To check kernel and system information
uname -a
# -a: all common system fields
# -r: kernel release only
# -m: machine architecture
# -n: network node name
Shows the kernel version, architecture, hostname, and system build details.
Intermediate 2.2 Field Guide
A linear Linux reference for turning the full course into quick checks, useful actions, and field-ready habits.
This page is an orientation before doing real work with Linux. It assumes you have already completed the full Linux course and now need a practical, repeatable way to inspect systems, troubleshoot issues, and collect useful evidence.
This guide follows a strict format: to do a practical task, use the matching command, then adjust the flags, values, paths, users, services, or targets to match the job in front of you.
How to read command comments: Lines starting with # are teaching notes, not part of the command to paste. Placeholder names such as file_name, folder_name, username, service_name, interface_name, and host should be replaced with real values.
Page rule: Every entry should stay practical: one goal, one command, and one short explanation. Add commands only when they help real Linux usage, troubleshooting, security checking, system administration, or investigation.
Goal: quickly understand what system you are working with.
uname -a
# -a: all common system fields
# -r: kernel release only
# -m: machine architecture
# -n: network node name
Shows the kernel version, architecture, hostname, and system build details.
hostname
# -I: assigned IP addresses
# hostnamectl: static hostname and OS summary on systemd systems
Shows the system name on the network.
whoami
Shows the current username.
id
# id username: check another user
# -u: UID only
# -nG: group names only
Shows your UID, GID, and group memberships.
pwd
# Use before copying, deleting, or moving files
# No normal daily flags are needed
Prints the full path of your current working directory.
ls -lah
# -l: long format with permissions, owner, size, and time
# -a: all entries, including hidden dotfiles
# -h: human-readable sizes
# ls -ltr: sort by time with newest entries at the bottom
Lists files, hidden entries, permissions, owners, sizes, and modification times in a readable format.
cd /path/to/folder
# /path/to/folder: replace with an absolute or relative path
# cd: go home
# cd -: return to the previous directory
# cd ..: move one level up
Changes your current working directory to the selected path.
cat /etc/passwd
# /etc/passwd: local account database, not necessarily every identity source
Lists local user accounts stored on the system.
getent passwd
# getent passwd username: check one account
# Use when LDAP, AD, NIS, or another identity source may exist
Shows user accounts using the system name service configuration, not only the local password file.
grep "/bin/bash" /etc/passwd
# Change "/bin/bash" to another shell such as "/bin/zsh"
# Use getent passwd when accounts may come from external identity sources
Shows users that likely have an interactive shell.
fastfetch
Shows a quick summary of OS, kernel, shell, CPU, memory, and desktop environment.
env | sort
# printenv PATH: show one variable
# env | grep -i proxy: find proxy-related settings
# Do not paste full output publicly; it may contain sensitive values
Shows environment variables in alphabetical order, which helps when checking shell, PATH, proxy, or application settings.
curl icanhazip.com
# -4: force IPv4
# -6: force IPv6
# -s: silent output for scripts
Shows the public IP address seen from the internet.
ip a
# ip -br a: compact interface summary
# ip a show interface_name: one interface only
# ip link: link state, MAC address, and interface flags
Shows local IP addresses, network interfaces, and connection state.
Goal: check whether the system is healthy, overloaded, or running out of resources.
htop
# F6: change sort column
# F9: send a signal to a selected process
# q: quit
# Save evidence separately with ps aux or screenshots if needed
Shows live CPU, RAM, process, and resource usage in an interactive view.
top
# P: sort by CPU
# M: sort by memory
# k: send a signal
# q: quit
# top -o %MEM: start with memory-heavy processes first
Shows live processes and resource usage using a default Linux tool.
free -h
# -h: human-readable units
# -m: MiB
# -g: GiB
# Focus on available for practical remaining capacity
Shows used, free, and available RAM in human-readable format.
df -h
# -h: human-readable sizes
# df -h /path: check the filesystem holding that path
# -i: inode usage when space is free but file creation fails
Shows mounted disks and available storage.
