Intermediate 2.2 Field Guide

Practical Linux Guide

A linear Linux reference for turning the full course into quick checks, useful actions, and field-ready habits.

This page is an orientation before doing real work with Linux. It assumes you have already completed the full Linux course and now need a practical, repeatable way to inspect systems, troubleshoot issues, and collect useful evidence.

How to Use This Guide

This guide follows a strict format: to do a practical task, use the matching command, then adjust the flags, values, paths, users, services, or targets to match the job in front of you.

  • Use it after the full Linux course, not as a replacement for the course.
  • Run commands only on systems you own, administer, or have permission to inspect.
  • Prefer read-only checks first. Use destructive or account-changing commands only when you understand the impact.
  • Keep notes when investigating: command, timestamp, system, output summary, and what you checked next.

How to read command comments: Lines starting with # are teaching notes, not part of the command to paste. Placeholder names such as file_name, folder_name, username, service_name, interface_name, and host should be replaced with real values.

Page rule: Every entry should stay practical: one goal, one command, and one short explanation. Add commands only when they help real Linux usage, troubleshooting, security checking, system administration, or investigation.

Phase 1: Basic Recon

Goal: quickly understand what system you are working with.

To check kernel and system information

uname -a
# -a: all common system fields
# -r: kernel release only
# -m: machine architecture
# -n: network node name

Shows the kernel version, architecture, hostname, and system build details.

To check the current hostname

hostname
# -I: assigned IP addresses
# hostnamectl: static hostname and OS summary on systemd systems

Shows the system name on the network.

To check who you are logged in as

whoami

Shows the current username.

To check your user ID and groups

id
# id username: check another user
# -u: UID only
# -nG: group names only

Shows your UID, GID, and group memberships.

To check your current directory

pwd
# Use before copying, deleting, or moving files
# No normal daily flags are needed

Prints the full path of your current working directory.

To list files clearly

ls -lah
# -l: long format with permissions, owner, size, and time
# -a: all entries, including hidden dotfiles
# -h: human-readable sizes
# ls -ltr: sort by time with newest entries at the bottom

Lists files, hidden entries, permissions, owners, sizes, and modification times in a readable format.

To move into another directory

cd /path/to/folder
# /path/to/folder: replace with an absolute or relative path
# cd: go home
# cd -: return to the previous directory
# cd ..: move one level up

Changes your current working directory to the selected path.

To view users on the system

cat /etc/passwd
# /etc/passwd: local account database, not necessarily every identity source

Lists local user accounts stored on the system.

To view users from the active identity source

getent passwd
# getent passwd username: check one account
# Use when LDAP, AD, NIS, or another identity source may exist

Shows user accounts using the system name service configuration, not only the local password file.

To filter normal login users

grep "/bin/bash" /etc/passwd
# Change "/bin/bash" to another shell such as "/bin/zsh"
# Use getent passwd when accounts may come from external identity sources

Shows users that likely have an interactive shell.

To view general system information

fastfetch

Shows a quick summary of OS, kernel, shell, CPU, memory, and desktop environment.

To view shell environment variables

env | sort
# printenv PATH: show one variable
# env | grep -i proxy: find proxy-related settings
# Do not paste full output publicly; it may contain sensitive values

Shows environment variables in alphabetical order, which helps when checking shell, PATH, proxy, or application settings.

To check public IP address

curl icanhazip.com
# -4: force IPv4
# -6: force IPv6
# -s: silent output for scripts

Shows the public IP address seen from the internet.

To check local IP addresses and interfaces

ip a
# ip -br a: compact interface summary
# ip a show interface_name: one interface only
# ip link: link state, MAC address, and interface flags

Shows local IP addresses, network interfaces, and connection state.

Phase 2: System Health

Goal: check whether the system is healthy, overloaded, or running out of resources.

To check live resource usage

htop
# F6: change sort column
# F9: send a signal to a selected process
# q: quit
# Save evidence separately with ps aux or screenshots if needed

Shows live CPU, RAM, process, and resource usage in an interactive view.

To check live resource usage without htop

top
# P: sort by CPU
# M: sort by memory
# k: send a signal
# q: quit
# top -o %MEM: start with memory-heavy processes first

Shows live processes and resource usage using a default Linux tool.

To check memory usage

free -h
# -h: human-readable units
# -m: MiB
# -g: GiB
# Focus on available for practical remaining capacity

Shows used, free, and available RAM in human-readable format.

