GREP
BASIC USAGE#
grep "pattern" file # Search for pattern in file grep "pattern" file1 file2 # Search in multiple files grep "pattern" * # Search in all files grep "pattern" *.txt # Search in .txt files cat file | grep "pattern" # Pipe input to grep
COMMON OPTIONS#
grep -i "pattern" file # Case insensitive grep -v "pattern" file # Invert match (exclude) grep -n "pattern" file # Show line numbers grep -c "pattern" file # Count matches grep -l "pattern" * # List files with matches grep -L "pattern" * # List files without matches grep -w "pattern" file # Match whole words only grep -x "pattern" file # Match whole lines only grep -o "pattern" file # Show only matching part grep -q "pattern" file # Quiet mode (for scripts)
CONTEXT OPTIONS#
grep -B 3 "pattern" file # Show 3 lines before match grep -A 3 "pattern" file # Show 3 lines after match grep -C 3 "pattern" file # Show 3 lines before and after
RECURSIVE SEARCH#
grep -r "pattern" directory/ # Recursive search grep -R "pattern" directory/ # Recursive, follow symlinks grep -rn "pattern" . # Recursive with line numbers grep -rl "pattern" . # List matching files
REGEX PATTERNS#
grep "^start" file # Lines starting with "start" grep "end$" file # Lines ending with "end" grep "^$" file # Empty lines grep "." file # Any single character grep "a*" file # Zero or more 'a' grep "a+" file # One or more 'a' (extended) grep "a?" file # Zero or one 'a' (extended) grep "[abc]" file # Any of a, b, or c grep "[^abc]" file # Not a, b, or c grep "[0-9]" file # Any digit grep "[a-z]" file # Any lowercase letter grep "[A-Z]" file # Any uppercase letter grep "\." file # Literal dot (escaped) grep "a\|b" file # a OR b
EXTENDED REGEX (-E or egrep)#
grep -E "pattern" file # Extended regex
egrep "pattern" file # Same as grep -E
grep -E "a|b" file # a OR b
grep -E "a{3}" file # Exactly 3 'a's
grep -E "a{2,4}" file # 2 to 4 'a's
grep -E "a{2,}" file # 2 or more 'a's
grep -E "(ab)+" file # One or more "ab"
PERL REGEX (-P)#
grep -P "\d+" file # Digits (Perl regex) grep -P "\w+" file # Word characters grep -P "\s+" file # Whitespace grep -P "(?<=prefix)" file # Lookbehind grep -P "(?=suffix)" file # Lookahead
PRACTICAL EXAMPLES#
# Find IP addresses
grep -E "[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}" file
# Find email addresses
grep -E "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b" file
# Find URLs
grep -E "https?://[^\s]+" file
# Find lines with numbers
grep "[0-9]" file
# Find blank lines
grep "^$" file
# Count lines with pattern
grep -c "error" logfile
# Find files containing pattern
grep -rl "TODO" --include="*.py" .
# Exclude directories
grep -r "pattern" --exclude-dir={.git,node_modules} .
# Exclude files
grep -r "pattern" --exclude="*.log" .
# Find and replace (with sed)
grep -l "old" * | xargs sed -i 's/old/new/g'
# Multiple patterns
grep -e "pattern1" -e "pattern2" file
# From file of patterns
grep -f patterns.txt file
# Binary files
grep -a "pattern" binary_file # Treat as text
grep -I "pattern" * # Ignore binary files
USEFUL COMBINATIONS#
# Find in code, skip binaries
grep -rIn "function" --include="*.js" .
