PowerShell and Linux: Getting Into Files

A beginner session built around one wall: not being able to get into specific files. The filesystem as a building, PowerShell's verb-noun naming rule and three lifeline commands, finding hidden files anywhere on a drive and reading them, pipelines and the comparison operators, the same ideas in Linux with a translation table, why case sensitivity and permissions cause most 'file not there' errors, and a six-question checklist for being stuck in a room.

Subject: Cyber Security 101 · 76 slides · code lesson

Open the interactive version of this deck · Homework for this lesson

What this lesson covers

The lesson, slide by slide

1. PowerShell and Linux: Getting Into Files

Title

Cyber Security 101 · Session 1

The room you are on now, and the wall you described

2. What we are doing tonight

Objectives

You said you can follow the basic commands but the specific tasks lose you, and that getting into particular files is the problem. That is a very specific diagnosis and it is a fixable one.

Everything is in the actual rooms. I will keep my talking short and your typing long.

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — the Cyber Security 101 path you are on

3. One Mental Model

Section

Section 1

4. Start with where you got stuck

Warm-up

Two minutes, before anything new.

Discussion prompt

Think of the last task in the PowerShell room that stopped you. What did the task ask for, and what did you type?

Hint: Say what the task wanted in your own words, not in the room's words.

Answer:

Almost every beginner stuck point is one of four things: the file is hidden, you are in a different folder than you think, the path is relative when you meant absolute, or you do not have permission.

None of those is about knowing more commands. All four are checkable in about ten seconds each, and by the end of tonight you will have a checklist for exactly them.

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — Windows PowerShell room

5. The building

Concept

A drive is a building. Folders are rooms, and rooms contain rooms. Files are things sitting in a room. Where am I means which room you are standing in.

A path is just the list of doors you walk through to get somewhere. An absolute path starts at the front door of the building. A relative path starts from wherever you are standing right now.

Microsoft Learn — PowerShell documentation — about_Path_Syntax

6. The building, drawn

Picture it

Four levels, and one file at the bottom.

Figure (svg): Nested boxes showing the C drive containing Users containing Eden containing notes dot txt, labelled as building, floor, room and object

Absolute starts at the outside; relative starts where you are.

Two small rules that save a lot of pain: put quotes around any path with a space in it, and press Tab to let the shell finish a name for you.

7. Absolute or relative?

Matching

You are standing in C:\Users\Eden.

Match the pairs

  • l1. C:\Users\Eden\Desktop
  • l2. .\Desktop
  • l3. ..\Public
  • l4. C:\Windows\System32
  • r1. absolute, and it is where you already are plus one room
  • r2. relative, meaning Desktop inside this room
  • r3. relative, meaning step back out one room, then into Public
  • r4. absolute, and completely elsewhere in the building

Why: A single dot means here, and two dots mean the room outside this one. Anything starting with a drive letter is absolute and does not care where you are standing.

8. Every command is a verb and a noun

Concept

PowerShell commands are named to a rule. The verb says what you are doing, the noun says what you are doing it to, and options come after with a dash in front.

# ---------- PowerShell ----------
Get-ChildItem -Path C:\Users -Force

# ---------- Linux ----------
ls -la /home
piecemeaningthe same piece in Linux
Getthe verb: look at somethingbaked into the name; ls just means list
ChildItemthe noun: the things inside a folderalso baked in; ls always lists a folder
-Pathan option name, always with a dashthere is no option name, the path just follows
C:\Usersthe value for that option/home
-Forcean option with no value; a switch-a, bundled into the -la above

Both lines do exactly the same job. PowerShell spells everything out, which makes it long but guessable. Linux abbreviates everything, which makes it short but something you have to learn. Neither is harder once you know that -Force and -a are the same idea.

If you can say the verb and the noun of what a task is asking for, you can usually guess the PowerShell command before looking it up. In Linux you guess the letter instead, which is what the manual page is for.

Microsoft Learn — about_Comparison_Operators, and the approved verbs list — the approved verbs list

9. Verb, then noun

Picture it

Six verbs cover most of what the room asks for.

Figure (svg): The command Get-ChildItem split into its verb and noun, with a table of six common verbs and their plain meanings

Get, Set, New, Remove, Copy, Move.

10. Guess the command

Prediction

Do not look it up. Use the rule.

Predict first

The task says: make a new folder. What is the command probably called?

  • Make-Folder
  • New-Item
  • Create-Directory
  • Add-Folder

Correct: New-Item.

Why: The verb for making something is New. The noun PowerShell uses for both files and folders is Item, with a type option to say which. Make and Create are not approved verbs, which is why guessing from the verb list works so reliably.

11. Three lifelines, before you ask anyone

Concept

These three exist so you are never fully stuck, and they are worth using before searching the internet.

# ---------- PowerShell ----------
Get-Command -Name *file*         # what commands exist about this?
Get-Help Get-ChildItem -Examples  # show me it being used
Get-Alias ls                      # what is ls really called?

# ---------- Linux ----------
apropos file                      # what commands exist about this?
man ls                            # show me the manual, q to quit
type ls                           # what is ls really called?
when to reach for itPowerShellLinux
you do not know the command nameGet-Command -Name fileapropos file
you know the name but not the optionsGet-Help <name> -Examplesman <name>
the room asks for the real nameGet-Alias lstype ls

Both shells have all three lifelines; only the spelling changes. The Linux manual opens in a pager, so remember that q gets you out of it, the same q that gets you out of less.

That last one matters for the room specifically: ls and dir and cat are nicknames, and sometimes the answer box wants the real name.

Microsoft Learn — PowerShell documentation — Get-Command and Get-Help

12. The three lifelines

Picture it

In this order.

Figure (svg): Three boxes listing Get-Command for finding a command, Get-Help with examples, and Get-Alias for real cmdlet names

Ten seconds each, and they answer most room questions.

13. Four keys that save more time than any command

Concept

None of these is a command and none of them is ever the answer to a room question. They are the difference between typing a line in ten seconds and typing it in a minute, and between a typo you spot and a typo you spend five minutes on.

keywhat it doeswhy it matters tonight
Tabfinishes the name you started typingno typos, correct capitals, and it adds the quotes for you
Up arrowbrings back the command you just ranchange one word instead of retyping the whole line
Ctrl and C togetherstops a command that is still runninga search of the whole drive can run for minutes
cls, or clear in Linuxwipes the screenwhen the thing you need has scrolled out of sight

Tab is the important one. Type the first three or four letters of a name and press it. If nothing happens, the name you started typing does not exist in this folder, and you have learned that in half a second rather than by reading an error.

Microsoft Learn — PowerShell documentation — PSReadLine key bindings

14. Finding and Reading Files

Section

Section 2

15. Where am I, and what is here

Concept

Two commands, and they are the first two things to type whenever anything goes wrong.