du -sh folder_name
# -s: summary total instead of every child
# -h: human-readable units
# folder_name: replace with the folder to measure
# --max-depth=1: show immediate child folder sizes
Shows the total size of a specific folder.
uptime
# Compare load averages with CPU count from nproc
# Load near or above CPU count for a long time deserves investigation
Shows how long the system has been running and its load average.
nproc
# Use this number when reading uptime load averages
# lscpu: detailed CPU, architecture, and virtualization information
Shows how many processing units Linux sees.
lsblk -f
# -f: filesystem details
# plain lsblk: simpler block-device tree
# Use before disk, partition, or mount work
Shows disks, partitions, filesystems, labels, UUIDs, and mount points.
Goal: understand what is running and stop processes safely when needed.
ps aux
# a: processes for all users
# u: user-oriented format
# x: include processes without a terminal
# --sort=-%cpu: high CPU first
# --sort=-%mem: high memory first
Shows all running processes with their users, CPU usage, memory usage, and PID.
pgrep -a process_name
# -a: show the full command line
# -u username: match one user only
# -f: match the full command line
# process_name: replace with the process pattern
Finds matching processes and shows their PIDs with command details.
pstree -p
# -p: show PIDs
# -a: show command arguments
# pstree -ap: tree with arguments and PIDs
Shows parent-child relationships between processes with PIDs.
kill PID
# PID: replace with the process ID from ps, pgrep, top, or htop
# plain kill sends SIGTERM
# kill -15 PID: explicit SIGTERM
# Verify before escalating to kill -9
Sends SIGTERM, asking the process to stop cleanly.
kill -9 PID
# -9: SIGKILL, which the process cannot cleanly handle
# Use only after kill PID or kill -15 PID fails
# Avoid on databases, package managers, backups, and write-heavy processes
Sends SIGKILL, useful only when a process refuses to stop normally.
pkill process_name
# Run pgrep -a process_name first to preview matches
# -u username: limit matching to one user
# -f pattern: match the full command line; can catch more than expected
Stops processes matching the given name.
lsof -p PID
# -p PID: inspect one process ID
# -i: focus on network sockets
# Use when a process holds a file, port, or mounted filesystem open
Shows files, sockets, and resources opened by a specific process.
Goal: understand IPs, routes, ports, DNS, connectivity, and packet movement.
ip a
# ip -br a: compact interface summary
# ip a show interface_name: inspect one interface
# ip link: link state, MAC address, and interface flags
Shows local IPs, interfaces, and link status.
ip r
# Look for the default via line to identify the gateway
# ip r get target_ip: show the route Linux would use for a target
# Check routes before blaming DNS or a service
Shows the default gateway and routing table.
ss -tulpen
# -t: TCP sockets
# -u: UDP sockets
# -l: listening sockets only
# -p: process details when permissions allow
# -e: extended socket information
# -n: numeric addresses and ports
Shows TCP/UDP listening ports, related processes, and users.
ping -c 4 8.8.8.8
# -c 4: send 4 packets
# Change 4 for a longer or shorter check
# Ping your gateway for local reachability
# Ping a domain only when you also want DNS involved
Tests whether the system can reach the internet by IP.
dig example.com
# example.com: replace with the domain you are testing
# dig A domain: IPv4 records
# dig AAAA domain: IPv6 records
# dig @1.1.1.1 domain: query a specific DNS server
# +short: answer only
Checks whether domain names are resolving correctly.
curl icanhazip.com
# -4: force IPv4
# -6: force IPv6
# -s: silent output for scripts
Shows the public IP address from the system's network.
sudo tcpdump -i interface_name -w capture.pcap
# -i interface_name: capture from one network interface
# -w capture.pcap: write packets to a file
# -c count: stop after a fixed number of packets
# Use a narrow capture filter when possible; captures may contain sensitive traffic
Captures packets from a specific interface into a pcap file.
tracepath example.com
# example.com: replace with a host or IP address
# Use traceroute if tracepath is not installed
# Middle hops may block replies; focus on the destination and pattern
Shows the network path and possible MTU issues to a destination.
ssh user@host
# user: remote username
# host: hostname or IP address
# -p port: custom SSH port
# -i key_file: use a specific private key
Starts a secure remote shell session.
scp capture.pcap user@host:/path/
# capture.pcap: local file to upload
# user@host:/path/: remote account, system, and destination
# -P port: custom SSH port; uppercase P for scp
# -r: recursively copy a directory
Copies a local capture file to a remote system over SSH.
