LINUX ONE-LINERS
Powerful one-line commands for common tasks. ================================================================================
FILE OPERATIONS#
# Find and delete files older than 30 days
find /path -type f -mtime +30 -delete
# Find large files (>100MB)
find / -type f -size +100M 2>/dev/null
# Find recently modified files (last hour)
find /path -type f -mmin -60
# Count files by extension
find . -type f | sed 's/.*\.//' | sort | uniq -c | sort -rn
# Find duplicate files (by size)
find . -type f -exec md5sum {} \; | sort | uniq -w32 -dD
# Recursively replace text in files
find . -type f -name "*.txt" -exec sed -i 's/old/new/g' {} +
# Backup with timestamp
cp file.txt{,.$(date +%Y%m%d_%H%M%S).bak}
# Sync directories
rsync -avz --progress /source/ /dest/
# Find empty directories
find . -type d -empty
# Remove empty directories
find . -type d -empty -delete
================================================================================
TEXT PROCESSING#
# Count occurrences of word in file
grep -c "word" file
# Count unique lines
sort file | uniq | wc -l
# Show only duplicate lines
sort file | uniq -d
# Extract unique values from column 2
awk '{print $2}' file | sort -u
# Sum numbers in a file
awk '{sum+=$1} END {print sum}' file
# Average of numbers
awk '{sum+=$1; n++} END {print sum/n}' file
# Remove blank lines
sed '/^$/d' file
# Remove trailing whitespace
sed 's/[[:space:]]*$//' file
# Print lines between patterns
sed -n '/START/,/END/p' file
# Print specific line (line 10)
sed -n '10p' file
# Print lines 5-10
sed -n '5,10p' file
# Replace nth occurrence
sed 's/pattern/replace/3' file
# CSV to TSV
sed 's/,/\t/g' file.csv
# Remove first column
cut -d' ' -f2- file
# Reverse lines
tac file
# Shuffle lines
shuf file
================================================================================
NETWORK#
# Show open ports ss -tulpn # Show connections by state ss -t state established # Monitor network traffic tcpdump -i eth0 -n # Download file curl -O http://example.com/file wget http://example.com/file # Test HTTP response curl -I http://example.com # Check if port is open nc -zv host 80 # Show routing table ip route # DNS lookup dig +short example.com # Get external IP curl -s ifconfig.me # Monitor bandwidth iftop -i eth0 # Show active connections netstat -an | grep ESTABLISHED | wc -l ================================================================================
SYSTEM MONITORING#
# Top 10 memory processes
ps aux --sort=-%mem | head -11
# Top 10 CPU processes
ps aux --sort=-%cpu | head -11
# Disk usage by directory
du -sh /* 2>/dev/null | sort -h
# Show largest files
find / -type f -exec du -h {} + 2>/dev/null | sort -rh | head -20
# Memory usage
free -h
# CPU info
lscpu
# Watch log in real-time
tail -f /var/log/syslog
# System uptime and load
uptime
# Who is logged in
w
# Last logins
last -n 10
# Failed login attempts
grep "Failed" /var/log/auth.log | tail -20
================================================================================
PROCESS MANAGEMENT#
# Kill process by name pkill -9 processname # Kill process using port kill $(lsof -t -i:8080) # List processes by name pgrep -l nginx # Run command immune to hangup nohup command & # Run command with timeout timeout 10s command # Background job with logging command > output.log 2>&1 & # Find process using most CPU ps aux | sort -nrk 3 | head -5 # Find process using most memory ps aux | sort -nrk 4 | head -5 ================================================================================
USER MANAGEMENT#
# List all users cut -d: -f1 /etc/passwd # List logged in users who # User's groups groups username # Add user to group usermod -aG groupname username # Change file owner recursively chown -R user:group /path ================================================================================
COMPRESSION#
# Create tar.gz tar -czvf archive.tar.gz /path/ # Extract tar.gz tar -xzvf archive.tar.gz # Create tar.gz excluding files tar -czvf archive.tar.gz --exclude='*.log' /path/ # Compress folder with progress tar cf - /path | pv | gzip > archive.tar.gz ================================================================================
DISK OPERATIONS#
# Check disk space df -h # Find large directories du -h --max-depth=1 / 2>/dev/null | sort -h # Check inode usage df -i # Mount ISO mount -o loop image.iso /mnt # Check filesystem fsck -n /dev/sda1 ================================================================================
LOG ANALYSIS#
# Count requests per IP (Apache)
awk '{print $1}' access.log | sort | uniq -c | sort -rn
# Top 10 requested URLs
awk '{print $7}' access.log | sort | uniq -c | sort -rn | head
# Requests per hour
awk '{print $4}' access.log | cut -d: -f2 | sort | uniq -c
# 404 errors
grep " 404 " access.log | awk '{print $7}' | sort | uniq -c | sort -rn
# Failed SSH attempts
grep "Failed password" /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn
# Error rate in last hour
grep "$(date +'%b %d %H')" /var/log/syslog | grep -c ERROR
================================================================================
SECURITY#