# ---------- PowerShell ----------
Get-Location                 # where am I
Get-ChildItem                # what is here
Get-ChildItem -Force         # now including hidden items
Set-Location C:\Users        # go somewhere else

# ---------- Linux ----------
pwd                          # where am I
ls                           # what is here
ls -la                       # now including hidden items
cd /home                     # go somewhere else
what it answersPowerShellLinux
which room am I standing inGet-Locationpwd
what is in this roomGet-ChildItemls
what is in this room, hidden things includedGet-ChildItem -Forcels -la
go to another roomSet-Location <path>cd <path>

The highlighted line is the same idea in both shells and it is the one that solves most 'the file is not there' problems. In PowerShell it is a word, in Linux it is a letter.

Microsoft Learn — PowerShell documentation — Get-ChildItem

16. The Mode column, and the hidden file

Picture it

Three items in one folder. Only two of them showed up the first time.

Figure (svg): A listing with a directory, an ordinary file, and a hidden file whose Mode column contains an h, highlighted

A file that is not there is very often a hidden file.

This is the first of the four beginner walls. If the room says a file exists and you cannot see it, add -Force before doing anything else.

17. Where is the file?

Prediction

The room says there is a file called flag.txt in your home folder. Get-ChildItem shows nothing.

Predict first

What do you try first?

  • Add -Force, because it may be hidden
  • Reboot the machine
  • Ask for a hint
  • Search the entire drive

Correct: Add -Force.

Why: Hidden is by far the most common explanation, and checking costs five characters. Searching the whole drive is the next step if that fails, and it is much slower. This ordering is the whole point of having a checklist.

18. Worked example: find a file when you do not know where it is

Worked example

This is the command you will use in nearly every room from here on.

Start from the top of the drive and go all the way down

Why: Recurse means look inside every folder, and every folder inside those.

Filter by name so the output is readable

Why: Filter takes a wildcard. A star means anything.

Silence the access-denied errors

Why: Without this the real answer scrolls off the top of the screen in a wall of red. It does not hide your results, only the complaints.

# ---------- PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Filter "*.txt" -ErrorAction SilentlyContinue

# ---------- Linux ----------
find / -name "*.txt" 2>/dev/null
the piecewithout itwith itthe Linux spelling
-Recurseonly the top folder is searchedevery folder underneath is searchedfind does this by default
-Filterthousands of files listedonly the ones you asked for-name "*.txt"
-ErrorAction SilentlyContinuescreens of red access-denied textjust the results2>/dev/null
-Path C:\nothing to searchstart from the top of the drivethe / straight after find

The two lines look nothing alike and are the same command. Both say: start here, go all the way down, match this name, and do not tell me about folders I am not allowed to open.

Verify: by running it without the last option once

Why: Do it once, on purpose, so you see what it is hiding. Then always use it. Knowing what a flag suppresses is different from copying it because someone said to.

19. The find command, one piece at a time

Picture it

Five pieces. None of them is mysterious once it is separated out.

Figure (svg): The recursive search command broken into five labelled parts: the command, the starting path, recurse, filter, and error action

Say each piece out loud as you type it.

20. Reading what you found

Concept

Once you have the file, three commands read it, and two of them stop you drowning in a long one.

# ---------- PowerShell ----------
Get-Content .\flag.txt                  # the whole file
Get-Content .\big.log -TotalCount 10    # first ten lines
Get-Content .\big.log -Tail 10          # last ten lines

# ---------- Linux ----------
cat flag.txt                           # the whole file
head -n 10 big.log                     # first ten lines
tail -n 10 big.log                     # last ten lines
showsPowerShellLinuxuse it when
the whole fileGet-Content flag.txtcat flag.txtthe file is short
the first ten linesGet-Content big.log -TotalCount 10head -n 10 big.logyou want the header
the last ten linesGet-Content big.log -Tail 10tail -n 10 big.logyou want the newest log entries

The Linux names are the giveaway: head is the top of the file and tail is the bottom. PowerShell borrowed Tail and invented TotalCount for the other one, which is the less memorable half of the pair.

Microsoft Learn — PowerShell documentation — Get-Content

21. Searching inside files

Concept

Finding the file is half the job. Finding the line inside it is the other half, and it is the same command in both worlds under a different name.

# ---------- PowerShell ----------
Select-String -Path .\notes.txt -Pattern "password"
Get-ChildItem -Recurse -Filter "*.txt" | Select-String -Pattern "flag"

# ---------- Linux ----------
grep "password" notes.txt
grep -r "flag" --include="*.txt" .
what it doesPowerShellLinux
look inside one file for textSelect-String -Path notes.txtgrep "password" notes.txt
the text you are looking for-Pattern "password"the first argument after grep
hand results to the next commandthe vertical barthe vertical bar, identically
search inside every text file below herelisting piped into Select-Stringgrep -r

That vertical bar is the pipe, and it is the single most useful character in either shell. It is the one piece of punctuation that is spelt the same in both.

That vertical bar is the pipe, and it is the single most useful character in either shell.

Microsoft Learn — PowerShell documentation — Select-String

22. Trap: looking in one folder and concluding the file is not there

Trap

The trap

The room says the flag is somewhere on the machine.

Annotate

  • No -Recurse, so this looks only in the room you are standing in.
  • No -Force, so a hidden flag would not appear even if it were here.
  • The Linux version has the same two holes: ls without -a hides dotfiles, and without -R it never leaves this folder.

Get no output, and assume the task is broken

Why: The command was correct and the search area was one folder out of thousands.

The fix

Search the whole drive, include hidden items, and silence the noise.

# ---------- PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Force -Filter "flag*" -ErrorAction SilentlyContinue

# ---------- Linux ----------
find / -name "flag*" 2>/dev/null
searchfolders looked inhidden includedthe Linux spelling
no options1nols
-Recurseall of themnols -R
-Recurse -Forceall of themyesfind, which shows hidden files anyway

That last row is worth remembering: find has no -Force because it never hid anything from you in the first place. The Linux search is the easier of the two to get right.

Make this your default

Why: Type the long version every time until it is muscle memory. It costs three seconds and it removes an entire category of being stuck.

23. Pattern: the three commands to type first

Pattern

Whenever anything goes wrong, before thinking, type these three. They cost five seconds and they answer most of it.

  1. Where am I? Get-Location, or pwd in Linux.
  2. What is actually here? Get-ChildItem -Force, or ls -la. The Force and the a are not optional.
  3. What is this command supposed to do? Get-Help with -Examples, or man.

Notice that none of the three requires you to know anything about the task. They are pure orientation, and orientation is what is missing when you feel stuck.

Microsoft Learn — PowerShell documentation — Get-Location, Get-ChildItem, Get-Help

24. Build the find command

Fill the middle

You want every text file on the C drive, hidden ones included, without the red error noise.