# Find errors in logs
grep -i "error\|fail\|critical" /var/log/syslog
# Find processes
ps aux | grep "apache"
# Find open ports
netstat -tuln | grep "LISTEN"
# Find large files
ls -la | grep -E "^-.*[0-9]{8,}"
# Configuration values
grep -v "^#" config.conf | grep -v "^$"
EXIT CODES#
0 = Match found 1 = No match found 2 = Error occurred
GREP CHEATSHEET
===============
Source: https://cheatsheet.johlem.net
BASIC USAGE
-----------
grep "pattern" file # Search for pattern in file
grep "pattern" file1 file2 # Search in multiple files
grep "pattern" * # Search in all files
grep "pattern" *.txt # Search in .txt files
cat file | grep "pattern" # Pipe input to grep
COMMON OPTIONS
--------------
grep -i "pattern" file # Case insensitive
grep -v "pattern" file # Invert match (exclude)
grep -n "pattern" file # Show line numbers
grep -c "pattern" file # Count matches
grep -l "pattern" * # List files with matches
grep -L "pattern" * # List files without matches
grep -w "pattern" file # Match whole words only
grep -x "pattern" file # Match whole lines only
grep -o "pattern" file # Show only matching part
grep -q "pattern" file # Quiet mode (for scripts)
CONTEXT OPTIONS
---------------
grep -B 3 "pattern" file # Show 3 lines before match
grep -A 3 "pattern" file # Show 3 lines after match
grep -C 3 "pattern" file # Show 3 lines before and after
RECURSIVE SEARCH
----------------
grep -r "pattern" directory/ # Recursive search
grep -R "pattern" directory/ # Recursive, follow symlinks
grep -rn "pattern" . # Recursive with line numbers
grep -rl "pattern" . # List matching files
REGEX PATTERNS
--------------
grep "^start" file # Lines starting with "start"
grep "end$" file # Lines ending with "end"
grep "^$" file # Empty lines
grep "." file # Any single character
grep "a*" file # Zero or more 'a'
grep "a+" file # One or more 'a' (extended)
grep "a?" file # Zero or one 'a' (extended)
grep "[abc]" file # Any of a, b, or c
grep "[^abc]" file # Not a, b, or c
grep "[0-9]" file # Any digit
grep "[a-z]" file # Any lowercase letter
grep "[A-Z]" file # Any uppercase letter
grep "\." file # Literal dot (escaped)
grep "a\|b" file # a OR b
EXTENDED REGEX (-E or egrep)
----------------------------
grep -E "pattern" file # Extended regex
egrep "pattern" file # Same as grep -E
grep -E "a|b" file # a OR b
grep -E "a{3}" file # Exactly 3 'a's
grep -E "a{2,4}" file # 2 to 4 'a's
grep -E "a{2,}" file # 2 or more 'a's
grep -E "(ab)+" file # One or more "ab"
PERL REGEX (-P)
---------------
grep -P "\d+" file # Digits (Perl regex)
grep -P "\w+" file # Word characters
grep -P "\s+" file # Whitespace
grep -P "(?<=prefix)" file # Lookbehind
grep -P "(?=suffix)" file # Lookahead
PRACTICAL EXAMPLES
------------------
# Find IP addresses
grep -E "[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}" file
# Find email addresses
grep -E "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b" file
# Find URLs
grep -E "https?://[^\s]+" file
# Find lines with numbers
grep "[0-9]" file
# Find blank lines
grep "^$" file
# Count lines with pattern
grep -c "error" logfile
# Find files containing pattern
grep -rl "TODO" --include="*.py" .
# Exclude directories
grep -r "pattern" --exclude-dir={.git,node_modules} .
# Exclude files
grep -r "pattern" --exclude="*.log" .
# Find and replace (with sed)
grep -l "old" * | xargs sed -i 's/old/new/g'
# Multiple patterns
grep -e "pattern1" -e "pattern2" file
# From file of patterns
grep -f patterns.txt file
# Binary files
grep -a "pattern" binary_file # Treat as text
grep -I "pattern" * # Ignore binary files
USEFUL COMBINATIONS
-------------------
# Find in code, skip binaries
grep -rIn "function" --include="*.js" .
# Find errors in logs
grep -i "error\|fail\|critical" /var/log/syslog
# Find processes
ps aux | grep "apache"
# Find open ports
netstat -tuln | grep "LISTEN"
# Find large files
ls -la | grep -E "^-.*[0-9]{8,}"
# Configuration values
grep -v "^#" config.conf | grep -v "^$"
EXIT CODES
----------
0 = Match found
1 = No match found
2 = Error occurred
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.