A beginner session built around one wall: not being able to get into specific files. The filesystem as a building, PowerShell's verb-noun naming rule and three lifeline commands, finding hidden files anywhere on a drive and reading them, pipelines and the comparison operators, the same ideas in Linux with a translation table, why case sensitivity and permissions cause most 'file not there' errors, and a six-question checklist for being stuck in a room.
Subject: Cyber Security 101 · 76 slides · code lesson
Open the interactive version of this deck · Homework for this lesson
Title
Cyber Security 101 · Session 1
The room you are on now, and the wall you described
Objectives
You said you can follow the basic commands but the specific tasks lose you, and that getting into particular files is the problem. That is a very specific diagnosis and it is a fixable one.
Everything is in the actual rooms. I will keep my talking short and your typing long.
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — the Cyber Security 101 path you are on
Section
Section 1
Warm-up
Two minutes, before anything new.
Discussion prompt
Think of the last task in the PowerShell room that stopped you. What did the task ask for, and what did you type?
Hint: Say what the task wanted in your own words, not in the room's words.
Answer:
Almost every beginner stuck point is one of four things: the file is hidden, you are in a different folder than you think, the path is relative when you meant absolute, or you do not have permission.
None of those is about knowing more commands. All four are checkable in about ten seconds each, and by the end of tonight you will have a checklist for exactly them.
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — Windows PowerShell room
Concept
A drive is a building. Folders are rooms, and rooms contain rooms. Files are things sitting in a room. Where am I means which room you are standing in.
A path is just the list of doors you walk through to get somewhere. An absolute path starts at the front door of the building. A relative path starts from wherever you are standing right now.
Microsoft Learn — PowerShell documentation — about_Path_Syntax
Picture it
Four levels, and one file at the bottom.
Figure (svg): Nested boxes showing the C drive containing Users containing Eden containing notes dot txt, labelled as building, floor, room and object
Two small rules that save a lot of pain: put quotes around any path with a space in it, and press Tab to let the shell finish a name for you.
Matching
You are standing in C:\Users\Eden.
Match the pairs
Why: A single dot means here, and two dots mean the room outside this one. Anything starting with a drive letter is absolute and does not care where you are standing.
Concept
PowerShell commands are named to a rule. The verb says what you are doing, the noun says what you are doing it to, and options come after with a dash in front.
# ---------- PowerShell ----------
Get-ChildItem -Path C:\Users -Force
# ---------- Linux ----------
ls -la /home| piece | meaning | the same piece in Linux |
|---|---|---|
| Get | the verb: look at something | baked into the name; ls just means list |
| ChildItem | the noun: the things inside a folder | also baked in; ls always lists a folder |
| -Path | an option name, always with a dash | there is no option name, the path just follows |
| C:\Users | the value for that option | /home |
| -Force | an option with no value; a switch | -a, bundled into the -la above |
Both lines do exactly the same job. PowerShell spells everything out, which makes it long but guessable. Linux abbreviates everything, which makes it short but something you have to learn. Neither is harder once you know that -Force and -a are the same idea.
If you can say the verb and the noun of what a task is asking for, you can usually guess the PowerShell command before looking it up. In Linux you guess the letter instead, which is what the manual page is for.
Microsoft Learn — about_Comparison_Operators, and the approved verbs list — the approved verbs list
Picture it
Six verbs cover most of what the room asks for.
Figure (svg): The command Get-ChildItem split into its verb and noun, with a table of six common verbs and their plain meanings
Prediction
Do not look it up. Use the rule.
Predict first
The task says: make a new folder. What is the command probably called?
Correct: New-Item.
Why: The verb for making something is New. The noun PowerShell uses for both files and folders is Item, with a type option to say which. Make and Create are not approved verbs, which is why guessing from the verb list works so reliably.
Concept
These three exist so you are never fully stuck, and they are worth using before searching the internet.
# ---------- PowerShell ----------
Get-Command -Name *file* # what commands exist about this?