Fill in the blanks

Get-ChildItem -Path C: -Recurse -Force -Filter "*.txt" -ErrorAction SilentlyContinue

Why: Those three options are the difference between a command that finds nothing and one that finds the flag. Recurse controls where it looks, Force controls what counts as visible, and the error action controls whether you can read the output.

25. Trap: a path with a space in it

Trap

The trap

Trying to enter a folder whose name has a space.

Annotate

  • The shell splits the line at the space, so it reads two separate things.
  • It tries to go to C:\Program and complains that it does not exist.
  • Linux does exactly the same thing: it tries to enter /home/eden/my and never sees the word notes.

Conclude the folder is missing

Why: It is right there. The command never saw the whole name.

The fix

Quote it, or let Tab do it for you.

# ---------- PowerShell ----------
Set-Location "C:\Program Files"

# ---------- Linux ----------
cd "/home/eden/my notes"
cd /home/eden/my\ notes
what you typewhat the shell seesresult
C:\Program Filestwo argumentserror
"C:\Program Files"one argumentworks
C:\Prog then Tabthe shell quotes it for youworks
/home/eden/my notestwo argumentserror
"/home/eden/my notes"one argumentworks
/home/eden/my\ notesthe backslash escapes the spaceworks

Linux gives you a second repair Windows does not: a backslash immediately before a space tells the shell to treat that space as part of the name. Quotes work in both, so quotes are the habit worth having.

Use Tab completion by default

Why: Type the first few letters and press Tab. It fills in the exact name, adds quotes when needed, and gets the capitalisation right, which matters enormously in Linux.

26. Check: which command finds a hidden file everywhere?

Check

Solve it on paper before you click.

Check your understanding

Which command searches the whole C drive, including hidden items, for anything starting with flag?

  • A. Get-ChildItem -Path C:\ -Recurse -Force -Filter "flag*" -ErrorAction SilentlyContinue (correct)
  • B. Get-ChildItem -Filter "flag*"
  • C. Get-Content -Path C:\ -Recurse
  • D. Select-String -Pattern "flag"

Answer: A

Why: Recurse goes down through every folder, Force includes hidden items, Filter narrows the names, and the error action hides the access-denied complaints so the result is readable.

Why B tempts people
This searches only the current folder and skips hidden items, which are the two commonest reasons a file looks missing.
Why C tempts people
Get-Content reads the contents of a file. It cannot list or search folders, and a drive is not a file.
Why D tempts people
Select-String looks inside files for text. It is the right tool for finding a line, not for finding a file by name.

27. Turning the Task into a Command

Section

Section 3

28. Read the question backwards

Concept

This is the part you said is hardest: you know the commands, but not which one the room is asking for. The fix is to stop reading the question for a command and start reading it for an answer shape.

Ask one thing first: when I have the answer, what will it look like? A name? A number? A line of text? The command follows from that, not from the wording.

what the answer will look likehow the room usually words itwhat produces it
a file or folder namewhat is the name of...Get-ChildItem, then read the Name column
a numberhow many...the listing command, piped into Measure-Object
the contents of a small filewhat is the flag / what does it sayGet-Content, or cat in Linux
one line out of a big filewhich line mentions... / what is the entry for...Select-String, or grep in Linux
a property of a filethe size / the hash / the dateGet-FileHash, or a column of Get-ChildItem
a fact about the machinewhich user / what version / what addresswhoami, Get-LocalUser, Get-NetIPConfiguration

Six rows covers almost every question in the 101 rooms. When a question does not fit any of them, it is usually two of them stacked: find the file first, then read it.

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — Cyber Security 101, the Windows PowerShell room

29. Match the task to the command

Translation

Five tasks worded the way a room words them. Decide the answer shape first.

Match the pairs

  • l1. How many files are in the Documents folder?
  • l2. What is the name of the hidden file in this folder?
  • l3. What is the flag inside secret.txt?
  • l4. Where on the drive is the file called backup.zip?
  • l5. Which line of app.log mentions a failed login?
  • r1. Get-ChildItem | Measure-Object
  • r2. Get-ChildItem -Force
  • r3. Get-Content .\secret.txt
  • r4. Get-ChildItem -Path C:\ -Recurse -Filter backup.zip
  • r5. Select-String -Path .\app.log -Pattern failed

Why: Only two of the five needed a command you had not already met. The work was reading the question: a count needs Measure-Object, a name needs a listing, contents need Get-Content, an unknown location needs -Recurse, and a line inside a file needs Select-String. Notice that l2 and l4 both look like 'find a file' but one is hidden here and the other is somewhere unknown, and that is what decides between -Force and -Recurse.

30. Worked example: a room task, question to answer

Worked example

The task: 'A hidden file in the Public folder contains the flag. What is it?' That is two of the six rows stacked, a name and then contents.

# ---------- PowerShell ----------
Set-Location C:\Users\Public
Get-ChildItem
Get-ChildItem -Force
Get-Content .\flag.txt

# ---------- Linux ----------
cd /home/eden
ls
ls -la
cat .flag.txt
you type (PowerShell / Linux)what appearswhat it tells you
Set-Location C:\Users\Public / cd /home/edenthe prompt changes to show the new folderyou are in the right folder now
Get-ChildItem / lsDesktop, Documents, Downloadsno flag file, and this is where most people stop
Get-ChildItem -Force / ls -laone more row: flag.txt with h in Mode, or .flag.txt with a leading dotit was there the whole time, just hidden
Get-Content .\flag.txt / cat .flag.txtTHM followed by the flag stringthat string is what goes in the answer box

The third row is the same discovery in two costumes. Windows hides a file with an attribute you can only see in the Mode column; Linux hides it with a dot at the front of the name. Both are revealed by one extra character on the listing command.

Decide the answer shape before typing

Why: The question wants the contents of a file, so the last command was always going to be Get-Content. Everything before it exists only to learn the file name.

Go to the folder rather than typing long paths

Why: Set-Location once, and then every path afterwards is short enough to type without mistakes.

Add -Force the moment a listing looks empty

Why: The word hidden in the question is a direct instruction to use it.

Verify: by checking the answer looks like an answer

Why: A flag has a recognisable shape. If Get-Content prints a wall of text, you opened the wrong file, and the fix is to go back one step rather than to reread the question.

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — the Windows PowerShell room tasks

31. The same task, as the screen shows it

Picture it

Three commands and their output, exactly as they appear.

Figure (svg): A PowerShell session listing a folder, listing it again with -Force so a hidden flag file appears, and then reading that file

The only difference between the first listing and the second is -Force.

Two things worth noticing. The prompt tells you which folder you are in, so you never have to wonder. And the run that found the file looks identical to the run that did not, apart from one word.

