← All cheat sheets

LINUX ONE-LINERS

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

Powerful one-line commands for common tasks.

================================================================================

FILE OPERATIONS#

# Find and delete files older than 30 days
find /path -type f -mtime +30 -delete

# Find large files (>100MB)
find / -type f -size +100M 2>/dev/null

# Find recently modified files (last hour)
find /path -type f -mmin -60

# Count files by extension
find . -type f | sed 's/.*\.//' | sort | uniq -c | sort -rn

# Find duplicate files (by size)
find . -type f -exec md5sum {} \; | sort | uniq -w32 -dD

# Recursively replace text in files
find . -type f -name "*.txt" -exec sed -i 's/old/new/g' {} +

# Backup with timestamp
cp file.txt{,.$(date +%Y%m%d_%H%M%S).bak}

# Sync directories
rsync -avz --progress /source/ /dest/

# Find empty directories
find . -type d -empty

# Remove empty directories
find . -type d -empty -delete

================================================================================

TEXT PROCESSING#

# Count occurrences of word in file
grep -c "word" file

# Count unique lines
sort file | uniq | wc -l

# Show only duplicate lines
sort file | uniq -d

# Extract unique values from column 2
awk '{print $2}' file | sort -u

# Sum numbers in a file
awk '{sum+=$1} END {print sum}' file

# Average of numbers
awk '{sum+=$1; n++} END {print sum/n}' file

# Remove blank lines
sed '/^$/d' file

# Remove trailing whitespace
sed 's/[[:space:]]*$//' file

# Print lines between patterns
sed -n '/START/,/END/p' file

# Print specific line (line 10)
sed -n '10p' file

# Print lines 5-10
sed -n '5,10p' file

# Replace nth occurrence
sed 's/pattern/replace/3' file

# CSV to TSV
sed 's/,/\t/g' file.csv

# Remove first column
cut -d' ' -f2- file

# Reverse lines
tac file

# Shuffle lines
shuf file

================================================================================

NETWORK#

# Show open ports
ss -tulpn

# Show connections by state
ss -t state established

# Monitor network traffic
tcpdump -i eth0 -n

# Download file
curl -O http://example.com/file
wget http://example.com/file

# Test HTTP response
curl -I http://example.com

# Check if port is open
nc -zv host 80

# Show routing table
ip route

# DNS lookup
dig +short example.com

# Get external IP
curl -s ifconfig.me

# Monitor bandwidth
iftop -i eth0

# Show active connections
netstat -an | grep ESTABLISHED | wc -l

================================================================================

SYSTEM MONITORING#

# Top 10 memory processes
ps aux --sort=-%mem | head -11

# Top 10 CPU processes
ps aux --sort=-%cpu | head -11

# Disk usage by directory
du -sh /* 2>/dev/null | sort -h

# Show largest files
find / -type f -exec du -h {} + 2>/dev/null | sort -rh | head -20

# Memory usage
free -h

# CPU info
lscpu

# Watch log in real-time
tail -f /var/log/syslog

# System uptime and load
uptime

# Who is logged in
w

# Last logins
last -n 10

# Failed login attempts
grep "Failed" /var/log/auth.log | tail -20

================================================================================

PROCESS MANAGEMENT#

# Kill process by name
pkill -9 processname

# Kill process using port
kill $(lsof -t -i:8080)

# List processes by name
pgrep -l nginx

# Run command immune to hangup
nohup command &

# Run command with timeout
timeout 10s command

# Background job with logging
command > output.log 2>&1 &

# Find process using most CPU
ps aux | sort -nrk 3 | head -5

# Find process using most memory
ps aux | sort -nrk 4 | head -5

================================================================================

USER MANAGEMENT#

# List all users
cut -d: -f1 /etc/passwd

# List logged in users
who

# User's groups
groups username

# Add user to group
usermod -aG groupname username

# Change file owner recursively
chown -R user:group /path

================================================================================

COMPRESSION#

# Create tar.gz
tar -czvf archive.tar.gz /path/

# Extract tar.gz
tar -xzvf archive.tar.gz

# Create tar.gz excluding files
tar -czvf archive.tar.gz --exclude='*.log' /path/

# Compress folder with progress
tar cf - /path | pv | gzip > archive.tar.gz

================================================================================

DISK OPERATIONS#

# Check disk space
df -h

# Find large directories
du -h --max-depth=1 / 2>/dev/null | sort -h

# Check inode usage
df -i

# Mount ISO
mount -o loop image.iso /mnt

# Check filesystem
fsck -n /dev/sda1

================================================================================

LOG ANALYSIS#

# Count requests per IP (Apache)
awk '{print $1}' access.log | sort | uniq -c | sort -rn

# Top 10 requested URLs
awk '{print $7}' access.log | sort | uniq -c | sort -rn | head

# Requests per hour
awk '{print $4}' access.log | cut -d: -f2 | sort | uniq -c

# 404 errors
grep " 404 " access.log | awk '{print $7}' | sort | uniq -c | sort -rn

# Failed SSH attempts
grep "Failed password" /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn

# Error rate in last hour
grep "$(date +'%b %d %H')" /var/log/syslog | grep -c ERROR

================================================================================

SECURITY#

# Find SUID files
find / -perm -4000 -type f 2>/dev/null

# Find world-writable files
find / -perm -0002 -type f 2>/dev/null

# Find files modified in last 24h
find / -type f -mtime -1 2>/dev/null

# Check for listening services
ss -tulpn | grep LISTEN

# View failed logins
lastb | head -20

# Check sudo logs
grep sudo /var/log/auth.log

================================================================================

GIT#

# Show files changed in commit
git diff-tree --no-commit-id --name-only -r HEAD

# Undo last commit (keep changes)
git reset HEAD~1

# Delete merged branches
git branch --merged | grep -v "\*" | xargs -n 1 git branch -d

# Search commit history
git log --all --grep="search term"

# Who changed this line
git blame file

# Stash changes
git stash && git stash pop

================================================================================

DOCKER#

# Remove all stopped containers
docker container prune -f

# Remove all unused images
docker image prune -a -f

# Stop all containers
docker stop $(docker ps -q)

# Remove all containers
docker rm $(docker ps -aq)

# Container stats
docker stats --no-stream

# View logs
docker logs -f --tail 100 container

================================================================================

MISCELLANEOUS#

# Generate random password
openssl rand -base64 32

# Calculate file hash
sha256sum file

# Convert image format
convert input.png output.jpg

# Resize image
convert input.jpg -resize 800x600 output.jpg

# Create multiple directories
mkdir -p project/{src,bin,lib,docs}

# Compare files
diff file1 file2

# Compare directories
diff -rq dir1/ dir2/

# Calendar
cal

# Base64 encode
echo "text" | base64

# Base64 decode
echo "dGV4dAo=" | base64 -d

# JSON pretty print
cat file.json | jq '.'

# Watch command output
watch -n 1 'command'

# Repeat command until success
until command; do sleep 1; done

# Run command at specific time
echo "command" | at 2:00

# Execute command on remote
ssh user@host 'command'

# Copy file to remote
scp file user@host:/path/

# Create symbolic link
ln -s /target /link

# Find and replace in multiple files
grep -rl "old" . | xargs sed -i 's/old/new/g'

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.