To check disk usage

df -h
# -h: human-readable sizes
# df -h /path: check the filesystem holding that path
# -i: inode usage when space is free but file creation fails

Shows mounted disks and available storage.

To check folder size

du -sh folder_name
# -s: summary total instead of every child
# -h: human-readable units
# folder_name: replace with the folder to measure
# --max-depth=1: show immediate child folder sizes

Shows the total size of a specific folder.

To check system uptime and load

uptime
# Compare load averages with CPU count from nproc
# Load near or above CPU count for a long time deserves investigation

Shows how long the system has been running and its load average.

To check CPU count

nproc
# Use this number when reading uptime load averages
# lscpu: detailed CPU, architecture, and virtualization information

Shows how many processing units Linux sees.

To check block devices and mount layout

lsblk -f
# -f: filesystem details
# plain lsblk: simpler block-device tree
# Use before disk, partition, or mount work

Shows disks, partitions, filesystems, labels, UUIDs, and mount points.

Phase 3: Process Management

Goal: understand what is running and stop processes safely when needed.

To view all running processes

ps aux
# a: processes for all users
# u: user-oriented format
# x: include processes without a terminal
# --sort=-%cpu: high CPU first
# --sort=-%mem: high memory first

Shows all running processes with their users, CPU usage, memory usage, and PID.

To find a process by name

pgrep -a process_name
# -a: show the full command line
# -u username: match one user only
# -f: match the full command line
# process_name: replace with the process pattern

Finds matching processes and shows their PIDs with command details.

To view processes as a tree

pstree -p
# -p: show PIDs
# -a: show command arguments
# pstree -ap: tree with arguments and PIDs

Shows parent-child relationships between processes with PIDs.

To stop a process safely

kill PID
# PID: replace with the process ID from ps, pgrep, top, or htop
# plain kill sends SIGTERM
# kill -15 PID: explicit SIGTERM
# Verify before escalating to kill -9

Sends SIGTERM, asking the process to stop cleanly.

To force-stop a stuck process

kill -9 PID
# -9: SIGKILL, which the process cannot cleanly handle
# Use only after kill PID or kill -15 PID fails
# Avoid on databases, package managers, backups, and write-heavy processes

Sends SIGKILL, useful only when a process refuses to stop normally.

To kill a process by name

pkill process_name
# Run pgrep -a process_name first to preview matches
# -u username: limit matching to one user
# -f pattern: match the full command line; can catch more than expected

Stops processes matching the given name.

To inspect open files for a process

lsof -p PID
# -p PID: inspect one process ID
# -i: focus on network sockets
# Use when a process holds a file, port, or mounted filesystem open

Shows files, sockets, and resources opened by a specific process.

Phase 4: Networking

Goal: understand IPs, routes, ports, DNS, connectivity, and packet movement.

To check local IP addresses

ip a
# ip -br a: compact interface summary
# ip a show interface_name: inspect one interface
# ip link: link state, MAC address, and interface flags

Shows local IPs, interfaces, and link status.

To check network routes

ip r
# Look for the default via line to identify the gateway
# ip r get target_ip: show the route Linux would use for a target
# Check routes before blaming DNS or a service

Shows the default gateway and routing table.

To check listening ports

ss -tulpen
# -t: TCP sockets
# -u: UDP sockets
# -l: listening sockets only
# -p: process details when permissions allow
# -e: extended socket information
# -n: numeric addresses and ports

Shows TCP/UDP listening ports, related processes, and users.

To test internet connectivity

ping -c 4 8.8.8.8
# -c 4: send 4 packets
# Change 4 for a longer or shorter check
# Ping your gateway for local reachability
# Ping a domain only when you also want DNS involved

Tests whether the system can reach the internet by IP.

To test DNS resolution

dig example.com
# example.com: replace with the domain you are testing
# dig A domain: IPv4 records
# dig AAAA domain: IPv6 records
# dig @1.1.1.1 domain: query a specific DNS server
# +short: answer only

Checks whether domain names are resolving correctly.

To check public IP

curl icanhazip.com
# -4: force IPv4
# -6: force IPv6
# -s: silent output for scripts

Shows the public IP address from the system's network.

To capture packets on an interface

sudo tcpdump -i interface_name -w capture.pcap
# -i interface_name: capture from one network interface
# -w capture.pcap: write packets to a file
# -c count: stop after a fixed number of packets
# Use a narrow capture filter when possible; captures may contain sensitive traffic

Captures packets from a specific interface into a pcap file.

