Linux Command List
Linux command list with arguments and category filter.
| Command | Category | Level | Description | Main arguments |
|---|---|---|---|---|
| 10 | Files | core | List directory content with metadata | -l long format -a include hidden files -h human-readable seed -R returnable indicating -t short by modification time -S short by file size |
| point | Files | core | Search files by name, type, size, or mtime | -name mesh -type f=file d=dir l=link -size +/-N[k/M/G] -mtime N days ago modified -exec run command on result - limit recovery |
| cp | Files | core | Copy files and directories | -r resource copy -p prevent timesteps and fashion -u copy only if newer -i pass -v verbose output |
| mv | Files | core | Move or rename files and directories | -i pass -u move only if newer -f %1 -v verbose output |
| rm | Files | core | Remove files or directories permanently | -r returnable -f force, ignore missing -i prompt beforee each removal -v verbose output |
| ln | Files | core | Create hard or semilic links | -s create symbolic link -f force over -v verbose output -r make relativeymlink |
| stat | Files | core | Display detail file and filesystem metadata | -f show filesystem status -c custom format string -t terse machine-readable output |
| file | Files | core | Descriptor file type regardless of extension | -i output -z look inside pressed files -b breef output without filename |
| rsync | Files | modern | Fast incremental file transfer - local or remote | -a archive mode (recursive + preserve) -v verbose output -z press data during transfer -P show progress + keep partial files --delete remove files not in source --dry-run simulate without changes --exclude skip pattern |
| fzf | Files | modern | Interactive fuzzy finish for files, history, and pipettes | --preview pipe to preview command --multimeters flow multiple selections -q start with initial queue --height % --bind kustomize key bindings |
| cat | Text | core | Concate and print file content to stdout | -n number -A show all non-printing chars -s suppress |
| 10 | Text | core | Interactively page through file content | -N show line numbers -S disable line wrapping -i case-intensive search -F exit if content points one screen |
| head | Text | core | Output the first | -n number of lines (default 10) -c of -q suppress filename heads |
| tal | Text | core | Output the last N lines of a file | -n number of lines (default 10) -f below file for new content -c of -q suppress filename heads |
| grep | Text | core | Search text using shelters and regular expressions | -i case-intensive match -r resource directory search -n prefix output with line number -v invert match (exclude patch) - E use extended regex (ERE) -P use Perl-compable regex -l print matching files only -c count -A/-B lines of context after/ before |
| sed | Text | core | Stream editor - filter and transform text in-place or piped | -i edit files in-place -n toppress output -e add script expression -r use extended regex s/old/new/g substitute panttern |
| awk | Text | core | Pattern scanning and structured text processing | -F set field separator -v signal variable before run -f read program from file NR current record number $1..$N access fields |
| short | Text | core | Short lines of text files | -n numeric short -r reverse short order -u output unique lines only -k short by key/field -t set field decimalr -h human-numeric assortment (1K, 2M) |
| cut | Text | core | Remove sections from each line of input | -d set field decimalr -f select field numbers -c select character position -b select byte positions |
| wc | Text | core | Count lines, words, and bytes in files | -l count lines only -w count words only -c count -m count characters |
| diff | Text | core | Compare files line by line and show differences | -u unified diff format -r company directories pursuant to article 4 (1) of directive 2013/34/eu -i ignore case differences -w ignore all whitespace |
| 3 | Text | core | Translate or delta characters from input | -d member of the commission -s squeeze reproduced characters -c complement the character set |
| bat | Text | modern | cat replacement with syntax highlighting and git makers | --style header, grid, numbers, changes --language yield -n show line numbers --diff show only changed lines --pager override pager |
| ripgarp (rg) | Text | modern | Extremely fast grep - respects .gitignore by default | -i case-intensive -n show line numbers -l list matching files only --type filter -A/-B lines of context --hidden include hidden files --no-ignore override .gitignore |