Get-Help Get-ChildItem -Examples # show me it being used
Get-Alias ls # what is ls really called?
# ---------- Linux ----------
apropos file # what commands exist about this?
man ls # show me the manual, q to quit
type ls # what is ls really called?| when to reach for it | PowerShell | Linux |
|---|---|---|
| you do not know the command name | Get-Command -Name file | apropos file |
| you know the name but not the options | Get-Help <name> -Examples | man <name> |
| the room asks for the real name | Get-Alias ls | type ls |
Both shells have all three lifelines; only the spelling changes. The Linux manual opens in a pager, so remember that q gets you out of it, the same q that gets you out of less.
That last one matters for the room specifically: ls and dir and cat are nicknames, and sometimes the answer box wants the real name.
Microsoft Learn — PowerShell documentation — Get-Command and Get-Help
Picture it
In this order.
Figure (svg): Three boxes listing Get-Command for finding a command, Get-Help with examples, and Get-Alias for real cmdlet names
Concept
None of these is a command and none of them is ever the answer to a room question. They are the difference between typing a line in ten seconds and typing it in a minute, and between a typo you spot and a typo you spend five minutes on.
| key | what it does | why it matters tonight |
|---|---|---|
| Tab | finishes the name you started typing | no typos, correct capitals, and it adds the quotes for you |
| Up arrow | brings back the command you just ran | change one word instead of retyping the whole line |
| Ctrl and C together | stops a command that is still running | a search of the whole drive can run for minutes |
| cls, or clear in Linux | wipes the screen | when the thing you need has scrolled out of sight |
Tab is the important one. Type the first three or four letters of a name and press it. If nothing happens, the name you started typing does not exist in this folder, and you have learned that in half a second rather than by reading an error.
Microsoft Learn — PowerShell documentation — PSReadLine key bindings
Section
Section 2
Concept
Two commands, and they are the first two things to type whenever anything goes wrong.
# ---------- PowerShell ----------
Get-Location # where am I
Get-ChildItem # what is here
Get-ChildItem -Force # now including hidden items
Set-Location C:\Users # go somewhere else
# ---------- Linux ----------
pwd # where am I
ls # what is here
ls -la # now including hidden items
cd /home # go somewhere else| what it answers | PowerShell | Linux |
|---|---|---|
| which room am I standing in | Get-Location | pwd |
| what is in this room | Get-ChildItem | ls |
| what is in this room, hidden things included | Get-ChildItem -Force | ls -la |
| go to another room | Set-Location <path> | cd <path> |
The highlighted line is the same idea in both shells and it is the one that solves most 'the file is not there' problems. In PowerShell it is a word, in Linux it is a letter.
Microsoft Learn — PowerShell documentation — Get-ChildItem
Picture it
Three items in one folder. Only two of them showed up the first time.
Figure (svg): A listing with a directory, an ordinary file, and a hidden file whose Mode column contains an h, highlighted
This is the first of the four beginner walls. If the room says a file exists and you cannot see it, add -Force before doing anything else.
Prediction
The room says there is a file called flag.txt in your home folder. Get-ChildItem shows nothing.
Predict first
What do you try first?
Correct: Add -Force.
Why: Hidden is by far the most common explanation, and checking costs five characters. Searching the whole drive is the next step if that fails, and it is much slower. This ordering is the whole point of having a checklist.
Worked example
This is the command you will use in nearly every room from here on.
Start from the top of the drive and go all the way down
Why: Recurse means look inside every folder, and every folder inside those.
Filter by name so the output is readable
Why: Filter takes a wildcard. A star means anything.
Silence the access-denied errors
Why: Without this the real answer scrolls off the top of the screen in a wall of red. It does not hide your results, only the complaints.
