DD COMMAND
BASIC SYNTAX#
dd if=<input> of=<output> [options] if= Input file (source) of= Output file (destination) bs= Block size (e.g., 512, 1K, 1M, 4M) count= Number of blocks to copy skip= Skip blocks at start of input seek= Skip blocks at start of output status=progress Show transfer progress
BASIC FILE OPERATIONS#
dd if=/path/to/source of=/path/to/dest # Basic file copy dd if=file.txt of=copy.txt bs=4M # Copy with 4MB block size dd if=/dev/zero of=/tmp/file bs=1M count=100 # Create 100MB file of zeros dd if=/dev/urandom of=/tmp/random bs=1M count=10 # Create 10MB random file
DISK IMAGING#
dd if=/dev/sda of=/mnt/backup/disk.img # Create full disk image dd if=/dev/sda1 of=/mnt/backup/partition.img # Backup single partition dd if=/dev/sda of=/dev/sdb # Clone disk to another disk dd if=/dev/sda of=/dev/sdb status=progress # Clone with progress display dd if=/dev/cdrom of=/tmp/cd.iso # Create ISO from CD/DVD
RESTORING FROM IMAGES#
dd if=/mnt/backup/disk.img of=/dev/sda # Restore disk from image dd if=/mnt/backup/partition.img of=/dev/sda1 # Restore partition gzip -dc backup.img.gz | dd of=/dev/sda # Restore from gzip image bzip2 -dc backup.img.bz2 | dd of=/dev/sdb # Restore from bzip2 image
COMPRESSED IMAGES#
dd if=/dev/sda bs=4M | gzip > disk.img.gz # Create gzip compressed image dd if=/dev/sda bs=4M | bzip2 -c > disk.img.bz2 # Create bzip2 compressed image dd if=/dev/sda bs=4M | xz > disk.img.xz # Create xz compressed image dd if=/dev/sda bs=4M | zstd > disk.img.zst # Create zstd compressed image
ENCRYPTED IMAGES#
dd if=/dev/sda bs=4M | openssl enc -aes-256-cbc -out encrypted.img # Create encrypted image openssl enc -d -aes-256-cbc -in encrypted.img | dd of=/dev/sdb # Restore encrypted image dd if=/dev/mapper/encrypted-sda1 of=/mnt/backup/encrypted.img # Backup encrypted partition
SECURE DISK WIPING#
dd if=/dev/zero of=/dev/sdb # Wipe disk with zeros dd if=/dev/urandom of=/dev/sdb # Wipe with random data (more secure) dd if=/dev/zero of=/dev/sdb bs=1M conv=fdatasync # Wipe SSD with sync dd if=/dev/urandom of=/path/to/file bs=1M conv=notrunc # Securely overwrite specific file
BOOTABLE USB CREATION#
dd if=/path/to/linux.iso of=/dev/sdb bs=4M && sync # Write ISO to USB dd if=/path/to/image.img of=/dev/sdb bs=4M status=progress && sync # With progress
BOOT SECTOR OPERATIONS#
dd if=/dev/sda of=/mnt/bootsector.bak bs=512 count=1 # Backup MBR (first 512 bytes) dd if=/mnt/bootsector.bak of=/dev/sda bs=512 count=1 # Restore MBR dd if=/dev/sda of=/mnt/mbr_full.bak bs=512 count=63 # Backup MBR + partition table dd if=/dev/zero of=/dev/sda bs=512 count=1 # Wipe MBR (DANGEROUS!)