| jq | Text | modern | JSON processor - slice, filter, map, and transform | 'key' extract object field '.[]' -r raw string output (from quotes) --arg pass 'select' () 'conditional filter 'keys' list all keys of object |
| ps | Processes | core | Report a snapshot of current running processes | -e show all processes -f full-format lighting aux BSD-style all processes --forest show process -o custom output format |
| top | Processes | core | Interactive real-time process and resource monitor | -d update -u filter by username -n number -b match (non-inactive) mode kill process |
| htop | Processes | modern | Enhanced interactive process viewer with tree view and meters | -u filter by user -p watch specific PIDs -d left --no- force F5 toggle tree view F9 send signal to process |
| kit | Processes | core | Send a signal to a process by PID | -9 SIGKILL - force terminate immediately -15 SIGTERM - graceful shutdown (default) -1 SIGHUP - reload configuration -l list all available signals |
| killall | Processes | core | Send a signal to all processes | -9 force kill -15 graceful terminate -i interactive firm -u only processes of user -v verbose output |
| nice | Processes | core | Launch a command with adjusted CPU scheduling priority | -n naeneness value from -20 (highest) to 19 |
| renice | Processes | core | Change the priority of a running process | -n new nieneness value -p apply to PID -u apply to all processes of user -g apply to process group |
| nohup | Processes | core | Run command IMmune to terminal hangup (SIGHUP) | nohup cmd output goes to nohup.out by default |
| strace | Processes | modern | Track system calls and signals made by a process | -p attach to running PID -e %1 -o write output to file -f follow child processes (fork) -c print sum -T show |
| lsof | Processes | modern | List open files, network pockets, and device hands | -p list files for PID -u list files for user -i wool -t output PIDs only for scripting lsof /path what has this file open |
| systemctl | System | core | Control and query the system service manager | start / stop / restart manage service state enable / disable set boot behavior list-units --type=service all services daemon-reload reload unit files is-active / is-enabled check state |
| journalctl | System | core | Query and display systemd journal window | -u %1 -f continue log in real time -n show last N lines --since / --until time range -p filter by priority level (err, warm...) -o json structured JSON output --disk-usage show journeynal size |
| uname | System | core | Print system body and OS information | -a print all information -r kernel release version -m machine hardware architecture -n network hostname -s kernel |
| uptime | System | core | Show how long the system has been running | -p pretty human-readable format -s show |
| dmesg | System | core | Print or control the kernel ring buffer message log | -T human-readable timesteps -l filter by log level -f filter by facility --follow live stream new messages -H colored human output |
| sysctl | System | modern | Read and modify the parameters at runtime | -a list all current parameters -w write param=value -p load settings from file (default /etc/sysctl.conf) net.ipv4.ip forward=1 enable routing |
| time | System | modern | Query and change system block, timezone, and NTP | status st. Petersburg set-time 'YYYY-MM-DD HH:MM:SS' set-ntp true enabled NTP sync |
| env / export | System | core | Display, set, or export environment variable | export VAR=value set and export env list all current variations printenv Var print specific variable unset Var remove variable env -i cmd run with empirical environment |
| crontab | System | core | Schedule return tasks via the cron daemon | -e edit current user's crontab -l list current user's crontab -r remove current user's crontab -u user operated on another user's crontab format: min hr dom mon dow command |
| git | System | modern | Distributed version control - track and collaborate on code | status log-oneline--graph compact history diff HEAD changes since last committee stash push/pop hatche and restore changes rebase -i interactive squash/reorderer bisect start/good/bad find bug committee blame show line-by-line authority |
| as possible | System | modern | Agent IT automation and configuration management | -i record file path --check dry-run (from changes) -v / -vvv verbosity level --tag run only tagged task --limit restrict to host subject --vault-id decrypt vault secrets -m specific module for ad-hoc task |
| terraform | System | modern | Infrastructure as Code - provision cloud and on-prem resources | init initialize working directory plan preview changes apply only changes to infra destroy ear down resources state list show tracked resources importbring existing resource under management |