32. The five messages you will actually see

Concept

An error is not a failure, it is the shell answering a different question than the one you asked. Three of these five say the file does not exist, and two say it does exist but you cannot have it. Telling those apart is the most useful reading skill in this room.

the messagewhat it really meansyour next move
Cannot find path ... because it does not existwrong path, wrong spelling, or the file is hiddenGet-ChildItem -Force here, then retype the name using Tab
is not recognized as the name of a cmdletthe command itself is misspelt or does not existGet-Command with a wildcard, for example Get-Command hash
Access to the path is deniedthe file exists and you were told nowhoami, then note it for the room and move on
No such file or directory (Linux)wrong name, wrong folder, or wrong capitalsls -la, then retype with Tab
Permission denied (Linux)it exists and you were told nols -l on the file, then id, then sudo -l

The two access messages are progress, not defeat. They confirm the file is real and that you found it, which is often exactly what the room wanted you to discover.

Microsoft Learn — PowerShell documentation — PowerShell error records

Linux manual pages — the shell manual pages

33. Read the error, not the command

Error analysis

PowerShell prints a lot of an error. Almost all of it is about where you typed it, which you already know.

Annotate

  • The first line of the error is the whole message. Read it and stop.
  • It prints the full path it tried. Compare that against where you believe the file is, and the mismatch is usually the entire answer.
  • 'Does not exist' means 'not visible to me'. Run Get-ChildItem -Force before you believe it.
  • This line tells you the error came from character one of line one. You typed it, so this tells you nothing. Skip it every time.
  • Linux says the same thing in one short line: the tool name, the file, the problem. There is no At line noise to skip.
  • It does not print the full path, so run pwd first if you are unsure which folder it was looking in. That is the one thing PowerShell gives you for free.

The habit worth building tonight: when red text appears, read only the sentence, and specifically read the path in the quotes. Nine times out of ten you are one folder away or one capital letter away.

Microsoft Learn — PowerShell documentation — PowerShell error records

34. The Rest of the Room

Section

Section 4

35. PowerShell passes objects, not text

Concept

This is the one idea that makes the second half of the room make sense. Other shells hand the next command a block of text. PowerShell hands it actual objects with named properties.

That is why you can filter and sort by a property name instead of cutting up text by column position.

# ---------- PowerShell: objects with names ----------
Get-ChildItem |
  Where-Object { $_.Length -gt 1000 } |
  Sort-Object Length -Descending |
  Select-Object Name, Length

# ---------- Linux: text in columns ----------
ls -l |
  awk '$5 > 1000' |
  sort -k5 -n -r |
  awk '{print $9, $5}'
plain EnglishPowerShellLinux
filterWhere-Object { $_.Length -gt 1000 }awk '$5 > 1000'
sortSort-Object Length -Descendingsort -k5 -n -r
choose columnsSelect-Object Name, Lengthawk '{print $9, $5}' or cut
how manyMeasure-Objectwc -l

The dollar underscore inside the braces means the current item being considered. Compare it with the Linux column: there the fields are numbered, because text has no property names and you have to count across to the fifth column to find the size.

That is the whole difference between the two shells in one slide. PowerShell is longer to type and harder to get wrong; Linux is shorter to type and depends on the columns staying where you expect them.

Microsoft Learn — PowerShell documentation — about_Objects and the *-Object cmdlets

36. The pipe, as a conveyor belt

Picture it

Each command hands its results to the next one.

Figure (svg): Four commands connected in a pipeline, from listing items through filtering and sorting to measuring

Read a pipeline left to right, out loud.

When a room asks how many files match something, the answer is almost always a pipeline ending in Measure-Object, or a dot Count on the end.

37. The comparison operators

Concept

These look strange for about a day and then become normal. They are words with a dash, not symbols.

operatormeansexample
-eqequals$_.Name -eq "flag.txt"
-nenot equal$_.Extension -ne ".log"
-gt and -ltgreater than, less than$_.Length -gt 1000
-ge and -leat least, at most$_.Length -ge 500
-likewildcard match$_.Name -like "flag*"
-matchregular expression match$_.Name -match "^fl"

The last two are the pair people mix up. Use -like with stars, and -match only when you actually want a regular expression.

Microsoft Learn — about_Comparison_Operators, and the approved verbs list — about_Comparison_Operators

38. Which operator?

Sorting

Match the job to the operator.

Sort into buckets

Wildcard, or exact, or numeric?

exact match
the name is exactly flag.txt; the extension is not .log
wildcard
the name starts with flag
numeric comparison
the file is bigger than one kilobyte
exact
Use -eq or -ne. These compare the whole value, and for text they ignore case by default in PowerShell.
wild
Use -like with a star. A star means any number of any characters.
num
Use -gt, -lt, -ge or -le. These work on numbers such as Length, which is a file's size in bytes.

One surprise worth knowing: PowerShell's text comparisons ignore capital letters by default, which is the opposite of Linux.

39. System and network information

Concept

The room asks for facts about the machine. Each one is a Get command with an obvious noun, which is the naming rule paying off.

# ---------- PowerShell ----------
Get-ComputerInfo          # everything about the machine
Get-LocalUser             # accounts on this machine
Get-Process               # what is running
Get-Service               # background services
Get-NetIPConfiguration    # IP address and gateway
Get-NetTCPConnection      # open network connections

# ---------- Linux ----------
uname -a                  # everything about the machine
cat /etc/passwd           # accounts on this machine
ps aux                    # what is running
systemctl list-units --type=service   # background services
ip a                      # IP address and gateway
ss -tulpn                 # open network connections
question the room asksPowerShellLinux
what operating system is thisGet-ComputerInfouname -a
which users existGet-LocalUsercat /etc/passwd
what is running right nowGet-Processps aux
what services are thereGet-Servicesystemctl list-units --type=service
what is this machine's IP addressGet-NetIPConfigurationip a
what is it connected toGet-NetTCPConnectionss -tulpn
can I reach that portTest-NetConnection -Portnc -zv <host> <port>

Reading /etc/passwd surprises people: on Linux the user list is simply a text file that anyone may read, which is why cat answers a question that needs a whole cmdlet on Windows.

Microsoft Learn — PowerShell documentation — the NetTCPIP and Microsoft.PowerShell.Management modules

40. File hashing, and why the room cares

Concept

A hash is a short fingerprint of a file's contents. Change one byte and the fingerprint changes completely, which is how you check that a file has not been tampered with.

# ---------- PowerShell ----------
Get-FileHash -Path .\tool.exe -Algorithm SHA256

# ---------- Linux ----------
sha256sum tool.bin
md5sum tool.bin
fieldmeaningwhere it is in Linux
Algorithmwhich fingerprinting method, usually SHA256you pick the tool: sha256sum or md5sum
Hashthe fingerprint itself, a long hexadecimal stringthe first column of the output
Pathwhich file it belongs tothe second column of the output

PowerShell prints a labelled table; Linux prints the hash and the filename on one line with no headings. Same fingerprint, and you can compare the two directly.