# ---------- PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Filter "*.txt" -ErrorAction SilentlyContinue
# ---------- Linux ----------
find / -name "*.txt" 2>/dev/null| the piece | without it | with it | the Linux spelling |
|---|---|---|---|
| -Recurse | only the top folder is searched | every folder underneath is searched | find does this by default |
| -Filter | thousands of files listed | only the ones you asked for | -name "*.txt" |
| -ErrorAction SilentlyContinue | screens of red access-denied text | just the results | 2>/dev/null |
| -Path C:\ | nothing to search | start from the top of the drive | the / straight after find |
The two lines look nothing alike and are the same command. Both say: start here, go all the way down, match this name, and do not tell me about folders I am not allowed to open.
Verify: by running it without the last option once
Why: Do it once, on purpose, so you see what it is hiding. Then always use it. Knowing what a flag suppresses is different from copying it because someone said to.
Picture it
Five pieces. None of them is mysterious once it is separated out.
Figure (svg): The recursive search command broken into five labelled parts: the command, the starting path, recurse, filter, and error action
Concept
Once you have the file, three commands read it, and two of them stop you drowning in a long one.
# ---------- PowerShell ----------
Get-Content .\flag.txt # the whole file
Get-Content .\big.log -TotalCount 10 # first ten lines
Get-Content .\big.log -Tail 10 # last ten lines
# ---------- Linux ----------
cat flag.txt # the whole file
head -n 10 big.log # first ten lines
tail -n 10 big.log # last ten lines| shows | PowerShell | Linux | use it when |
|---|---|---|---|
| the whole file | Get-Content flag.txt | cat flag.txt | the file is short |
| the first ten lines | Get-Content big.log -TotalCount 10 | head -n 10 big.log | you want the header |
| the last ten lines | Get-Content big.log -Tail 10 | tail -n 10 big.log | you want the newest log entries |
The Linux names are the giveaway: head is the top of the file and tail is the bottom. PowerShell borrowed Tail and invented TotalCount for the other one, which is the less memorable half of the pair.
Microsoft Learn — PowerShell documentation — Get-Content
Concept
Finding the file is half the job. Finding the line inside it is the other half, and it is the same command in both worlds under a different name.
# ---------- PowerShell ----------
Select-String -Path .\notes.txt -Pattern "password"
Get-ChildItem -Recurse -Filter "*.txt" | Select-String -Pattern "flag"
# ---------- Linux ----------
grep "password" notes.txt
grep -r "flag" --include="*.txt" .| what it does | PowerShell | Linux |
|---|---|---|
| look inside one file for text | Select-String -Path notes.txt | grep "password" notes.txt |
| the text you are looking for | -Pattern "password" | the first argument after grep |
| hand results to the next command | the vertical bar | the vertical bar, identically |
| search inside every text file below here | listing piped into Select-String | grep -r |
That vertical bar is the pipe, and it is the single most useful character in either shell. It is the one piece of punctuation that is spelt the same in both.
That vertical bar is the pipe, and it is the single most useful character in either shell.
Microsoft Learn — PowerShell documentation — Select-String
Trap
The room says the flag is somewhere on the machine.
Annotate
Get no output, and assume the task is broken
Why: The command was correct and the search area was one folder out of thousands.
Search the whole drive, include hidden items, and silence the noise.
# ---------- PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Force -Filter "flag*" -ErrorAction SilentlyContinue
# ---------- Linux ----------
find / -name "flag*" 2>/dev/null| search | folders looked in | hidden included | the Linux spelling |
|---|---|---|---|
| no options | 1 | no | ls |
| -Recurse | all of them | no | ls -R |
| -Recurse -Force | all of them | yes | find, which shows hidden files anyway |
That last row is worth remembering: find has no -Force because it never hid anything from you in the first place. The Linux search is the easier of the two to get right.
Make this your default
Why: Type the long version every time until it is muscle memory. It costs three seconds and it removes an entire category of being stuck.
Pattern
Whenever anything goes wrong, before thinking, type these three. They cost five seconds and they answer most of it.
Notice that none of the three requires you to know anything about the task. They are pure orientation, and orientation is what is missing when you feel stuck.
