← All cheat sheets

DD COMMAND

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

BASIC SYNTAX#

dd if=<input> of=<output> [options]

if=    Input file (source)
of=    Output file (destination)
bs=    Block size (e.g., 512, 1K, 1M, 4M)
count= Number of blocks to copy
skip=  Skip blocks at start of input
seek=  Skip blocks at start of output
status=progress  Show transfer progress

BASIC FILE OPERATIONS#

dd if=/path/to/source of=/path/to/dest                 # Basic file copy
dd if=file.txt of=copy.txt bs=4M                       # Copy with 4MB block size
dd if=/dev/zero of=/tmp/file bs=1M count=100           # Create 100MB file of zeros
dd if=/dev/urandom of=/tmp/random bs=1M count=10       # Create 10MB random file

DISK IMAGING#

dd if=/dev/sda of=/mnt/backup/disk.img                 # Create full disk image
dd if=/dev/sda1 of=/mnt/backup/partition.img           # Backup single partition
dd if=/dev/sda of=/dev/sdb                             # Clone disk to another disk
dd if=/dev/sda of=/dev/sdb status=progress             # Clone with progress display
dd if=/dev/cdrom of=/tmp/cd.iso                        # Create ISO from CD/DVD

RESTORING FROM IMAGES#

dd if=/mnt/backup/disk.img of=/dev/sda                 # Restore disk from image
dd if=/mnt/backup/partition.img of=/dev/sda1           # Restore partition
gzip -dc backup.img.gz | dd of=/dev/sda                # Restore from gzip image
bzip2 -dc backup.img.bz2 | dd of=/dev/sdb              # Restore from bzip2 image

COMPRESSED IMAGES#

dd if=/dev/sda bs=4M | gzip > disk.img.gz              # Create gzip compressed image
dd if=/dev/sda bs=4M | bzip2 -c > disk.img.bz2         # Create bzip2 compressed image
dd if=/dev/sda bs=4M | xz > disk.img.xz                # Create xz compressed image
dd if=/dev/sda bs=4M | zstd > disk.img.zst             # Create zstd compressed image

ENCRYPTED IMAGES#

dd if=/dev/sda bs=4M | openssl enc -aes-256-cbc -out encrypted.img       # Create encrypted image
openssl enc -d -aes-256-cbc -in encrypted.img | dd of=/dev/sdb           # Restore encrypted image
dd if=/dev/mapper/encrypted-sda1 of=/mnt/backup/encrypted.img            # Backup encrypted partition

SECURE DISK WIPING#

dd if=/dev/zero of=/dev/sdb                            # Wipe disk with zeros
dd if=/dev/urandom of=/dev/sdb                         # Wipe with random data (more secure)
dd if=/dev/zero of=/dev/sdb bs=1M conv=fdatasync       # Wipe SSD with sync
dd if=/dev/urandom of=/path/to/file bs=1M conv=notrunc # Securely overwrite specific file

BOOTABLE USB CREATION#

dd if=/path/to/linux.iso of=/dev/sdb bs=4M && sync     # Write ISO to USB
dd if=/path/to/image.img of=/dev/sdb bs=4M status=progress && sync       # With progress

BOOT SECTOR OPERATIONS#

dd if=/dev/sda of=/mnt/bootsector.bak bs=512 count=1   # Backup MBR (first 512 bytes)
dd if=/mnt/bootsector.bak of=/dev/sda bs=512 count=1   # Restore MBR
dd if=/dev/sda of=/mnt/mbr_full.bak bs=512 count=63    # Backup MBR + partition table
dd if=/dev/zero of=/dev/sda bs=512 count=1             # Wipe MBR (DANGEROUS!)

DATA RECOVERY#

dd if=/dev/sda of=/mnt/recovery.img conv=noerror,sync                    # Skip bad sectors
dd if=/dev/sda of=/mnt/recovery.img conv=noerror,sync 2> /tmp/error.log  # With error logging
dd if=/dev/sda of=/mnt/data bs=512 skip=10000 count=50000                # Recover from specific sector

NETWORK OPERATIONS#

# Clone disk over SSH
dd if=/dev/sda | ssh user@remote dd of=/dev/sdb

# Clone over SSH with compression
dd if=/dev/sda bs=4M | gzip | ssh user@remote "gzip -d | dd of=/dev/sdb"

# Clone using netcat (faster, no encryption)
# Receiver: nc -l 1234 | dd of=/dev/sdb
# Sender:   dd if=/dev/sda bs=4M | nc 192.168.1.2 1234

PERFORMANCE TESTING#

dd if=/dev/zero of=/tmp/test bs=1G count=1 oflag=dsync     # Test write speed
dd if=/tmp/test of=/dev/null bs=1G                         # Test read speed
dd if=/dev/zero of=/tmp/test bs=64k count=16k conv=fdatasync  # Sequential write test