DATA RECOVERY#
dd if=/dev/sda of=/mnt/recovery.img conv=noerror,sync # Skip bad sectors dd if=/dev/sda of=/mnt/recovery.img conv=noerror,sync 2> /tmp/error.log # With error logging dd if=/dev/sda of=/mnt/data bs=512 skip=10000 count=50000 # Recover from specific sector
NETWORK OPERATIONS#
# Clone disk over SSH dd if=/dev/sda | ssh user@remote dd of=/dev/sdb # Clone over SSH with compression dd if=/dev/sda bs=4M | gzip | ssh user@remote "gzip -d | dd of=/dev/sdb" # Clone using netcat (faster, no encryption) # Receiver: nc -l 1234 | dd of=/dev/sdb # Sender: dd if=/dev/sda bs=4M | nc 192.168.1.2 1234
PERFORMANCE TESTING#
dd if=/dev/zero of=/tmp/test bs=1G count=1 oflag=dsync # Test write speed dd if=/tmp/test of=/dev/null bs=1G # Test read speed dd if=/dev/zero of=/tmp/test bs=64k count=16k conv=fdatasync # Sequential write test
PROGRESS MONITORING#
dd if=/dev/sda of=/dev/sdb status=progress # Built-in progress (modern dd) # Using pv (pipe viewer) pv -petra /dev/sda | dd of=/mnt/backup.img bs=4M # Send USR1 signal for progress (older dd) # In another terminal: kill -USR1 $(pgrep ^dd)
FORENSIC OPERATIONS#
# Forensic copy with MD5 hash verification dd if=/dev/sda | tee >(md5sum > hash.txt) | dd of=/mnt/forensic.img # Create forensic image with SHA256 dd if=/dev/sda bs=4M | tee /mnt/forensic.img | sha256sum > hash.txt # Verify disk clone dd if=/dev/sda bs=4M | md5sum dd if=/dev/sdb bs=4M | md5sum
RAID OPERATIONS#
dd if=/dev/md0 of=/mnt/raid_backup.img bs=4M # Backup RAID array dd if=/mnt/raid_backup.img of=/dev/md0 bs=4M # Restore RAID array
SPARSE FILES#
dd if=/dev/zero of=sparse.img bs=1 count=0 seek=10G # Create 10GB sparse file dd if=/dev/zero of=sparse.img bs=1 count=0 seek=100G # Create 100GB sparse file
SPLITTING AND MERGING#
# Split into 1GB chunks dd if=/mnt/large.img of=/mnt/split1.img bs=1G count=1 dd if=/mnt/large.img of=/mnt/split2.img bs=1G count=1 skip=1 dd if=/mnt/large.img of=/mnt/split3.img bs=1G count=1 skip=2 # Merge files back cat split1.img split2.img split3.img > merged.img
EXTRACT SPECIFIC BYTES#
dd if=/dev/sda of=output bs=1 skip=512 count=1024 # Extract bytes 512-1535 dd if=file of=output bs=1M skip=10 count=5 # Extract MB 10-14 dd if=disk.img of=partition.img skip=2048 count=102400 # Extract partition from image
TEXT CONVERSIONS#
dd if=input.txt of=output.txt conv=ucase # Convert to uppercase dd if=input.txt of=output.txt conv=lcase # Convert to lowercase dd if=ascii.txt of=ebcdic.txt conv=ebcdic # ASCII to EBCDIC dd if=file.txt of=swapped.txt conv=swab # Swap byte pairs
MEMORY OPERATIONS#
dd if=/dev/mem of=/tmp/memdump bs=1M # Dump physical memory dd if=/proc/kcore of=/tmp/kernel_mem bs=1M count=100 # Dump kernel memory
COMMON BLOCK SIZES#
bs=512 # Disk sector size bs=4096 # Common filesystem block size bs=1K # 1 Kilobyte bs=1M # 1 Megabyte bs=4M # Good default for USB/disk operations bs=64M # Large transfers over fast media bs=1G # Very large transfers
CONVERSION FLAGS (conv=)#
noerror Continue on read errors sync Pad blocks with zeros notrunc Don't truncate output file fdatasync Sync data before finishing fsync Sync data and metadata swab Swap every pair of bytes ucase Convert to uppercase lcase Convert to lowercase ebcdic ASCII to EBCDIC ascii EBCDIC to ASCII
OUTPUT FLAGS (oflag=)#
dsync Synchronized I/O for data sync Synchronized I/O for data and metadata direct Direct I/O (bypass cache) append Append to output file
INPUT FLAGS (iflag=)#
direct Direct I/O (bypass cache) fullblock Accumulate full blocks skip_bytes Treat skip as bytes not blocks count_bytes Treat count as bytes not blocks
SAFETY TIPS#
# ALWAYS double-check device names! lsblk # List block devices fdisk -l # Show disk partitions blkid # Show device UUIDs # Use sync after writing to removable media dd if=image.iso of=/dev/sdb bs=4M && sync # Verify with checksums md5sum /dev/sda > before.md5 md5sum /dev/sdb > after.md5 diff before.md5 after.md5
QUICK REFERENCE#
# Full disk backup dd if=/dev/sda of=/backup/disk.img bs=4M status=progress # Restore disk dd if=/backup/disk.img of=/dev/sda bs=4M status=progress # Create bootable USB dd if=linux.iso of=/dev/sdb bs=4M status=progress && sync # Wipe disk securely dd if=/dev/urandom of=/dev/sdb bs=4M status=progress # Test disk speed dd if=/dev/zero of=/tmp/test bs=1G count=1 oflag=dsync WARNING: dd is called "disk destroyer" for a reason! Always verify if= and of= parameters before executing. Wrong device = data loss. There is no confirmation prompt.