In security work you compare the hash you computed against the one the publisher listed. If they differ, the file is not the one they published.

Microsoft Learn — PowerShell documentation — Get-FileHash

41. Which command answers it?

Discrimination

The naming rule means you can often work this out without looking anything up.

Sort into buckets

Which noun does each question need?

a Net command
what is my IP address?
a pipeline ending in Measure-Object
how many text files are in this folder?
Get-FileHash
has this file been modified?
Get-LocalUser
which accounts exist on this machine?
net
Anything about addresses, connections or reachability starts with Get-Net or Test-Net.
pipe
How many always means counting, so list the things, filter them, then measure them.
hash
Comparing a file against a known fingerprint is exactly what hashing is for.
user
Local accounts have their own noun, and the plural form lists them all.

42. Scripting, named but not learned tonight

Concept

A script is a file of commands ending in dot p s 1. You will meet three things immediately, and it is worth recognising them now.

# ---------- PowerShell, saved as a .ps1 file ----------
$name = "Eden"
foreach ($f in Get-ChildItem) { Write-Output $f.Name }

# ---------- Linux, saved as a .sh file ----------
name="Eden"
for f in *; do echo "$f"; done
thingPowerShellLinuxthe gotcha
a variable$name = "Eden"name="Eden"Linux allows no spaces around the equals sign
do this once per itemforeach ($f in ...) { ... }for f in *; do ... doneLinux needs the semicolons and the word done
reading a variable back$f$fthe dollar sign is on the read, not the write, in Linux
the script filea .ps1 filea .sh fileWindows blocks scripts by default; Linux needs chmod +x first

That last row is the error everyone hits: the execution policy blocks scripts. In a lab you can allow them for the current window only, which is safer than changing the machine.

Microsoft Learn — PowerShell documentation — about_Execution_Policies

43. Which statement about the pipe is right?

Two truths and a lie

Three claims, one survivor.

Eliminate the wrong options

Which is true?

  • A. The pipe hands the left command's results to the right command instead of printing them.
  • B. The pipe runs both commands at the same time and combines their output.
  • C. The pipe only works with text output.
  • D. You can only put two commands in a pipeline.

Survives elimination: A

Why: A pipeline is a conveyor belt. Each command does one small job and passes the result along, which is why small commands are more useful than one big one.

44. How sure are you?

Commit first

Answer, then rate your confidence honestly.

Predict first

In PowerShell, is the comparison "FLAG.txt" -eq "flag.txt" true or false?

  • True
  • False
  • It errors
  • It depends on the folder

Correct: True.

Why: PowerShell string comparisons ignore capital letters by default, so those two are equal. In Linux the same two names are different files entirely. That difference between the two systems is worth carrying with you, because it flips exactly when you move between rooms.

45. How long should it take?

Estimation

Searching the whole C drive with a recursive listing.

Predict first

Roughly how long will that command take on a normal machine?

  • Instantly
  • A few seconds to a minute
  • About an hour
  • It will never finish

Correct: A few seconds to a minute.

Why: It is walking every folder on the drive, so it is not instant, but it is not slow either. Knowing this matters: if you expect it to be instant you will cancel it too early, and cancelling a search that was about to succeed is a genuinely common way to stay stuck.

46. Linux: The Same Ideas

Section

Section 5

47. You already know most of this

Picture it

Left column is what you want. The two right columns are just spellings.

Figure (svg): A translation table pairing six tasks with their PowerShell command and their Linux command

Same six ideas, twice.

Open Linux Fundamentals with this table beside you and the first half of the room will feel like revision.

48. Four differences that actually catch people

Concept

The commands translate easily. These four do not, and between them they explain most Linux confusion for a Windows user.

  1. The top is a slash, not a drive letter. Everything lives under one root, and your home folder is written as a tilde.
  2. Slashes lean the other way. Forward slashes in paths, always.
  3. Hidden files start with a dot, and you show them with ls -a rather than a Force option.
  4. Everything is case sensitive. Flag.txt and flag.txt are two different files, and this is the biggest single cause of 'the file is not there'.

Linux manual pages — the ls and bash manual pages

49. Why can she not find it?

Prediction

The room says there is a file called Flag.txt. She types cat flag.txt and gets 'No such file or directory'.

Predict first

What is wrong?

  • The file is hidden
  • Linux is case sensitive, so the capital F matters
  • She needs sudo
  • The file is in another folder

Correct: Linux is case sensitive.

Why: Flag.txt and flag.txt are different names entirely. This is the single most common Linux stumble for someone coming from Windows, where the two would be the same file. Tab completion prevents it: type fl and press Tab, and the shell fills in the exact name.

50. Finding and reading, in Linux

Concept

The same two jobs as before, with different spelling and one new piece of punctuation.

# ---------- Linux ----------
find / -name "flag*" 2>/dev/null    # search the whole system
grep -r "password" /home            # search inside files
ls -la                              # list everything, including hidden
cat notes.txt                       # read a short file
less big.log                        # page through a long one, q to quit

# ---------- the same five in PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Filter "flag*" -ErrorAction SilentlyContinue
Get-ChildItem -Path C:\Users -Recurse | Select-String -Pattern "password"
Get-ChildItem -Force
Get-Content notes.txt
Get-Content big.log | more
piecemeaningthe PowerShell equivalent
find / -namesearch from the root by filenameGet-ChildItem -Recurse -Filter
2>/dev/nullthrow away the error messages-ErrorAction SilentlyContinue
grep -rsearch inside files, recursivelySelect-String
ls -lalong listing, including hiddenGet-ChildItem -Force
lesspage through, q to quitGet-Content, more or less

Do not cat a huge file. Use less, and press q to get out, which is the thing nobody tells you and everyone needs.

GNU Coreutils manual — ls, cat, chmod and friends — and the find and grep manual pages

51. Permissions, the Real Wall

Section

Section 6

52. Why you actually cannot get into that folder

Concept

You said getting into specific files is the problem. Half the time in a Linux room, the reason is not the command. It is that you are not allowed.

Every file and folder carries ten characters describing who may do what. Once you can read those ten characters, permission-denied stops being mysterious.

Linux manual pages — the chmod and ls manual pages

53. Ten characters, decoded

Picture it

One type character, then three groups of three.

Figure (svg): The permission string dash r w x r dash x r dash dash split into type, owner, group and everyone else, with r w and x explained

On a directory, x means permission to enter it.

That last line is the one that unlocks things. A folder you cannot enter looks empty or refuses you, no matter what is inside it.

54. Worked example: read a permissions line out loud

Worked example

The listing shows a line beginning with the ten characters for a regular file, then owner read write execute, then group read and execute, then others read only.

Split off the first character

Why: A dash means an ordinary file. A d would mean a directory, and that changes what x means.