Goal: understand identity, groups, sudo access, and account changes.
whoami
Shows the username for the current shell.
id username
# username: replace with the account to inspect
# -u: UID only
# -nG: group names only
Shows UID, GID, and groups for a specific user.
groups username
# username: replace with the account to inspect
# Groups affect file access, sudo rules, and service permissions
Shows group memberships for a specific user.
sudo -l
# -l: list allowed sudo rules
# -U username: inspect another user only if you have permission
# NOPASSWD means sudo may not ask for a password for listed commands
Shows what commands your user can run with sudo.
sudo passwd username
# username: account whose password will change
# This is an account-changing action; confirm you are allowed to do it
# Use passwd without sudo to change your own password
Changes the password for a user account.
sudo usermod -L username
# -L: lock the password field
# This may not stop active sessions or SSH-key access
# Check policy and document why the account was locked
Locks password authentication for a user account.
sudo usermod -U username
# -U: unlock the password field
# Unlock only when the reason for the lock is resolved
# Check login method and account policy after unlocking
Unlocks password authentication for a user account.
sudo usermod -aG group_name username
# -a: append instead of replacing group memberships
# -G group_name: supplementary group list
# Omitting -a can remove existing supplementary groups
# The user may need to log out and back in
Adds a user to a supplementary group.
sudo userdel username
# username: account to remove
# Check running processes, ownership, and data retention first
# This usually leaves the home directory behind
Removes a user account but normally leaves the home directory behind.
sudo userdel -r username
# -r: remove the home directory and mail spool
# Back up or review files before using this
# Do not use on accounts with evidence or data-retention requirements
Removes a user account and its home directory.
sudo useradd -m -s /bin/bash username
# -m: create a home directory
# -s /bin/bash: set the login shell
# username: new account name
# Set a password separately with sudo passwd username if needed
Creates a user with a home directory and Bash as the login shell.
Goal: inspect files, permissions, ownership, size, and recent changes.
stat file_name
# file_name: replace with a file or folder path
# -c: custom output format on GNU systems
# Use when timestamps, ownership, permissions, or inode details matter
Shows file size, permissions, owner, access time, modify time, and change time.
ls -lah file_name
# -l: long format with permission bits
# -a: include hidden entries
# -h: human-readable sizes
# ls -ld folder_name: inspect the folder itself, not its contents
Shows permissions, owner, group, size, and modification time.
cp -av source_path destination_path
# -a: archive mode; preserves metadata and copies directories recursively
# -v: verbose output
# source_path and destination_path: verify both before copying
# -i: prompt before overwrite
Copies files or folders while preserving useful metadata and showing what is copied.
mv -i old_name new_name
# -i: prompt before overwrite
# mv file folder/: move into a folder
# mv old_name new_name: rename in the same folder
# Keep a copy first when rollback matters
Moves or renames a file and asks before overwriting an existing destination.
chmod 640 file_name
# 640: owner read/write, group read, others no access
# +x: add execute permission, useful for scripts
# -R: recursive; use carefully because mistakes can break apps or expose data
# Check current permissions with ls -lah first
Changes who can read, write, or execute a file.
sudo chown user:group file_name
# user:group: new owner and group
# file_name: file or folder to change
# -R: recursive ownership change; use only when required
# Check ownership before and after with ls -lah
Changes the owner and group assigned to a file or folder.
find /path -type f -mtime -1
# /path: smallest safe folder to search
# -type f: files only
# -type d: directories only
# -mtime -1: modified less than one day ago
# -ls: show metadata with results
Finds files modified within the last 24 hours.