DD COMMAND CHEATSHEET ===================== Source: https://cheatsheet.johlem.net BASIC SYNTAX ------------ dd if=<input> of=<output> [options] if= Input file (source) of= Output file (destination) bs= Block size (e.g., 512, 1K, 1M, 4M) count= Number of blocks to copy skip= Skip blocks at start of input seek= Skip blocks at start of output status=progress Show transfer progress BASIC FILE OPERATIONS --------------------- dd if=/path/to/source of=/path/to/dest # Basic file copy dd if=file.txt of=copy.txt bs=4M # Copy with 4MB block size dd if=/dev/zero of=/tmp/file bs=1M count=100 # Create 100MB file of zeros dd if=/dev/urandom of=/tmp/random bs=1M count=10 # Create 10MB random file DISK IMAGING ------------ dd if=/dev/sda of=/mnt/backup/disk.img # Create full disk image dd if=/dev/sda1 of=/mnt/backup/partition.img # Backup single partition dd if=/dev/sda of=/dev/sdb # Clone disk to another disk dd if=/dev/sda of=/dev/sdb status=progress # Clone with progress display dd if=/dev/cdrom of=/tmp/cd.iso # Create ISO from CD/DVD RESTORING FROM IMAGES --------------------- dd if=/mnt/backup/disk.img of=/dev/sda # Restore disk from image dd if=/mnt/backup/partition.img of=/dev/sda1 # Restore partition gzip -dc backup.img.gz | dd of=/dev/sda # Restore from gzip image bzip2 -dc backup.img.bz2 | dd of=/dev/sdb # Restore from bzip2 image COMPRESSED IMAGES ----------------- dd if=/dev/sda bs=4M | gzip > disk.img.gz # Create gzip compressed image dd if=/dev/sda bs=4M | bzip2 -c > disk.img.bz2 # Create bzip2 compressed image dd if=/dev/sda bs=4M | xz > disk.img.xz # Create xz compressed image dd if=/dev/sda bs=4M | zstd > disk.img.zst # Create zstd compressed image ENCRYPTED IMAGES ---------------- dd if=/dev/sda bs=4M | openssl enc -aes-256-cbc -out encrypted.img # Create encrypted image openssl enc -d -aes-256-cbc -in encrypted.img | dd of=/dev/sdb # Restore encrypted image dd if=/dev/mapper/encrypted-sda1 of=/mnt/backup/encrypted.img # Backup encrypted partition SECURE DISK WIPING ------------------ dd if=/dev/zero of=/dev/sdb # Wipe disk with zeros dd if=/dev/urandom of=/dev/sdb # Wipe with random data (more secure) dd if=/dev/zero of=/dev/sdb bs=1M conv=fdatasync # Wipe SSD with sync dd if=/dev/urandom of=/path/to/file bs=1M conv=notrunc # Securely overwrite specific file BOOTABLE USB CREATION --------------------- dd if=/path/to/linux.iso of=/dev/sdb bs=4M && sync # Write ISO to USB dd if=/path/to/image.img of=/dev/sdb bs=4M status=progress && sync # With progress BOOT SECTOR OPERATIONS ---------------------- dd if=/dev/sda of=/mnt/bootsector.bak bs=512 count=1 # Backup MBR (first 512 bytes) dd if=/mnt/bootsector.bak of=/dev/sda bs=512 count=1 # Restore MBR dd if=/dev/sda of=/mnt/mbr_full.bak bs=512 count=63 # Backup MBR + partition table dd if=/dev/zero of=/dev/sda bs=512 count=1 # Wipe MBR (DANGEROUS!) DATA RECOVERY ------------- dd if=/dev/sda of=/mnt/recovery.img conv=noerror,sync # Skip bad sectors dd if=/dev/sda of=/mnt/recovery.img conv=noerror,sync 2> /tmp/error.log # With error logging dd if=/dev/sda of=/mnt/data bs=512 skip=10000 count=50000 # Recover from specific sector NETWORK OPERATIONS ------------------ # Clone disk over SSH dd if=/dev/sda | ssh user@remote dd of=/dev/sdb # Clone over SSH with compression dd if=/dev/sda bs=4M | gzip | ssh user@remote "gzip -d | dd of=/dev/sdb" # Clone using netcat (faster, no encryption) # Receiver: nc -l 1234 | dd of=/dev/sdb # Sender: dd if=/dev/sda bs=4M | nc 192.168.1.2 1234 PERFORMANCE TESTING ------------------- dd if=/dev/zero of=/tmp/test bs=1G count=1 oflag=dsync # Test write speed dd if=/tmp/test of=/dev/null bs=1G # Test read speed dd if=/dev/zero of=/tmp/test bs=64k count=16k conv=fdatasync # Sequential write test PROGRESS MONITORING ------------------- dd if=/dev/sda of=/dev/sdb status=progress # Built-in