Read the next three as the owner

Why: Read, write, execute. The owner can do everything with it.

Read the next three as the group

Why: Read and execute, but no write. Members of the file's group can run it but not change it.

Read the last three as everyone else

Why: Read only.

whocharacterscan they readwriterun or enter
ownerrwxyesyesyes
groupr-xyesnoyes
everyone elser--yesnono

Verify: by asking who you are

Why: Run whoami and id. If you are not the owner and not in the group, you are in the last row, and the last row is what applies to you.

55. The numbers are just the letters added up

Picture it

Read four, write two, execute one.

Figure (svg): A table of permission numbers four two and one with their letter equivalents, and the common combinations 755 and 644

755 for a directory, 644 for a file.

So chmod 755 means owner everything, everyone else read and enter. You will type that combination more than any other.

56. Changing them, and the three commands to run when stuck

Concept

In a lab you are usually allowed to change permissions or to become the administrator. Outside a lab, think first.

# ---------- Linux ----------
chmod +x script.sh       # make it runnable
chmod 644 notes.txt      # owner read/write, everyone else read
chown eden notes.txt     # change who owns it
sudo cat /root/flag.txt  # run one command as the administrator

# ---------- Windows ----------
icacls notes.txt                       # show who may do what
icacls notes.txt /grant Eden:F         # give Eden full control
takeown /F notes.txt                   # take ownership of it
Start-Process powershell -Verb RunAs   # open a shell as administrator
when stuck, run thisit tells youthe Windows version
whoamiwhich user you currently arewhoami
idwhich groups you belong towhoami /groups
sudo -lwhich commands you may run as rootnet localgroup administrators

Those three are the first thing to type on any permission-denied message, and sudo -l is frequently the whole answer to a Linux room.

Windows has no sudo. Instead of raising one command you open a whole new shell as administrator, which is why the Windows habit is to check the title bar rather than to prefix a command.

Linux manual pages — chmod, chown and sudo

57. Trap: assuming the file is missing when it is protected

Trap

The trap

Trying to read a file in another user's home directory.

Annotate

  • The message says permission, not 'no such file'. Those are two completely different problems.
  • Permission denied means the file exists and you were told no, which is progress.
  • Windows words it differently, 'access is denied', but it is the identical situation: the file is real and you were refused.

Conclude the path is wrong and go looking elsewhere

Why: And spend twenty minutes searching for a file you had already found.

The fix

Read the error message, then check who you are.

# ---------- Linux ----------
ls -l /home/bob/notes.txt    # who owns it, who may read it
whoami                       # who am I
id                           # which groups am I in
sudo -l                      # what may I run as root

# ---------- Windows ----------
icacls C:\Users\Bob\notes.txt   # who may do what to it
whoami                          # who am I
whoami /groups                  # which groups am I in
net localgroup administrators   # who are the administrators
messagemeansnext stepthe other shell says
No such file or directorywrong name or wrong placecheck spelling and case, then searchCannot find path ... does not exist
Permission deniedit exists, you are not allowedcheck who you are, and sudo -lAccess to the path ... is denied
Is a directoryyou tried to read a folderuse ls, not catGet-Content fails on a folder too

Treat the error text as information

Why: Error messages in both shells are short but specific. The difference between those first two rows saves the most time of anything in this deck.

Run whoami first, in either shell

Why: It is the one command spelt the same on both systems, and on a permission message it is always the right next thing to type.

58. Check: what does this permission mean?

Check

Solve it on paper before you click.

Check your understanding

A directory shows the characters d r w x, then six dashes. Who can enter it?

  • A. Only the owner (correct)
  • B. Everyone
  • C. Nobody, because it is a directory
  • D. The owner and the group

Answer: A

Why: The d says directory. The owner has read, write and execute, and execute on a directory means permission to enter. Both the group and everyone else have no permissions at all, so neither can go in.

Why B tempts people
The six dashes mean the group and everyone else have nothing. Only the first three characters after the d grant anything.
Why C tempts people
Directories can certainly be entered; that is what the x is for. The owner can enter this one.
Why D tempts people
The middle three characters are the group's, and they are all dashes here, so the group has no access.

59. Commands to Try Tonight

Section

Section 7

60. Moving around and listing

Concept

Everything from here on is meant to be typed, not read. Every slide gives the PowerShell block and the Linux block for the same jobs, and the table underneath lines them up one against one. Nothing here changes anything on the machine.

# ---------- PowerShell ----------
Get-Location                    # where am I
Set-Location C:\Users\Public     # go there
Set-Location ..                  # up one level
Get-ChildItem                    # what is here
Get-ChildItem -Force             # including hidden items
Get-ChildItem -Recurse           # and everything below here
Get-ChildItem -Directory         # folders only
Get-ChildItem -File              # files only

# ---------- Linux ----------
pwd                             # where am I
cd /home/eden                   # go there
cd ..                           # up one level
ls                              # what is here
ls -la                          # including hidden items
ls -R                           # and everything below here
ls -d */                        # folders only
find . -maxdepth 1 -type f      # files only
the jobPowerShellLinux
which folder am I standing inGet-Locationpwd
go into a folderSet-Location <path>cd <path>
go up one levelSet-Location ..cd ..
list this folderGet-ChildItemls
list hidden items as wellGet-ChildItem -Forcels -la
list everything below here tooGet-ChildItem -Recursels -R
folders onlyGet-ChildItem -Directoryls -d */
files onlyGet-ChildItem -Filefind . -maxdepth 1 -type f

Run the highlighted line in a folder where the plain listing looked empty. In both shells that one change is the answer to most of the room's early questions.

Microsoft Learn — PowerShell documentation — Get-ChildItem and Set-Location

Linux manual pages — the ls manual page

61. Reading files, five ways

Concept

Get-Content and cat are the only two you strictly need. The rest exist so that a large file does not fill your screen.

# ---------- PowerShell ----------
Get-Content .\notes.txt                 # print the whole file
Get-Content .\big.log -TotalCount 20    # the first 20 lines
Get-Content .\big.log -Tail 20          # the last 20 lines
Get-Content .\big.log | more            # one screen at a time
(Get-Content .\notes.txt).Count         # how many lines is it
Get-Item .\notes.txt | Format-List *    # everything about the file

# ---------- Linux ----------
cat notes.txt                          # print the whole file
head -n 20 big.log                     # the first 20 lines
tail -n 20 big.log                     # the last 20 lines
less big.log                           # one screen at a time, q to quit
wc -l notes.txt                        # how many lines is it
stat notes.txt                         # everything about the file
the jobPowerShellLinux
print the whole fileGet-Content notes.txtcat notes.txt
the first twenty linesGet-Content big.log -TotalCount 20head -n 20 big.log
the last twenty linesGet-Content big.log -Tail 20tail -n 20 big.log
a screen at a timeGet-Content big.log | moreless big.log
count the lines(Get-Content notes.txt).Countwc -l notes.txt
size, dates and attributesGet-Item notes.txt | Format-List *stat notes.txt

The brackets in the PowerShell counting line matter: they tell it to finish reading the file first and then ask the result how many lines it has, the same idea as brackets in arithmetic. Linux uses a separate small tool instead, and that difference between the two shells is the whole of the next section.