To trace the path to a destination

tracepath example.com
# example.com: replace with a host or IP address
# Use traceroute if tracepath is not installed
# Middle hops may block replies; focus on the destination and pattern

Shows the network path and possible MTU issues to a destination.

To connect to another system over SSH

ssh user@host
# user: remote username
# host: hostname or IP address
# -p port: custom SSH port
# -i key_file: use a specific private key

Starts a secure remote shell session.

To transfer a file securely to another system

scp capture.pcap user@host:/path/
# capture.pcap: local file to upload
# user@host:/path/: remote account, system, and destination
# -P port: custom SSH port; uppercase P for scp
# -r: recursively copy a directory

Copies a local capture file to a remote system over SSH.

Phase 5: Users and Privileges

Goal: understand identity, groups, sudo access, and account changes.

To check your current user

whoami

Shows the username for the current shell.

To check a user's ID and groups

id username
# username: replace with the account to inspect
# -u: UID only
# -nG: group names only

Shows UID, GID, and groups for a specific user.

To check a user's groups

groups username
# username: replace with the account to inspect
# Groups affect file access, sudo rules, and service permissions

Shows group memberships for a specific user.

To check your sudo permissions

sudo -l
# -l: list allowed sudo rules
# -U username: inspect another user only if you have permission
# NOPASSWD means sudo may not ask for a password for listed commands

Shows what commands your user can run with sudo.

To change a user password

sudo passwd username
# username: account whose password will change
# This is an account-changing action; confirm you are allowed to do it
# Use passwd without sudo to change your own password

Changes the password for a user account.

To lock a user account

sudo usermod -L username
# -L: lock the password field
# This may not stop active sessions or SSH-key access
# Check policy and document why the account was locked

Locks password authentication for a user account.

To unlock a user account

sudo usermod -U username
# -U: unlock the password field
# Unlock only when the reason for the lock is resolved
# Check login method and account policy after unlocking

Unlocks password authentication for a user account.

To add a user to a group

sudo usermod -aG group_name username
# -a: append instead of replacing group memberships
# -G group_name: supplementary group list
# Omitting -a can remove existing supplementary groups
# The user may need to log out and back in

Adds a user to a supplementary group.

To delete a user

sudo userdel username
# username: account to remove
# Check running processes, ownership, and data retention first
# This usually leaves the home directory behind

Removes a user account but normally leaves the home directory behind.

To delete a user with home directory

sudo userdel -r username
# -r: remove the home directory and mail spool
# Back up or review files before using this
# Do not use on accounts with evidence or data-retention requirements

Removes a user account and its home directory.

To create a new user account

sudo useradd -m -s /bin/bash username
# -m: create a home directory
# -s /bin/bash: set the login shell
# username: new account name
# Set a password separately with sudo passwd username if needed

Creates a user with a home directory and Bash as the login shell.

Phase 6: Files, Metadata, and Changes

Goal: inspect files, permissions, ownership, size, and recent changes.

To view file metadata

stat file_name
# file_name: replace with a file or folder path
# -c: custom output format on GNU systems
# Use when timestamps, ownership, permissions, or inode details matter

Shows file size, permissions, owner, access time, modify time, and change time.

To view file permissions clearly

ls -lah file_name
# -l: long format with permission bits
# -a: include hidden entries
# -h: human-readable sizes
# ls -ld folder_name: inspect the folder itself, not its contents

Shows permissions, owner, group, size, and modification time.

To copy files while preserving metadata

cp -av source_path destination_path
# -a: archive mode; preserves metadata and copies directories recursively
# -v: verbose output
# source_path and destination_path: verify both before copying
# -i: prompt before overwrite

Copies files or folders while preserving useful metadata and showing what is copied.

To move or rename a file safely

mv -i old_name new_name
# -i: prompt before overwrite
# mv file folder/: move into a folder
# mv old_name new_name: rename in the same folder
# Keep a copy first when rollback matters

Moves or renames a file and asks before overwriting an existing destination.

To change file permissions

chmod 640 file_name
# 640: owner read/write, group read, others no access
# +x: add execute permission, useful for scripts
# -R: recursive; use carefully because mistakes can break apps or expose data
# Check current permissions with ls -lah first

Changes who can read, write, or execute a file.

To change file ownership

sudo chown user:group file_name
# user:group: new owner and group
# file_name: file or folder to change
# -R: recursive ownership change; use only when required
# Check ownership before and after with ls -lah

Changes the owner and group assigned to a file or folder.

To find recently modified files

find /path -type f -mtime -1
# /path: smallest safe folder to search
# -type f: files only
# -type d: directories only
# -mtime -1: modified less than one day ago
# -ls: show metadata with results

Finds files modified within the last 24 hours.