find /path -type f -size +100M
# /path: smallest safe folder to search
# -type f: files only
# -size +100M: larger than 100 MiB
# -xdev: do not cross into other mounted filesystems
Finds files larger than 100 MB.
find /path -name ".*"
# /path: use a narrow scope such as a home directory
# -name ".*": names that start with a dot
# -type f: hidden files only
# -type d: hidden directories only
# Hidden does not automatically mean malicious
Finds hidden files and directories.
find /path -type f -perm -o+w
# /path: focused search scope
# -type f: files only
# -perm -o+w: others write bit is set
# Use -type d to check world-writable directories
# Some temporary directories are intentionally writable
Finds files that any user on the system can write to.
sha256sum file_name
# file_name: file to verify
# sha256sum file_name > file_name.sha256: save a hash record
# -c file_name.sha256: verify from a saved hash file
# Hash before and after transfer when integrity matters
Creates a SHA-256 hash for integrity checking or evidence tracking.
less file_name
# file_name: file to view
# /pattern: search inside the file
# n: next search match
# q: quit
# +G: open at the end of the file
Opens a file in a pager without editing it.
tail -n 50 file_name
# -n 50: show the last 50 lines
# Change 50 to the amount of context you need
# -f: follow new lines as they are written
# Ctrl+C: stop following
Shows the last 50 lines of a file, useful for recent log entries.
head -n 20 file_name
# -n 20: show the first 20 lines
# Use before parsing unknown files so you understand the structure
Shows the first 20 lines of a file, useful for checking headers or file format.
Goal: check what runs automatically, what is active, and what failed.
systemctl list-unit-files --type=service --state=enabled
# list-unit-files: unit-file enablement, not current runtime state
# --type=service: service units only
# --state=enabled: enabled at boot
# Change enabled to disabled to review disabled services
Shows services configured to start automatically with the system.
systemctl list-units --type=service --state=running
# list-units: loaded runtime units
# --type=service: service units only
# --state=running: active running services only
# Remove --state to see more service states
Shows services currently active on the system.
systemctl --failed
# --failed: units in failed state
# Check status and logs for any important failed service
Shows services that failed to start or crashed.
systemctl status service_name
# service_name: real unit such as ssh, nginx, docker, or cron
# --no-pager: print output without opening a pager
# is-active: script-friendly active/inactive check
# is-enabled: check boot enablement
Shows whether a service is running, failed, disabled, or enabled.
sudo systemctl stop service_name
# stop: stop for the current boot only
# service_name: real unit to stop
# start: start it again
# Check status first; stopping SSH, network, database, or production services can break access
Stops a running service until it is started again or the system reboots.
sudo systemctl disable service_name
# disable: change boot behavior
# --now: disable and stop immediately
# enable: allow it to start at boot again
# Document why before disabling security, logging, networking, or backup services
Prevents a service from starting automatically at boot.
sudo systemctl restart service_name
# restart: fully stop and start the service
# reload: apply config without dropping sessions when supported
# reload-or-restart: reload if possible, restart otherwise
# Check status and logs afterward
Stops and starts a service, usually to apply configuration changes.
Goal: check what happened recently on the system.
journalctl --since "1 hour ago"
# --since: start time for the log window
# Use values like "10 minutes ago", "24 hours ago", or "2026-06-30 09:00"
# -n 100: last 100 log lines
# -f: follow logs live
# --no-pager: print output without opening a pager
Shows system logs from the last hour.
journalctl -u service_name --since "1 hour ago"
# -u service_name: logs for one systemd unit
# --since: investigation time window
# -f: follow that service live
# -b: current boot only
Shows recent logs for a specific service.
journalctl _COMM=sudo --since "24 hours ago"
# _COMM=sudo: filter logs where the command name is sudo
# --since: investigation time window
# Use as a lead; confirm important actions with other logs or records
Shows sudo commands used recently.