# Find SUID files find / -perm -4000 -type f 2>/dev/null # Find world-writable files find / -perm -0002 -type f 2>/dev/null # Find files modified in last 24h find / -type f -mtime -1 2>/dev/null # Check for listening services ss -tulpn | grep LISTEN # View failed logins lastb | head -20 # Check sudo logs grep sudo /var/log/auth.log ================================================================================
GIT#
# Show files changed in commit git diff-tree --no-commit-id --name-only -r HEAD # Undo last commit (keep changes) git reset HEAD~1 # Delete merged branches git branch --merged | grep -v "\*" | xargs -n 1 git branch -d # Search commit history git log --all --grep="search term" # Who changed this line git blame file # Stash changes git stash && git stash pop ================================================================================
DOCKER#
# Remove all stopped containers docker container prune -f # Remove all unused images docker image prune -a -f # Stop all containers docker stop $(docker ps -q) # Remove all containers docker rm $(docker ps -aq) # Container stats docker stats --no-stream # View logs docker logs -f --tail 100 container ================================================================================
MISCELLANEOUS#
# Generate random password
openssl rand -base64 32
# Calculate file hash
sha256sum file
# Convert image format
convert input.png output.jpg
# Resize image
convert input.jpg -resize 800x600 output.jpg
# Create multiple directories
mkdir -p project/{src,bin,lib,docs}
# Compare files
diff file1 file2
# Compare directories
diff -rq dir1/ dir2/
# Calendar
cal
# Base64 encode
echo "text" | base64
# Base64 decode
echo "dGV4dAo=" | base64 -d
# JSON pretty print
cat file.json | jq '.'
# Watch command output
watch -n 1 'command'
# Repeat command until success
until command; do sleep 1; done
# Run command at specific time
echo "command" | at 2:00
# Execute command on remote
ssh user@host 'command'
# Copy file to remote
scp file user@host:/path/
# Create symbolic link
ln -s /target /link
# Find and replace in multiple files
grep -rl "old" . | xargs sed -i 's/old/new/g'
LINUX ONE-LINERS CHEATSHEET
===========================
Source: https://cheatsheet.johlem.net
Powerful one-line commands for common tasks.
================================================================================
FILE OPERATIONS
================================================================================
# Find and delete files older than 30 days
find /path -type f -mtime +30 -delete
# Find large files (>100MB)
find / -type f -size +100M 2>/dev/null
# Find recently modified files (last hour)
find /path -type f -mmin -60
# Count files by extension
find . -type f | sed 's/.*\.//' | sort | uniq -c | sort -rn
# Find duplicate files (by size)
find . -type f -exec md5sum {} \; | sort | uniq -w32 -dD
# Recursively replace text in files
find . -type f -name "*.txt" -exec sed -i 's/old/new/g' {} +
# Backup with timestamp
cp file.txt{,.$(date +%Y%m%d_%H%M%S).bak}
# Sync directories
rsync -avz --progress /source/ /dest/
# Find empty directories
find . -type d -empty
# Remove empty directories
find . -type d -empty -delete
================================================================================
TEXT PROCESSING
================================================================================
# Count occurrences of word in file
grep -c "word" file
# Count unique lines
sort file | uniq | wc -l
# Show only duplicate lines
sort file | uniq -d
# Extract unique values from column 2
awk '{print $2}' file | sort -u
# Sum numbers in a file
awk '{sum+=$1} END {print sum}' file
# Average of numbers
awk '{sum+=$1; n++} END {print sum/n}' file
# Remove blank lines
sed '/^$/d' file
# Remove trailing whitespace
sed 's/[[:space:]]*$//' file
# Print lines between patterns
sed -n '/START/,/END/p' file
# Print specific line (line 10)
sed -n '10p' file
# Print lines 5-10
sed -n '5,10p' file
# Replace nth occurrence
sed 's/pattern/replace/3' file
# CSV to TSV
sed 's/,/\t/g' file.csv
# Remove first column
cut -d' ' -f2- file
# Reverse lines
tac file
# Shuffle lines
shuf file
================================================================================
NETWORK
================================================================================
# Show open ports
ss -tulpn
# Show connections by state
ss -t state established
# Monitor network traffic
tcpdump -i eth0 -n
# Download file
curl -O http://example.com/file
wget http://example.com/file
# Test HTTP response
curl -I http://example.com
# Check if port is open
nc -zv host 80
# Show routing table
ip route
# DNS lookup
dig +short example.com
# Get external IP
curl -s ifconfig.me
# Monitor bandwidth
iftop -i eth0
# Show active connections
netstat -an | grep ESTABLISHED | wc -l
================================================================================
SYSTEM MONITORING
================================================================================
# Top 10 memory processes
ps aux --sort=-%mem | head -11
# Top 10 CPU processes
ps aux --sort=-%cpu | head -11
# Disk usage by directory
du -sh /* 2>/dev/null | sort -h
# Show largest files
find / -type f -exec du -h {} + 2>/dev/null | sort -rh | head -20
# Memory usage
free -h
# CPU info
lscpu
# Watch log in real-time
tail -f /var/log/syslog