| chmod | Rights | core | Change file fashion bits | -R only monthly u/g/o/a user/group/other/all +/-/= add/ remove/set exactly 755 rwxr-xr-x common executable 644 rw-r--r--common file chmod +x make available |
| chown | Rights | core | Change file owner and/or group ownership | -R resource -v verbose, print each file user:group change both owner and group --from=user change only if current owner matches |
| chgrp | Rights | core | Change the group ownership of files | -R resource -v verbose output -h changes |
| sudo | Rights | core | Executive a command as root or another user | -u user run as specified user -i start root login shell -l list lowered communities -s run shell as target user -v validate and extend timestep -k invalidate cached credentials |
| umask | Rights | core | Set the default permission mask for new files | 022 files 644, dirs 755 027 files 640, dirs 750 (stracter) -S display -p print as umask command for reuse |
| getfacl / setfacl | Rights | modern | Get and set POSIX Access Control Lists on files | -m modification or add ACL entry -x remove specific ACL entry -R only monthly -b remove all extended ACL entities -d set default ACL (for new files in dir) getfacel display all ACL entities |
| auditcl | Rights | modern | Configure the Linux Audit subsystem with watch rules | -w add filesystem watch on path -p permission filter: r w x a -l list all current rules -D delete all audit rules asearch -f search window by file information general audit reports |
| passwd | Rights | core | Change User Password and manage account blocks | -l lock user account -u unlock user account -e force -d delete password --stdin read password from stdin (RHEL) |
| ip | Network | core | Manage network interfaces, addresses, routes, and ARPs | add show display all IP addresses addr add/del add/remove address route show display selectable link set up/downbring interface up or down next show display ARP table rule list show policy setting rules |
| tn | Network | core | Socket statistics - modern replacement for netstat | -t TCP pockets -u UDP pockets -l litering pockets only -n numeric (no hostname resolution) -p show process using pocket -s print summary statistics -4/-6 IPv4 or IPv6 only |
| ping | Network | core | Test network host reachability using ICMP echo | -c number of packages -i interval between packages -t set IP TTL value -s package payload size -W time |
| tracoute | Network | core | Track the network path packages take to a host | -n numeric output, skip DNS lookup -m set maximum TTL (hops) -w wait timeout per probe -I use ICMP echo requests -T use TCP SYN package |
| dig | Network | core | DNA query tool - lookup and troubleshoot records | + +trace follow full delegation chain server ANY request all record types AAAA request IPv6 address record + |
| nslookup | Network | core | Interactive and non-interactive DNA lookup | nslookup domain basic lookup nslookup domain server set type=MX change queue type |
| sh | Network | core | Secure Shell - remote login, execution, and tunneling | -i identity (private key) file -p remote port number -L local port forwarding -R remote port forwarding -J jump -N do not execute remote command -X enabled X11 forwarding -v verbose debug output |
| nftables (nft) | Network | modern | Modern kernel package filtering - replicates iptables | list ruleset show all rules add table ip create table add chain add chain to table add roule append filtering roule flush rouleset delete all rules -f file load from rule file |
| iptables | Network | core | Kernel IPv4 package filtering and NAT firewall | -A append rules to chain -D delete specific rule -L list chain rules -F flush / clear chain -P set default chain policy -j jump to target: ACCEPT DROP REJECT |
| firewall-cmd | Network | modern | Management tool for fuel (used on RHEL/CentOS/Rocky) | --list-all show zone config --add-port=80/tcp open port --add-service=https all service --remove-port close port --permanent persimmon --reload apply permanent rules |
| curl | Transmission | core | Transfer data over HTTP, HTTPS, FTP, and many other protons | -o write output to file -X specific HTTP method (GET POST PUT...) -H add custom request header -d send POST body data -L follow 3xx redirects -k skip TLS certificate verification --retry N rtry on transient file --compressed request and handle gzip --data-binary send raw binary data -u user:pass HTTP basic authentication --form send multipart/form-data -s silent mode (from progress bar) |
