Labs · Cyber Security
Lab: Make Your Own One-Page Defensive Command Cheat Sheet and Test Every Command in Your Lab
Course: Cyber Security · Chapter 49: Cheat Sheets
Chapter 49 gives ready-made cheat sheets; this lab makes you build and test your own, which is how commands really stick.
Chala mitrano! A cheat sheet you copied is forgotten in a week. A cheat sheet you built and tested yourself stays with you for years. Today we pick 20 commands from our labs, run every one on our own VM, write what the output should look like, and fit it on one page. Aapli swatahchi cheat sheet!
चला मित्रांनो! Copy केलेली cheat sheet आठवड्यात विसरली जाते. स्वतः बनवलेली आणि test केलेली cheat sheet वर्षानुवर्षं लक्षात राहते. आज आपण labs मधून 20 commands निवडणार, प्रत्येक आपल्या VM वर चालवणार, output कसा दिसायला हवा ते लिहिणार, आणि एका page मध्ये बसवणार. आपली स्वतःची cheat sheet!
चलो दोस्तों! Copy की हुई cheat sheet हफ़्ते में भूल जाती है। खुद बनाई और test की हुई cheat sheet सालों याद रहती है। आज हम labs से 20 commands चुनेंगे, हर एक अपने VM पर चलाएँगे, output कैसा दिखना चाहिए वो लिखेंगे, और एक page में फिट करेंगे। अपनी खुद की cheat sheet!
Suppose we are…
Suppose we are on the night shift in the SOC at Wipro. When an alert fires at 3 a.m., nobody wants to search Google for the right grep or ss command. Experienced analysts keep a tested one-page cheat sheet on their desk. We build ours from the commands we used in this course, and we test each one so we know it works on our systems.
Goal of this lab
By the end you will have:
- 20 commands in four groups: Check, Harden, Detect, Recover.
- Each command tested on your own VM, with a short "expected output" note and the lab it came from.
- A one-page PDF or printout.
What you need (all free)
- Your own Ubuntu Server VM with the tools from earlier labs (ufw, fail2ban, auditd). A text editor or Google Docs. About 45 minutes.
Safety and ethics
Your cheat sheet is for defending your own and authorised systems. Test every command only on your own VM. Keep real IP addresses, usernames and passwords off the printed sheet.
Steps
- Create a document with a table: Group, Task, Command, Expected output (short), Lab, Tested ✓.
-
Add these 20 starter commands (change or replace any to match your work). The comment after
#gives the task and the lab it came from:# CHECK sudo ss -tulpn # listening ports (Lab 2) getent group sudo # who is admin (Lab 26) apt list --upgradable # pending updates (Lab 23) df -h # disk usage (Lab 5) sudo find / -xdev -perm -4000 -type f 2>/dev/null # SUID files (Lab 26) # HARDEN sudo sshd -t # test SSH config (Lab 32) sudo sshd -T | grep -E "passwordauth|permitroot" # effective SSH settings (Lab 32) sudo ufw status verbose # firewall status (Lab 32) sudo nginx -t # test Nginx config (Lab 7) curl -I https://yourdomain # check security headers (Lab 8) # DETECT grep "Failed password" /var/log/auth.log | grep -oE "from [0-9.]+" | sort | uniq -c | sort -rn # failed SSH per IP (Lab 31) grep "Accepted" /var/log/auth.log # successful logins (Lab 31) last -n 10 # recent logins (Lab 6) sudo fail2ban-client status sshd # current bans (Lab 32) sudo ausearch -k identity -i | tail # audit events by key (Lab 36) # RECOVER sha256sum file # hash a file (Lab 28) sha256sum -c hashes.txt # verify hashes (Lab 28) sudo tar -czf /root/backups/etc-$(date +%F).tgz /etc # back up config (Lab 45) sudo tar -tzf /root/backups/etc-<date>.tgz | head # list backup contents (Lab 45) sudo systemctl restart ssh && systemctl status ssh --no-pager # restart and check (Lab 23) -
Start your VM and run each command. Fill Expected output in under 8 words, for example
ufw status→ "Status: active, 22/tcp ALLOW".What you should see: every command runs without "command not found". If one fails, install the tool or fix the command, then retest.
-
Tick Tested ✓ only after it worked on your VM. Remove commands you cannot make work, or note the fix.
- Add one "danger" line at the bottom of the Harden group: "Before restarting SSH or enabling a firewall, keep a second session open."
-
Make it fit one page: font 9–10 pt, landscape, narrow margins, short task names. Export to PDF (File → Download → PDF in Google Docs, or File → Save as → PDF in Word).
What you should see: all 20 commands readable on one A4 page.
-
Print it or keep the PDF on your phone. Next time you use a new command in a lab, test it and add it, replacing one you no longer need.
Ravindra Bagale's Tip
Note small differences between systems on your sheet: Amazon Linux uses journalctl -u sshd and has no /var/log/auth.log, while Ubuntu has both. A tested sheet tells you this before the 3 a.m. alert, not during it. Ratri teen la shant raha!
Ravindra Bagale's Tip – मराठी
Systems मधले छोटे फरक sheet वर नोंदवा: Amazon Linux मध्ये journalctl -u sshd वापरतात आणि /var/log/auth.log नसतो, तर Ubuntu मध्ये दोन्ही असतात. Test केलेली sheet हे रात्री 3 च्या alert आधीच सांगते, त्या वेळी नाही. रात्री तीनला शांत राहा!
Ravindra Bagale's Tip – हिंदी
Systems के छोटे फ़र्क sheet पर लिखो: Amazon Linux में journalctl -u sshd चलता है और /var/log/auth.log नहीं होता, जबकि Ubuntu में दोनों होते हैं। Test की हुई sheet ये बात रात 3 बजे के alert से पहले बताती है, उस वक़्त नहीं। रात तीन बजे शांत रहो!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Copying commands without running them | Typos and wrong flags at the worst moment | Test every line on your VM |
| Too many commands on the sheet | Nobody can find anything | 20 lines, one page |
| No expected output | You cannot tell good from bad results | Add a short expected result |
| Real IPs and usernames on a printout | Sensitive details left on a desk | Use placeholders |
| Never updating it | Old commands, missing new ones | Review the sheet monthly |
Self-check checklist
0 of 5 done
Try-at-home challenge
Your sheet has grep "Failed password" /var/log/auth.log. Write the equivalent command for Amazon Linux 2023, which has no auth.log, and test it on your EC2 server.
Check your answer
sudo journalctl -u sshd --since today | grep "Failed password" | grep -oE "from [0-9.]+" | sort | uniq -c | sort -rn. On Amazon Linux, SSH logs live in the systemd journal, so journalctl -u sshd replaces /var/log/auth.log (Lab 6).
Samjla ka? Pick, test, note the expected output, fit it on one page. Aata pudhe jaauya: Chapter 50 builds your bilingual glossary.