To find large files

find /path -type f -size +100M
# /path: smallest safe folder to search
# -type f: files only
# -size +100M: larger than 100 MiB
# -xdev: do not cross into other mounted filesystems

Finds files larger than 100 MB.

To find hidden files

find /path -name ".*"
# /path: use a narrow scope such as a home directory
# -name ".*": names that start with a dot
# -type f: hidden files only
# -type d: hidden directories only
# Hidden does not automatically mean malicious

Finds hidden files and directories.

To find world-writable files

find /path -type f -perm -o+w
# /path: focused search scope
# -type f: files only
# -perm -o+w: others write bit is set
# Use -type d to check world-writable directories
# Some temporary directories are intentionally writable

Finds files that any user on the system can write to.

To calculate a file hash

sha256sum file_name
# file_name: file to verify
# sha256sum file_name > file_name.sha256: save a hash record
# -c file_name.sha256: verify from a saved hash file
# Hash before and after transfer when integrity matters

Creates a SHA-256 hash for integrity checking or evidence tracking.

To read a long file safely

less file_name
# file_name: file to view
# /pattern: search inside the file
# n: next search match
# q: quit
# +G: open at the end of the file

Opens a file in a pager without editing it.

To view the end of a file

tail -n 50 file_name
# -n 50: show the last 50 lines
# Change 50 to the amount of context you need
# -f: follow new lines as they are written
# Ctrl+C: stop following

Shows the last 50 lines of a file, useful for recent log entries.

To view the start of a file

head -n 20 file_name
# -n 20: show the first 20 lines
# Use before parsing unknown files so you understand the structure

Shows the first 20 lines of a file, useful for checking headers or file format.

Optional Phase 7: Services and Startup

Goal: check what runs automatically, what is active, and what failed.

To check services enabled at boot

systemctl list-unit-files --type=service --state=enabled
# list-unit-files: unit-file enablement, not current runtime state
# --type=service: service units only
# --state=enabled: enabled at boot
# Change enabled to disabled to review disabled services

Shows services configured to start automatically with the system.

To check currently running services

systemctl list-units --type=service --state=running
# list-units: loaded runtime units
# --type=service: service units only
# --state=running: active running services only
# Remove --state to see more service states

Shows services currently active on the system.

To check failed services

systemctl --failed
# --failed: units in failed state
# Check status and logs for any important failed service

Shows services that failed to start or crashed.

To check one service

systemctl status service_name
# service_name: real unit such as ssh, nginx, docker, or cron
# --no-pager: print output without opening a pager
# is-active: script-friendly active/inactive check
# is-enabled: check boot enablement

Shows whether a service is running, failed, disabled, or enabled.

To stop a service

sudo systemctl stop service_name
# stop: stop for the current boot only
# service_name: real unit to stop
# start: start it again
# Check status first; stopping SSH, network, database, or production services can break access

Stops a running service until it is started again or the system reboots.

To disable a service from boot

sudo systemctl disable service_name
# disable: change boot behavior
# --now: disable and stop immediately
# enable: allow it to start at boot again
# Document why before disabling security, logging, networking, or backup services

Prevents a service from starting automatically at boot.

To restart or reload a service

sudo systemctl restart service_name
# restart: fully stop and start the service
# reload: apply config without dropping sessions when supported
# reload-or-restart: reload if possible, restart otherwise
# Check status and logs afterward

Stops and starts a service, usually to apply configuration changes.

Optional Phase 8: Logs and Investigation

Goal: check what happened recently on the system.

To check recent system logs

journalctl --since "1 hour ago"
# --since: start time for the log window
# Use values like "10 minutes ago", "24 hours ago", or "2026-06-30 09:00"
# -n 100: last 100 log lines
# -f: follow logs live
# --no-pager: print output without opening a pager

Shows system logs from the last hour.

To check logs for one service

journalctl -u service_name --since "1 hour ago"
# -u service_name: logs for one systemd unit
# --since: investigation time window
# -f: follow that service live
# -b: current boot only

Shows recent logs for a specific service.

To check recent sudo usage

journalctl _COMM=sudo --since "24 hours ago"
# _COMM=sudo: filter logs where the command name is sudo
# --since: investigation time window
# Use as a lead; confirm important actions with other logs or records

Shows sudo commands used recently.

To check successful logins

last
# Use with w, journalctl, and service logs when confirming unusual sessions

Shows recent successful login sessions.