| wget | Transmission | core | Non-interactive network file downloader | -r resource download -O save to specified filename -q quiet mode -c continue interrupted download -P set local directory prefix --spider check URL without downloading --limit-rate third download speed --user / --password authentication |
| scp | Transmission | core | Securely copy files between hosts over SSH | -r resource copy of directories -P specific remote port -i identity (private key) file -p prevent timesteps and fashion -v verbose debug output |
| sftp | Transmission | core | Interactive secure file transfer over SSH | -P specify port -i identity file get / put download / upload file ls / lls list remote / local files mget / mput match transfer |
| tcpdump | Monitoring | modern | Capture and analysis raw network traffic packages | -i specific interface -w write package to pcap file -r read from pcap file -n no hostname/port resolution host X filter by IP address port -A print payload in ASCII -c N receipt N packages 'tcp and port 443' BPF filter example |
| nethog | Monitoring | modern | Per-process real-time network bandwideth monitor | -d refresh -t run in track (non-interactive) mode -p enabled promiscuous fashion device specific interface to monitor |
| iftop | Monitoring | modern | Display real-time band | -i network interface to choose on -n suppress DNA hostname lookups -P show port numbers -B display |
| iostat | Monitoring | modern | Report CPU utilisation and I/O statistics for devices | -x extended device statistics -d display device I/O only -c display CPU statistics only -k display stats -m display stats intercount |
| vmstat | Monitoring | modern | Report virtual memory, CPU, and disk I/O statistics | -s display memory statistics table -d display disk statistics -w side output format intercount periodic sampling |
| 4 | Monitoring | modern | Collection, report, and save system activity data | -u CPU utilisation -r memory statistics -n DEV network interface status -d disk activity -f read from data file -s specify start time 1 5 single every second, 5 times |
| granules | Monitoring | modern | Cross-platform courses system monitor with export plugins | -w start as web server --port web server port -1 per-CPU core display -t refresh interval --export csv/json output data --browser discover remote glosses |
| netstat | Monitoring | core | Network statistics - legacy tool | -t TCP connections -u UDP pockets -l lighting port only -n numeric IPs and port -p show program using pocket -r show selectable |
| df | Discs | core | Report file system disk space usage | -h human-readable seed -T show filesystem type -i show -a include all files -x exclude filesystem type |
| du | Discs | core | Estimate file and directory space on disk | -h human-readable output -s display summary total only -a report for all files -d N limit depth to N level --exclude skip matching pattern du -sh ./* size of each item in CWD |
| lsblk | Discs | core | List block devices and parts in tree format | -a show all including empirical devices -f show filesystem and UUID -o specialy output lumps -d do not show device children -p print full device path |
| fdisk | Discs | core | Manipulate MBR partition tables interactively | -l list all partition tablets -u %1 zettameters p print table n new d delete w write and exit q quit no save |
| parted | Discs | core | Partition manipulation - support GPT and large disc | -l list all disks and parts mkpart create new partition resizepart resize existing partition print show partition table rm N remove partition N |
| mount / umount | Discs | core | Attach or detailed filesystems to the directory tree | -t specific filesystem type -o mount options (rw, ro, noexec...) -a mount all entities in /etc/fstab -r mount as read-only --bind %1 umount -l lazy unmount |
| lvm (pvs/vgs/lvs) | Discs | modern | Logical Volume Manager | pvcreate initialize physical volume vgcreate create volume group lvcreate -L -n created logical volume lvextend -L +size grow EN lvreduce -L-size shrimp vgdisplay / endisplay inspect |
| smartctl | Discs | modern | Monitor disc health using S.M.A.R.T. diagnostics | -a print all SMART information -H check health summation only -t short/long run self-test -l selftest view test results --scan find all SMART-capable drives |
| tar | core | Create and extract archives; compose with compressors | -c create new archive -x extract archive contents -z filter through gzip (.tar.gz) -j filter through bzip2 (.tar.bz2) --zstd filter through zstd (.tar.zst) -v verbose - list files processed -f specify archive filename -t list archive contents without extract --strip-compponents N strip N path level |
|
| gzip / gunzip | core | Compass or decompress files in .gz format | -d decompress file -k keep original file -v verbose output -9 maximum compression level -1 fascest compression -l list compression statistics |
