bash' /etc/passwd | cut -d':' -f1
# Extract error codes from log
grep ERROR app.log | cut -d'[' -f2 | cut -d']' -f1
# Get IP addresses
cat access.log | cut -d' ' -f1 | sort | uniq -c
# CSV to specific columns
cut -d',' -f1,3,5 data.csv > subset.csv
# Remove last field
rev file | cut -d',' -f2- | rev
# Extract filename from path
echo "/path/to/file.txt" | rev | cut -d'/' -f1 | rev
# Or: basename /path/to/file.txt
# Fixed width data
cut -c1-10,20-30,50-60 fixedwidth.txt
# Tab-separated values
cut -f1,3 data.tsv
COMPARISON WITH AWK
-------------------
# cut is simpler and faster for basic extraction
cut -d':' -f1 /etc/passwd
# awk is more powerful for complex operations
awk -F':' '{print $1}' /etc/passwd
# awk can do calculations, conditions
awk -F':' '$3 > 1000 {print $1}' /etc/passwd
# cut cannot:
# - Handle multiple delimiters
# - Do regex matching
# - Perform calculations
# - Conditional output
HANDLING SPACES
---------------
# Multiple spaces as one delimiter - use awk or tr
# cut treats each space as delimiter
# Compress multiple spaces first
cat file | tr -s ' ' | cut -d' ' -f2
# Or use awk
awk '{print $2}' file
EDGE CASES
----------
# Empty fields
echo "a,,c" | cut -d',' -f2
# Output: (empty)
# Trailing delimiter
echo "a,b,c," | cut -d',' -f4
# Output: (empty)
# No delimiter in line
echo "no comma here" | cut -d',' -f1
# Output: no comma here (entire line)
# With -s flag
echo "no comma here" | cut -d',' -f1 -s
# Output: (nothing - line suppressed)
COMBINING WITH OTHER TOOLS
--------------------------
# Sort by field
cut -d',' -f3 data.csv | sort -n
# Count unique values
cut -d':' -f7 /etc/passwd | sort | uniq -c
# Filter then cut
grep "ERROR" log | cut -d' ' -f1,2
# Cut then filter
cut -d':' -f1,3 /etc/passwd | grep "^root"
# Multiple cuts
echo "a:b:c:d:e" | cut -d':' -f1-3 | cut -d':' -f2
QUICK REFERENCE
---------------
cut -f1 file First field (tab delimited)
cut -f1,3 file Fields 1 and 3
cut -f1-3 file Fields 1 through 3
cut -f2- file Field 2 to end
cut -d':' -f1 file Colon delimiter, field 1
cut -c1-10 file Characters 1-10
cut -c5- file Character 5 to end
cut -d',' -f2 --output-delimiter=' ' Change output
cut -f1 --complement Everything except field 1
cut -d':' -f1 -s Suppress lines without delimiter
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.