# System uptime and load
uptime
# Who is logged in
w
# Last logins
last -n 10
# Failed login attempts
grep "Failed" /var/log/auth.log | tail -20
================================================================================
PROCESS MANAGEMENT
================================================================================
# Kill process by name
pkill -9 processname
# Kill process using port
kill $(lsof -t -i:8080)
# List processes by name
pgrep -l nginx
# Run command immune to hangup
nohup command &
# Run command with timeout
timeout 10s command
# Background job with logging
command > output.log 2>&1 &
# Find process using most CPU
ps aux | sort -nrk 3 | head -5
# Find process using most memory
ps aux | sort -nrk 4 | head -5
================================================================================
USER MANAGEMENT
================================================================================
# List all users
cut -d: -f1 /etc/passwd
# List logged in users
who
# User's groups
groups username
# Add user to group
usermod -aG groupname username
# Change file owner recursively
chown -R user:group /path
================================================================================
COMPRESSION
================================================================================
# Create tar.gz
tar -czvf archive.tar.gz /path/
# Extract tar.gz
tar -xzvf archive.tar.gz
# Create tar.gz excluding files
tar -czvf archive.tar.gz --exclude='*.log' /path/
# Compress folder with progress
tar cf - /path | pv | gzip > archive.tar.gz
================================================================================
DISK OPERATIONS
================================================================================
# Check disk space
df -h
# Find large directories
du -h --max-depth=1 / 2>/dev/null | sort -h
# Check inode usage
df -i
# Mount ISO
mount -o loop image.iso /mnt
# Check filesystem
fsck -n /dev/sda1
================================================================================
LOG ANALYSIS
================================================================================
# Count requests per IP (Apache)
awk '{print $1}' access.log | sort | uniq -c | sort -rn
# Top 10 requested URLs
awk '{print $7}' access.log | sort | uniq -c | sort -rn | head
# Requests per hour
awk '{print $4}' access.log | cut -d: -f2 | sort | uniq -c
# 404 errors
grep " 404 " access.log | awk '{print $7}' | sort | uniq -c | sort -rn
# Failed SSH attempts
grep "Failed password" /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn
# Error rate in last hour
grep "$(date +'%b %d %H')" /var/log/syslog | grep -c ERROR
================================================================================
SECURITY
================================================================================
# Find SUID files
find / -perm -4000 -type f 2>/dev/null
# Find world-writable files
find / -perm -0002 -type f 2>/dev/null
# Find files modified in last 24h
find / -type f -mtime -1 2>/dev/null
# Check for listening services
ss -tulpn | grep LISTEN
# View failed logins
lastb | head -20
# Check sudo logs
grep sudo /var/log/auth.log
================================================================================
GIT
================================================================================
# Show files changed in commit
git diff-tree --no-commit-id --name-only -r HEAD
# Undo last commit (keep changes)
git reset HEAD~1
# Delete merged branches
git branch --merged | grep -v "\*" | xargs -n 1 git branch -d
# Search commit history
git log --all --grep="search term"
# Who changed this line
git blame file
# Stash changes
git stash && git stash pop
================================================================================
DOCKER
================================================================================
# Remove all stopped containers
docker container prune -f
# Remove all unused images
docker image prune -a -f
# Stop all containers
docker stop $(docker ps -q)
# Remove all containers
docker rm $(docker ps -aq)
# Container stats
docker stats --no-stream
# View logs
docker logs -f --tail 100 container
================================================================================
MISCELLANEOUS
================================================================================
# Generate random password
openssl rand -base64 32
# Calculate file hash
sha256sum file
# Convert image format
convert input.png output.jpg
# Resize image
convert input.jpg -resize 800x600 output.jpg
# Create multiple directories
mkdir -p project/{src,bin,lib,docs}
# Compare files
diff file1 file2
# Compare directories
diff -rq dir1/ dir2/
# Calendar
cal
# Base64 encode
echo "text" | base64
# Base64 decode
echo "dGV4dAo=" | base64 -d
# JSON pretty print
cat file.json | jq '.'
# Watch command output
watch -n 1 'command'
# Repeat command until success
until command; do sleep 1; done
# Run command at specific time
echo "command" | at 2:00
# Execute command on remote
ssh user@host 'command'
# Copy file to remote
scp file user@host:/path/
# Create symbolic link
ln -s /target /link
# Find and replace in multiple files
grep -rl "old" . | xargs sed -i 's/old/new/g'
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.