To check current logged-in users

w
# Shows user, terminal, source host, idle time, and current command

Shows who is logged in and what they are doing.

To check failed SSH login attempts

grep "Failed password" /var/log/auth.log
# Change the quoted pattern for different services or distro wording
# -i: case-insensitive matching
# tail -n 20: focus on recent matches
# Some systems use /var/log/secure or journalctl instead of auth.log

Shows failed SSH/password login attempts on Debian/Ubuntu systems.

To check successful SSH logins

grep "Accepted" /var/log/auth.log
# "Accepted": common SSH success pattern
# "Accepted publickey": key-based logins
# "Accepted password": password logins
# Confirm unusual logins with last, w, and service logs

Shows successful SSH login attempts on Debian/Ubuntu systems.

To follow a log file live

tail -f /var/log/auth.log
# -f: follow appended lines
# -n 100 -f: show recent context before following
# Change the path to the log you need
# Ctrl+C: stop following

Shows new log lines as they are written.

To review shell history

history | tail -n 50
# tail -n 50: show the last 50 history lines
# Change 50 to the amount you need
# History may be incomplete, disabled, edited, or split across shells
# Treat history as a lead, not proof by itself

Shows the last 50 commands from the current user's shell history.

Optional Phase 9: Packages and Application Checks

Goal: check whether a command exists, where it is located, and what package/application is installed.

To check if a command exists

which command_name
# command_name: replace with a binary such as curl or python3
# Useful interactively; command -v is usually better in scripts

Shows the path of a command if it exists in the system PATH.

To check command location more reliably

command -v command_name
# command_name: binary, shell builtin, function, or alias to check
# > /dev/null: hide output when you only need success or failure in scripts
# type command_name: show whether it is a binary, builtin, function, or alias

Shows how the shell resolves a command.

To find related binary, source, and manual paths

whereis command_name
# command_name: command to inspect
# -b: binaries only
# man command_name: full manual when documentation is needed

Shows common locations related to a command.

To check installed packages on Debian/Ubuntu

apt list --installed
# --installed: installed packages only
# Pipe to less when reviewing interactively
# dpkg -l: classic package table format

Lists installed packages on Debian/Ubuntu systems.

To search installed packages on Debian/Ubuntu

apt list --installed | grep package_name
# package_name: package or keyword to search for
# grep -i: case-insensitive matching
# apt-cache policy package_name: installed and candidate versions
# dpkg -L package_name: files installed by a package

Checks whether a specific package is installed.

To inspect package details on Debian/Ubuntu

apt show package_name
# package_name: package to review
# Use before installing so you understand what it is and where it comes from
# apt search keyword: find package names by keyword

Shows package description, version, dependencies, maintainer, and repository information.

Optional Phase 10: Secure Transfer and Evidence Handling

Goal: move files safely and keep basic integrity records.

To compress a folder

tar -czf archive.tar.gz folder_name
# -c: create a new archive
# -z: gzip compression
# -f archive.tar.gz: output file name; the name must come right after -f
# folder_name: folder to archive
# -v: verbose output

Creates a compressed archive of a folder.

To extract a compressed archive

tar -xzf archive.tar.gz
# -x: extract an archive
# -z: handle gzip compression
# -f archive.tar.gz: archive file to read
# -t: list contents before extracting
# -C destination_folder: extract into a specific folder

Extracts a gzip-compressed tar archive into the current directory.

To copy a file securely to another system

scp file_name user@host:/path/
# file_name: local file to upload
# user@host:/path/: remote account, system, and destination
# -P port: custom SSH port; uppercase P for scp
# -r: recursively copy a directory

Transfers a file securely over SSH.

To download a file securely from another system

scp user@host:/path/file_name .
# final .: download into the current directory
# Replace . with a local folder path for a specific destination
# -P port: custom SSH port; uppercase P for scp
# Quote remote paths that contain spaces

Downloads a file from a remote system over SSH.

To sync files with resume-friendly behavior

rsync -avP source_path user@host:/path/
# -a: archive mode with recursion and metadata preservation
# -v: verbose output
# -P: progress plus partial transfer handling
# --dry-run: preview important syncs first
# Trailing slash matters: source/ copies contents, source copies the directory

Copies files over SSH while preserving useful metadata and showing progress.

To verify file integrity

sha256sum file_name
# file_name: file to verify
# > file_name.sha256: save the hash record
# -c file_name.sha256: verify from the saved hash file
# Record hash, filename, timestamp, and system name for evidence

Creates a hash that can be used to confirm the file did not change.