Microsoft Learn — PowerShell documentation — Get-Content

GNU Coreutils manual — ls, cat, chmod and friends — cat, head, tail and wc

62. Searching, when you do not know where it is

Concept

Two different jobs that beginners mix up constantly. Finding a file by its name is one command in both shells. Finding text inside files is a different command in both shells.

# ---------- PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Filter "flag*" -ErrorAction SilentlyContinue
Get-ChildItem -Path C:\Users -Recurse -Force -Include "*.txt"
Select-String -Path .\notes.txt -Pattern "password"
Select-String -Path .\notes.txt -Pattern "admin" -Context 2
Get-ChildItem -Recurse -Filter "*.txt" | Select-String -Pattern "flag"

# ---------- Linux ----------
find / -name "flag*" 2>/dev/null
find /home -name "*.txt"
grep "password" notes.txt
grep -C 2 "admin" notes.txt
grep -r "flag" --include="*.txt" .
the jobPowerShellLinux
find a file by name, anywhere below hereGet-ChildItem -Recurse -Filter "flag*"find / -name "flag*"
narrow to one kind of file-Include "*.txt"-name "*.txt"
hide the access-denied complaints-ErrorAction SilentlyContinue2>/dev/null
find text inside one fileSelect-String -Pattern "password"grep "password" notes.txt
show two lines either side of a hit-Context 2grep -C 2
find text inside every file below herelisting piped into Select-Stringgrep -r

The two highlighted lines are the ones to memorise. Both answer 'the file is somewhere on this machine and I do not know where', and both are the same four pieces: where to start, go downwards, match this name, be quiet about what you cannot open.

Microsoft Learn — PowerShell documentation — Select-String and Get-ChildItem

Linux manual pages — the find and grep manual pages

63. Counting, sorting and picking columns

Concept

This group turns a listing into an answer. A room almost never wants the listing; it wants one number or one name out of it.

# ---------- PowerShell ----------
Get-ChildItem | Measure-Object                        # how many items
Get-ChildItem | Measure-Object -Property Length -Sum  # total size in bytes
Get-ChildItem | Sort-Object Length -Descending        # biggest first
Get-ChildItem | Select-Object Name, Length            # only these two columns
Get-ChildItem | Select-Object -First 5                # only the first five
Get-ChildItem | Where-Object { $_.Length -gt 1000 }   # only ones over 1000 bytes

# ---------- Linux ----------
ls | wc -l                       # how many items
du -sh .                         # total size of this folder
ls -lS                           # biggest first
ls -l | awk '{print $9, $5}'     # only name and size
ls | head -n 5                   # only the first five
find . -maxdepth 1 -size +1k     # only ones over 1000 bytes
the room questionPowerShellLinux
how many files are in...Get-ChildItem | Measure-Objectls | wc -l
what is the total size of...Measure-Object -Property Length -Sumdu -sh .
what is the largest file in...Sort-Object Length -Descendingls -lS
the output is too wide to readSelect-Object Name, Lengthls -l | awk '{print $9, $5}'
list the top five...Select-Object -First 5ls | head -n 5
which files are bigger than...Where-Object { test }find . -size +1k

Read the last PowerShell line as 'give me the items, then keep only the ones whose Length is greater than 1000'. The dollar-underscore is just the word 'it', meaning the item currently coming down the belt. Linux has no equivalent because find does its own filtering.

Microsoft Learn — about_Comparison_Operators, and the approved verbs list — Where-Object and the comparison operators

GNU Coreutils manual — ls, cat, chmod and friends — wc, du and head

64. The machine, the user and the network

Concept

Seven questions a room asks over and over, with the answer in each shell. None of them needs an option.

# ---------- PowerShell ----------
whoami                       # which account am I using
Get-LocalUser                # who has an account on this machine
Get-ComputerInfo             # OS name, version and build
Get-Process                  # what is running right now
Get-Service                  # background services
Get-NetIPConfiguration       # IP address and gateway
Get-FileHash .\tool.exe -Algorithm SHA256

# ---------- Linux ----------
whoami                       # which account am I using
cat /etc/passwd              # who has an account on this machine
uname -a                     # OS name, version and build
ps aux                       # what is running right now
systemctl list-units --type=service   # background services
ip a                         # IP address and gateway
sha256sum tool.bin           # the file's fingerprint
the questionPowerShellLinux
which account am Iwhoamiwhoami
who has an account hereGet-LocalUsercat /etc/passwd
what operating system is thisGet-ComputerInfouname -a
what is running right nowGet-Processps aux
what services are runningGet-Servicesystemctl list-units --type=service
what is my IP addressGet-NetIPConfigurationip a
what is this file's fingerprintGet-FileHash -Algorithm SHA256sha256sum

whoami is the one command spelt identically in both, which is why it is the safest thing to type when you are unsure which shell you are even looking at. Get-ComputerInfo prints a great deal, so pipe it into Select-Object with the property names you want.

Microsoft Learn — PowerShell documentation — the CimCmdlets and NetTCPIP modules

Linux manual pages — uname, ps and ip

65. Two habits that only bite you in Linux

Concept

The commands translate cleanly. Two things about Linux itself do not, and both of them look exactly like a missing file.

# ---------- PowerShell ----------
Get-Content .\Flag.txt      # works
Get-Content .\flag.txt      # also works, Windows ignores capitals
Get-ChildItem               # hidden files do not appear
Get-ChildItem -Force        # now they do

# ---------- Linux ----------
cat Flag.txt                # works
cat flag.txt                # No such file or directory
ls                          # does not show .flag.txt
ls -la                      # does show it, because of the leading dot
the differenceWindowsLinux
capital letters in a nameignored, Flag.txt is flag.txtdifferent files entirely
what makes a file hiddenthe h attribute, in the Mode columna dot at the front of the name
how you reveal hidden filesGet-ChildItem -Forcels -la
the folder separatora backslash, C:\Usersa forward slash, /home

Both differences produce the same complaint, which is why 'No such file or directory' is the least informative message you will meet. Before believing it, retype the name with Tab and list the folder with hidden items showing.

Linux manual pages — the ls and bash manual pages

66. Eleven lines to run right now, in both shells

Pattern

A safe drill that touches every idea in this deck. It makes one file, reads it, counts, hashes it and deletes it again, so nothing is left behind on the machine. Run whichever block matches the box you are on, and the numbers line up one to one.