progress (modern dd) # Using pv (pipe viewer) pv -petra /dev/sda | dd of=/mnt/backup.img bs=4M # Send USR1 signal for progress (older dd) # In another terminal: kill -USR1 $(pgrep ^dd) FORENSIC OPERATIONS ------------------- # Forensic copy with MD5 hash verification dd if=/dev/sda | tee >(md5sum > hash.txt) | dd of=/mnt/forensic.img # Create forensic image with SHA256 dd if=/dev/sda bs=4M | tee /mnt/forensic.img | sha256sum > hash.txt # Verify disk clone dd if=/dev/sda bs=4M | md5sum dd if=/dev/sdb bs=4M | md5sum RAID OPERATIONS --------------- dd if=/dev/md0 of=/mnt/raid_backup.img bs=4M # Backup RAID array dd if=/mnt/raid_backup.img of=/dev/md0 bs=4M # Restore RAID array SPARSE FILES ------------ dd if=/dev/zero of=sparse.img bs=1 count=0 seek=10G # Create 10GB sparse file dd if=/dev/zero of=sparse.img bs=1 count=0 seek=100G # Create 100GB sparse file SPLITTING AND MERGING --------------------- # Split into 1GB chunks dd if=/mnt/large.img of=/mnt/split1.img bs=1G count=1 dd if=/mnt/large.img of=/mnt/split2.img bs=1G count=1 skip=1 dd if=/mnt/large.img of=/mnt/split3.img bs=1G count=1 skip=2 # Merge files back cat split1.img split2.img split3.img > merged.img EXTRACT SPECIFIC BYTES ---------------------- dd if=/dev/sda of=output bs=1 skip=512 count=1024 # Extract bytes 512-1535 dd if=file of=output bs=1M skip=10 count=5 # Extract MB 10-14 dd if=disk.img of=partition.img skip=2048 count=102400 # Extract partition from image TEXT CONVERSIONS ---------------- dd if=input.txt of=output.txt conv=ucase # Convert to uppercase dd if=input.txt of=output.txt conv=lcase # Convert to lowercase dd if=ascii.txt of=ebcdic.txt conv=ebcdic # ASCII to EBCDIC dd if=file.txt of=swapped.txt conv=swab # Swap byte pairs MEMORY OPERATIONS ----------------- dd if=/dev/mem of=/tmp/memdump bs=1M # Dump physical memory dd if=/proc/kcore of=/tmp/kernel_mem bs=1M count=100 # Dump kernel memory COMMON BLOCK SIZES ------------------ bs=512 # Disk sector size bs=4096 # Common filesystem block size bs=1K # 1 Kilobyte bs=1M # 1 Megabyte bs=4M # Good default for USB/disk operations bs=64M # Large transfers over fast media bs=1G # Very large transfers CONVERSION FLAGS (conv=) ------------------------ noerror Continue on read errors sync Pad blocks with zeros notrunc Don't truncate output file fdatasync Sync data before finishing fsync Sync data and metadata swab Swap every pair of bytes ucase Convert to uppercase lcase Convert to lowercase ebcdic ASCII to EBCDIC ascii EBCDIC to ASCII OUTPUT FLAGS (oflag=) --------------------- dsync Synchronized I/O for data sync Synchronized I/O for data and metadata direct Direct I/O (bypass cache) append Append to output file INPUT FLAGS (iflag=) -------------------- direct Direct I/O (bypass cache) fullblock Accumulate full blocks skip_bytes Treat skip as bytes not blocks count_bytes Treat count as bytes not blocks SAFETY TIPS ----------- # ALWAYS double-check device names! lsblk # List block devices fdisk -l # Show disk partitions blkid # Show device UUIDs # Use sync after writing to removable media dd if=image.iso of=/dev/sdb bs=4M && sync # Verify with checksums md5sum /dev/sda > before.md5 md5sum /dev/sdb > after.md5 diff before.md5 after.md5 QUICK REFERENCE --------------- # Full disk backup dd if=/dev/sda of=/backup/disk.img bs=4M status=progress # Restore disk dd if=/backup/disk.img of=/dev/sda bs=4M status=progress # Create bootable USB dd if=linux.iso of=/dev/sdb bs=4M status=progress && sync # Wipe disk securely dd if=/dev/urandom of=/dev/sdb bs=4M status=progress # Test disk speed dd if=/dev/zero of=/tmp/test bs=1G count=1 oflag=dsync WARNING: dd is called "disk destroyer" for a reason! Always verify if= and of= parameters before executing. Wrong device = data loss. There is no confirmation prompt.
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.