last
# Use with w, journalctl, and service logs when confirming unusual sessions
Shows recent successful login sessions.
w
# Shows user, terminal, source host, idle time, and current command
Shows who is logged in and what they are doing.
grep "Failed password" /var/log/auth.log
# Change the quoted pattern for different services or distro wording
# -i: case-insensitive matching
# tail -n 20: focus on recent matches
# Some systems use /var/log/secure or journalctl instead of auth.log
Shows failed SSH/password login attempts on Debian/Ubuntu systems.
grep "Accepted" /var/log/auth.log
# "Accepted": common SSH success pattern
# "Accepted publickey": key-based logins
# "Accepted password": password logins
# Confirm unusual logins with last, w, and service logs
Shows successful SSH login attempts on Debian/Ubuntu systems.
tail -f /var/log/auth.log
# -f: follow appended lines
# -n 100 -f: show recent context before following
# Change the path to the log you need
# Ctrl+C: stop following
Shows new log lines as they are written.
history | tail -n 50
# tail -n 50: show the last 50 history lines
# Change 50 to the amount you need
# History may be incomplete, disabled, edited, or split across shells
# Treat history as a lead, not proof by itself
Shows the last 50 commands from the current user's shell history.
Goal: check whether a command exists, where it is located, and what package/application is installed.
which command_name
# command_name: replace with a binary such as curl or python3
# Useful interactively; command -v is usually better in scripts
Shows the path of a command if it exists in the system PATH.
command -v command_name
# command_name: binary, shell builtin, function, or alias to check
# > /dev/null: hide output when you only need success or failure in scripts
# type command_name: show whether it is a binary, builtin, function, or alias
Shows how the shell resolves a command.
whereis command_name
# command_name: command to inspect
# -b: binaries only
# man command_name: full manual when documentation is needed
Shows common locations related to a command.
apt list --installed
# --installed: installed packages only
# Pipe to less when reviewing interactively
# dpkg -l: classic package table format
Lists installed packages on Debian/Ubuntu systems.
apt list --installed | grep package_name
# package_name: package or keyword to search for
# grep -i: case-insensitive matching
# apt-cache policy package_name: installed and candidate versions
# dpkg -L package_name: files installed by a package
Checks whether a specific package is installed.
apt show package_name
# package_name: package to review
# Use before installing so you understand what it is and where it comes from
# apt search keyword: find package names by keyword
Shows package description, version, dependencies, maintainer, and repository information.
Goal: move files safely and keep basic integrity records.
tar -czf archive.tar.gz folder_name
# -c: create a new archive
# -z: gzip compression
# -f archive.tar.gz: output file name; the name must come right after -f
# folder_name: folder to archive
# -v: verbose output
Creates a compressed archive of a folder.
tar -xzf archive.tar.gz
# -x: extract an archive
# -z: handle gzip compression
# -f archive.tar.gz: archive file to read
# -t: list contents before extracting
# -C destination_folder: extract into a specific folder
Extracts a gzip-compressed tar archive into the current directory.
scp file_name user@host:/path/
# file_name: local file to upload
# user@host:/path/: remote account, system, and destination
# -P port: custom SSH port; uppercase P for scp
# -r: recursively copy a directory
Transfers a file securely over SSH.
scp user@host:/path/file_name .
# final .: download into the current directory
# Replace . with a local folder path for a specific destination
# -P port: custom SSH port; uppercase P for scp
# Quote remote paths that contain spaces
Downloads a file from a remote system over SSH.
rsync -avP source_path user@host:/path/
# -a: archive mode with recursion and metadata preservation
# -v: verbose output
# -P: progress plus partial transfer handling
# --dry-run: preview important syncs first
# Trailing slash matters: source/ copies contents, source copies the directory
Copies files over SSH while preserving useful metadata and showing progress.
sha256sum file_name
# file_name: file to verify
# > file_name.sha256: save the hash record
# -c file_name.sha256: verify from the saved hash file
# Record hash, filename, timestamp, and system name for evidence
Creates a hash that can be used to confirm the file did not change.