# ---------- PowerShell ----------
Get-Location                                  # 1
Get-ChildItem                                 # 2
Get-ChildItem -Force                          # 3
Get-Help Get-ChildItem -Examples              # 4
Get-Alias ls                                  # 5
New-Item -ItemType File -Name test.txt        # 6
Set-Content .\test.txt "hello from the room"  # 7
Get-Content .\test.txt                        # 8
Get-ChildItem | Measure-Object                # 9
Get-FileHash .\test.txt -Algorithm SHA256     # 10
Remove-Item .\test.txt                        # 11

# ---------- Linux ----------
pwd                                        # 1
ls                                         # 2
ls -la                                     # 3
man ls                                     # 4  (q to quit)
type ls                                    # 5
touch test.txt                             # 6
echo "hello from the room" > test.txt      # 7
cat test.txt                               # 8
ls | wc -l                                 # 9
sha256sum test.txt                         # 10
rm test.txt                                # 11
linewhat you should seewhat it proves you can do
1 and 2a path, then a list of namesyou can tell where you are and what is around you
3the same list, possibly with extra rowsyou can see hidden files, the first beginner wall
4 and 5worked examples, then the real name behind lsyou can answer your own question without leaving the shell
6 and 7no output, or a single new rowyou can create a file and put text in it
8hello from the roomyou can read a file back
9Count : some number, or just a numberyou can turn a listing into a number
10a long string of letters and digitsyou can fingerprint a file, which the hashing tasks want
11no outputyou cleaned up after yourself

Line 11 is worth noticing in both shells: a successful delete prints nothing at all. Silence after a command is usually success, and beginners often retype a line because they were waiting for a message that was never coming.

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — run these on the room's attached machine

67. Six more commands the 101 rooms keep asking for

Concept

One line each. You do not need to learn them tonight; you need to recognise them when a room mentions one.

commandwhat it is for
file mysterywhat kind of file is this really
strings binary | grep flagpull readable text out of a non-text file
base64 -d encoded.txtdecode base64, which rooms use constantly
tar -xzf archive.tar.gzunpack an archive; unzip for zip files
historywhat commands were run on this machine before
python3 -m http.serverserve the current folder over HTTP, for moving files

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — these appear throughout the Cyber Security 101 path

68. Pattern: the stuck-in-a-room checklist

Pattern

Six questions, in this order. Between them they cover almost every reason a beginner cannot complete a task.

  1. Where am I? Get-Location, or pwd.
  2. What is here, including hidden? Get-ChildItem -Force, or ls -la.
  3. What is the task's verb and noun? Say it in plain English first, then guess the command.
  4. Is my path absolute or relative? And does it have a space needing quotes?
  5. Do I have permission? Read the ten characters; run whoami, id, sudo -l.
  6. What does the help say? Get-Help with -Examples, or man, before searching the internet.

Work down the list rather than trying things. Trying things is what makes an hour disappear.

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — and see the room's own hints as a last resort, not a first one

69. The checklist

Picture it

Screenshot this, or write it on a sticky note.

Figure (svg): A six step checklist from where am I, through what is here including hidden, verb and noun, path type, permission, and the help command

Down the list, in order, before trying anything.

70. Order the checklist

Ranking

Same six questions, shuffled. The order is what makes it fast.

Put in order

  1. Where am I?
  2. What is here, including hidden items?
  3. What is the verb and the noun of the task?
  4. Is my path absolute or relative?
  5. Do I have permission?
  6. What do the built-in help and examples say?

Why: The first two are free and answer most cases. Permission comes after the path questions because a wrong path also produces a confusing error, and you want to rule out the cheap explanations first. Help is last because it is the slowest, not because it is least useful.

71. Which is the right first move?

Elimination

A room says there is a flag in your home directory. ls shows nothing.

Eliminate the wrong options

What do you do first?

  • A. Run ls -la to include hidden files
  • B. Search the entire filesystem with find
  • C. Use sudo
  • D. Ask for the room's hint

Survives elimination: A

Why: Hidden files start with a dot and plain ls does not show them. This is step two of the checklist, it costs three characters, and in a Cyber Security 101 room it is right a large fraction of the time.

72. Explain the pipe to someone who has never used a shell

Explain it

Two sentences, out loud.

Discussion prompt

What does the vertical bar actually do?

Hint: Think of it as a conveyor belt between two machines.

Answer:

It takes whatever the command on the left produced and hands it straight to the command on the right, instead of printing it to the screen.

So you can chain small commands into one job: list the files, keep the big ones, sort them, count them. Each command does one thing and the pipe joins them up.

Microsoft Learn — PowerShell documentation — about_Pipelines

73. Where this goes next

Real world

You are learning this for a reason, so it is worth seeing where it lands.

Discussion prompt

Almost every security task starts with the same two questions you practised tonight. Which two, and why do they come first?

Hint: What did you type first in every example tonight?

Answer:

Where am I, and what is here. On your own machine those are orientation; on someone else's machine they are the first steps of understanding what you are looking at.

Everything later in the path — reading logs, finding credentials left in files, spotting a process that should not be running — is a longer version of tonight's find and read.

Which is why the checklist is worth more than the individual commands. The commands change between rooms; the six questions do not.

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — the rest of the Cyber Security 101 path

74. Exit ticket

Exit ticket

One honest answer, and it decides what we open with next time.

Predict first

Which of these still feels least solid?

  • Paths, and absolute against relative
  • Guessing a command from its verb and noun
  • Finding a file anywhere, including hidden ones
  • The pipe, and filtering or counting
  • Linux permissions and why you get denied

Correct: Whichever you picked is where we start next session.

Why: If it is the last one, that is the highest-value thing to fix, because permissions come up in nearly every room from here on and the same ten characters explain all of it.

75. Your own command list

Connect it up

As you finish the room this week.

Draw it

Keep a running list of every command you had to look up, with one line on what it does in your own words. Do not copy the room's wording.

Send me the list before next session. It is a better plan for the hour than anything I would choose in advance.

76. What you can do now

Recap

One model, one naming rule, three lifelines, and a checklist. That is the whole of tonight.

you want toPowerShellLinux
find a file anywhereGet-ChildItem -Recurse -Force -Filterfind / -name
hide error noise-ErrorAction SilentlyContinue2>/dev/null
show hidden items-Forcels -a
search inside filesSelect-String -Patterngrep -r
read a long file safelyGet-Content -Tail 10less, then q
find out why you were denied-whoami, id, sudo -l

TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — finish the PowerShell room, then start Linux Fundamentals Part 1

Sources

  1. TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms
  2. Microsoft Learn — PowerShell documentation
  3. Microsoft Learn — about_Comparison_Operators, and the approved verbs list — Microsoft Learn, PowerShell language reference
  4. Linux manual pages
  5. GNU Coreutils manual — ls, cat, chmod and friends

Want this taught 1-on-1? Alexander tutors Cyber Security 101 — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108