|
| zip / unzip | core | Create or extract ZIP archives | zip -r returnive add directory -e insert with password -9 maximum compression unzip -l list archive contents unzip -d dir extract to directory -v verbose listing |
|
| zstd | modern | Fast modern compression - high speed at good ratios | -d decompress file -k keep original -T0 use all CPU threes -19 high compression level --fast a.k.a --progress show progress during compress |
|
| nmap | Intrusion test | security | Network Scanner - host discovery, port scan, service detection | -sV detect service versions -sC run default NSE scripts -O enable OS fingerprinting -p specific port range (e.g. 1-65535) -A aggressive: OS+version+scripts+traceroute --script nSE Script -oN / -oX output to file (normal/XML) -Pn slip host discovery (size up) -sS TCP SYN stealth scan |
| netcat (nc) | Intrusion test | security | TCP/UDP multipurpose tool - banner grab, file pipe, reverse shell | -l listen mode (server side) -v verbose output -z zero-I/O scan mode (port check) -u use UDP -e execute command on connect -p specific source port nc -lvnp 4444 listener for reverse shell |
| openssl | Intrusion test | security | TLS/SSL toolkit - certificates, keys, entry, and testing | s client -connect host:443 test TLS x509 -in cert.pem -text inspect cert genrsa -out key.pem 4096 generate RSA key req -new generation CSR enc -aes-256-cbc encrypt/decrypt file verify -CAfile validate certificate chain speed benchmark cipher performance |
| ssh-keygen | Intrusion test | security | Generation, management, and convert SSH authentication keys | -t ed25519 modern key type (recommended) -b 4096 key bit length (for RWA) -C 'comment' add identifying comment -f exit file path -p change or remove -l print -A generate all default host key types |
| gpg | Intrusion test | security | GNU Privacy Guard - encrypt, decrypt, sign, and verify data | --gen-key generic new key pair -e -r recipient encrypt file --decrypt decrypt .gpg file -s create detailed signature --verify verify signature file --armo output in ASCII armor format --export / --import key management |
| linnis | Intrusion test | security | Security auditing tool - scan and harden Linux systems | audit system run full system audit --test-from-group auth focus on group --quiet volume --no-colors played --pentest pentest-oriented mode --report-file write report to file |
| file2ban-client | Intrusion test | security | Manage file2ban - auto-ban IPs on reviewed files | status status set sshd unbanip IP manually unban reload removal configuration start / stop control service banned list currently banned IPs |
| hashcat | Intrusion test | security | GPU-qualified password hash cracking tool | -m hash type (0=MD5, 1800=sha512crypt) -a image mode (0=dict, 3=bruteforce) -w workload profile (12.2006,4) -r apply roules file --show show already cracked hashes --status live progress update |
| john (JtR) | Intrusion test | security | CPU-based password hash cracker with auto-detection | --wordlist dictionary file path --rolls apply mangling rules --format specific hash type --show display cracked passwords --fork N run N parallel processes unshadow merge passwd and shadow |
| docker | Containers | modern | Build, ship, and run application containers | run -d run container detached run --rm auto-remove on exit exec -it open shell in running container window -f follow container log stream inspect detailed JSON metadata ps -a list all holders (including stopped) building -t building image with tag network ls / inspection management networks volume ls/inspect manage volumes system usage |
| kubectl | Containers | modern | CLI to manage Cubanetes clusters and jobs | get pot/svc/nodes list resources describe pod applicable -f manifest.yaml employment/update resource exec -it pod -- bash shell into pod window -f pod follow pod log stream top node / top pod resource use rollout status/undo employment control port-ward forward local port to pod config use-text |
| podman | Containers | modern | Rootless daemonless OCI contains engine - docker-compatible | run --rm auto-remove after exit --user 1000 run as non-root UID --pod attach to pod group -v single mount host volume generale kube export as Kubernetes Yaml play kube run from Cubanettes YAML pod creation / start / stop manage pot |
| helm | Containers | modern | Cubanettes package manager for tempered chart employments | install release upgrade --install upsert employment rollback release list show all requested releases value repo add / update management chart repos template tender manifests locally |