PROGRESS MONITORING#

dd if=/dev/sda of=/dev/sdb status=progress                 # Built-in progress (modern dd)

# Using pv (pipe viewer)
pv -petra /dev/sda | dd of=/mnt/backup.img bs=4M

# Send USR1 signal for progress (older dd)
# In another terminal: kill -USR1 $(pgrep ^dd)

FORENSIC OPERATIONS#

# Forensic copy with MD5 hash verification
dd if=/dev/sda | tee >(md5sum > hash.txt) | dd of=/mnt/forensic.img

# Create forensic image with SHA256
dd if=/dev/sda bs=4M | tee /mnt/forensic.img | sha256sum > hash.txt

# Verify disk clone
dd if=/dev/sda bs=4M | md5sum
dd if=/dev/sdb bs=4M | md5sum

RAID OPERATIONS#

dd if=/dev/md0 of=/mnt/raid_backup.img bs=4M             # Backup RAID array
dd if=/mnt/raid_backup.img of=/dev/md0 bs=4M             # Restore RAID array

SPARSE FILES#

dd if=/dev/zero of=sparse.img bs=1 count=0 seek=10G      # Create 10GB sparse file
dd if=/dev/zero of=sparse.img bs=1 count=0 seek=100G     # Create 100GB sparse file

SPLITTING AND MERGING#

# Split into 1GB chunks
dd if=/mnt/large.img of=/mnt/split1.img bs=1G count=1
dd if=/mnt/large.img of=/mnt/split2.img bs=1G count=1 skip=1
dd if=/mnt/large.img of=/mnt/split3.img bs=1G count=1 skip=2

# Merge files back
cat split1.img split2.img split3.img > merged.img

EXTRACT SPECIFIC BYTES#

dd if=/dev/sda of=output bs=1 skip=512 count=1024        # Extract bytes 512-1535
dd if=file of=output bs=1M skip=10 count=5               # Extract MB 10-14
dd if=disk.img of=partition.img skip=2048 count=102400   # Extract partition from image

TEXT CONVERSIONS#

dd if=input.txt of=output.txt conv=ucase                 # Convert to uppercase
dd if=input.txt of=output.txt conv=lcase                 # Convert to lowercase
dd if=ascii.txt of=ebcdic.txt conv=ebcdic                # ASCII to EBCDIC
dd if=file.txt of=swapped.txt conv=swab                  # Swap byte pairs

MEMORY OPERATIONS#

dd if=/dev/mem of=/tmp/memdump bs=1M                     # Dump physical memory
dd if=/proc/kcore of=/tmp/kernel_mem bs=1M count=100     # Dump kernel memory

COMMON BLOCK SIZES#

bs=512      # Disk sector size
bs=4096     # Common filesystem block size
bs=1K       # 1 Kilobyte
bs=1M       # 1 Megabyte
bs=4M       # Good default for USB/disk operations
bs=64M      # Large transfers over fast media
bs=1G       # Very large transfers

CONVERSION FLAGS (conv=)#

noerror     Continue on read errors
sync        Pad blocks with zeros
notrunc     Don't truncate output file
fdatasync   Sync data before finishing
fsync       Sync data and metadata
swab        Swap every pair of bytes
ucase       Convert to uppercase
lcase       Convert to lowercase
ebcdic      ASCII to EBCDIC
ascii       EBCDIC to ASCII

OUTPUT FLAGS (oflag=)#

dsync       Synchronized I/O for data
sync        Synchronized I/O for data and metadata
direct      Direct I/O (bypass cache)
append      Append to output file

INPUT FLAGS (iflag=)#

direct      Direct I/O (bypass cache)
fullblock   Accumulate full blocks
skip_bytes  Treat skip as bytes not blocks
count_bytes Treat count as bytes not blocks

SAFETY TIPS#

# ALWAYS double-check device names!
lsblk                                    # List block devices
fdisk -l                                 # Show disk partitions
blkid                                    # Show device UUIDs

# Use sync after writing to removable media
dd if=image.iso of=/dev/sdb bs=4M && sync

# Verify with checksums
md5sum /dev/sda > before.md5
md5sum /dev/sdb > after.md5
diff before.md5 after.md5

QUICK REFERENCE#

# Full disk backup
dd if=/dev/sda of=/backup/disk.img bs=4M status=progress

# Restore disk
dd if=/backup/disk.img of=/dev/sda bs=4M status=progress

# Create bootable USB
dd if=linux.iso of=/dev/sdb bs=4M status=progress && sync

# Wipe disk securely
dd if=/dev/urandom of=/dev/sdb bs=4M status=progress

# Test disk speed
dd if=/dev/zero of=/tmp/test bs=1G count=1 oflag=dsync

WARNING: dd is called "disk destroyer" for a reason!
Always verify if= and of= parameters before executing.
Wrong device = data loss. There is no confirmation prompt.

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.