← All cheat sheets

CUT COMMAND

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

cut extracts sections from each line of input.
Works with fields (columns), characters, or bytes.

BASIC SYNTAX#

cut [OPTIONS] [FILE]
cut -f FIELDS file          # Extract fields
cut -c CHARS file           # Extract characters
cut -b BYTES file           # Extract bytes

FIELD EXTRACTION (-f)#

cut -f1 file                # First field
cut -f2 file                # Second field
cut -f1,3 file              # Fields 1 and 3
cut -f1-3 file              # Fields 1 through 3
cut -f2- file               # Field 2 to end
cut -f-3 file               # Start to field 3
cut -f1,3-5,7 file          # Mixed selection

# Default delimiter is TAB
# Specify delimiter with -d
cut -d':' -f1 /etc/passwd   # Colon delimiter
cut -d',' -f2 data.csv      # Comma (CSV)
cut -d' ' -f1 file          # Space
cut -d$'\t' -f1 file        # Explicit tab

CHARACTER EXTRACTION (-c)#

cut -c1 file                # First character
cut -c1-5 file              # Characters 1-5
cut -c5- file               # Character 5 to end
cut -c-10 file              # First 10 characters
cut -c1,3,5 file            # Characters 1, 3, 5
cut -c1-5,10-15 file        # Ranges

BYTE EXTRACTION (-b)#

cut -b1 file                # First byte
cut -b1-10 file             # Bytes 1-10
cut -b5- file               # Byte 5 to end

# For UTF-8, use -c not -b
# -b counts bytes (may split multibyte chars)
# -c counts characters (UTF-8 safe)

OPTIONS#

-d DELIM        Field delimiter (default: TAB)
-f FIELDS       Select fields
-c CHARS        Select characters
-b BYTES        Select bytes
-s              Only lines with delimiter (skip others)
--complement    Invert selection
--output-delimiter=STR    Change output delimiter

COMMON EXAMPLES#

# Extract username from /etc/passwd
cut -d':' -f1 /etc/passwd

# Extract username and shell
cut -d':' -f1,7 /etc/passwd

# Extract from CSV
cut -d',' -f2,4 data.csv

# First 10 characters
cut -c1-10 file

# Remove first character
cut -c2- file

# Get file extensions
ls | cut -d'.' -f2

# Extract IP from log
cat access.log | cut -d' ' -f1

OUTPUT DELIMITER#

# Change output delimiter
cut -d':' -f1,7 --output-delimiter=' ' /etc/passwd
# john /bin/bash

cut -d',' -f1-3 --output-delimiter=$'\t' data.csv

COMPLEMENT (INVERSE)#

# Everything EXCEPT field 2
cut -d':' -f2 --complement /etc/passwd

# Everything except characters 1-5
cut -c1-5 --complement file

SUPPRESS LINES#

# Only show lines containing delimiter
cut -d':' -f1 -s file

# Without -s: lines without delimiter print as-is
# With -s: lines without delimiter are suppressed

PIPING EXAMPLES#

# Get PIDs from ps
ps aux | cut -c10-15

# Extract specific fields from command output
df -h | cut -d' ' -f1

# Chain with other tools
cat file | cut -d',' -f1 | sort | uniq

# Extract from environment
echo $PATH | cut -d':' -f1

# Get domain from URLs
cat urls.txt | cut -d'/' -f3

PRACTICAL EXAMPLES#

# List all users
cut -d':' -f1 /etc/passwd

# Users with bash shell
grep '/bin/bash' /etc/passwd | cut -d':' -f1

# Extract error codes from log
grep ERROR app.log | cut -d'[' -f2 | cut -d']' -f1

# Get IP addresses
cat access.log | cut -d' ' -f1 | sort | uniq -c

# CSV to specific columns
cut -d',' -f1,3,5 data.csv > subset.csv

# Remove last field
rev file | cut -d',' -f2- | rev

# Extract filename from path
echo "/path/to/file.txt" | rev | cut -d'/' -f1 | rev
# Or: basename /path/to/file.txt

# Fixed width data
cut -c1-10,20-30,50-60 fixedwidth.txt

# Tab-separated values
cut -f1,3 data.tsv

COMPARISON WITH AWK#

# cut is simpler and faster for basic extraction
cut -d':' -f1 /etc/passwd

# awk is more powerful for complex operations
awk -F':' '{print $1}' /etc/passwd

# awk can do calculations, conditions
awk -F':' '$3 > 1000 {print $1}' /etc/passwd

# cut cannot:
# - Handle multiple delimiters
# - Do regex matching
# - Perform calculations
# - Conditional output

HANDLING SPACES#

# Multiple spaces as one delimiter - use awk or tr
# cut treats each space as delimiter

# Compress multiple spaces first
cat file | tr -s ' ' | cut -d' ' -f2

# Or use awk
awk '{print $2}' file

EDGE CASES#

# Empty fields
echo "a,,c" | cut -d',' -f2
# Output: (empty)

# Trailing delimiter
echo "a,b,c," | cut -d',' -f4
# Output: (empty)

# No delimiter in line
echo "no comma here" | cut -d',' -f1
# Output: no comma here (entire line)

# With -s flag
echo "no comma here" | cut -d',' -f1 -s
# Output: (nothing - line suppressed)

COMBINING WITH OTHER TOOLS#

# Sort by field
cut -d',' -f3 data.csv | sort -n

# Count unique values
cut -d':' -f7 /etc/passwd | sort | uniq -c

# Filter then cut
grep "ERROR" log | cut -d' ' -f1,2

# Cut then filter
cut -d':' -f1,3 /etc/passwd | grep "^root"

# Multiple cuts
echo "a:b:c:d:e" | cut -d':' -f1-3 | cut -d':' -f2

QUICK REFERENCE#

cut -f1 file            First field (tab delimited)
cut -f1,3 file          Fields 1 and 3
cut -f1-3 file          Fields 1 through 3
cut -f2- file           Field 2 to end
cut -d':' -f1 file      Colon delimiter, field 1
cut -c1-10 file         Characters 1-10
cut -c5- file           Character 5 to end
cut -d',' -f2 --output-delimiter=' '    Change output
cut -f1 --complement    Everything except field 1
cut -d':' -f1 -s        Suppress lines without delimiter

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.