Microsoft Learn — PowerShell documentation — Get-Location, Get-ChildItem, Get-Help
Fill the middle
You want every text file on the C drive, hidden ones included, without the red error noise.
Fill in the blanks
Get-ChildItem -Path C: -Recurse -Force -Filter "*.txt" -ErrorAction SilentlyContinue
Why: Those three options are the difference between a command that finds nothing and one that finds the flag. Recurse controls where it looks, Force controls what counts as visible, and the error action controls whether you can read the output.
Trap
Trying to enter a folder whose name has a space.
Annotate
Conclude the folder is missing
Why: It is right there. The command never saw the whole name.
Quote it, or let Tab do it for you.
# ---------- PowerShell ----------
Set-Location "C:\Program Files"
# ---------- Linux ----------
cd "/home/eden/my notes"
cd /home/eden/my\ notes| what you type | what the shell sees | result |
|---|---|---|
| C:\Program Files | two arguments | error |
| "C:\Program Files" | one argument | works |
| C:\Prog then Tab | the shell quotes it for you | works |
| /home/eden/my notes | two arguments | error |
| "/home/eden/my notes" | one argument | works |
| /home/eden/my\ notes | the backslash escapes the space | works |
Linux gives you a second repair Windows does not: a backslash immediately before a space tells the shell to treat that space as part of the name. Quotes work in both, so quotes are the habit worth having.
Use Tab completion by default
Why: Type the first few letters and press Tab. It fills in the exact name, adds quotes when needed, and gets the capitalisation right, which matters enormously in Linux.
Check
Solve it on paper before you click.
Check your understanding
Which command searches the whole C drive, including hidden items, for anything starting with flag?
Answer: A
Why: Recurse goes down through every folder, Force includes hidden items, Filter narrows the names, and the error action hides the access-denied complaints so the result is readable.
Section
Section 3
Concept
This is the part you said is hardest: you know the commands, but not which one the room is asking for. The fix is to stop reading the question for a command and start reading it for an answer shape.
Ask one thing first: when I have the answer, what will it look like? A name? A number? A line of text? The command follows from that, not from the wording.
| what the answer will look like | how the room usually words it | what produces it |
|---|---|---|
| a file or folder name | what is the name of... | Get-ChildItem, then read the Name column |
| a number | how many... | the listing command, piped into Measure-Object |
| the contents of a small file | what is the flag / what does it say | Get-Content, or cat in Linux |
| one line out of a big file | which line mentions... / what is the entry for... | Select-String, or grep in Linux |
| a property of a file | the size / the hash / the date | Get-FileHash, or a column of Get-ChildItem |
| a fact about the machine | which user / what version / what address | whoami, Get-LocalUser, Get-NetIPConfiguration |
Six rows covers almost every question in the 101 rooms. When a question does not fit any of them, it is usually two of them stacked: find the file first, then read it.
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — Cyber Security 101, the Windows PowerShell room
Translation
Five tasks worded the way a room words them. Decide the answer shape first.
Match the pairs
Why: Only two of the five needed a command you had not already met. The work was reading the question: a count needs Measure-Object, a name needs a listing, contents need Get-Content, an unknown location needs -Recurse, and a line inside a file needs Select-String. Notice that l2 and l4 both look like 'find a file' but one is hidden here and the other is somewhere unknown, and that is what decides between -Force and -Recurse.
Worked example
The task: 'A hidden file in the Public folder contains the flag. What is it?' That is two of the six rows stacked, a name and then contents.
# ---------- PowerShell ----------
Set-Location C:\Users\Public
Get-ChildItem
Get-ChildItem -Force
Get-Content .\flag.txt
# ---------- Linux ----------
cd /home/eden
ls
ls -la
cat .flag.txt| you type (PowerShell / Linux) | what appears | what it tells you |
|---|---|---|
| Set-Location C:\Users\Public / cd /home/eden | the prompt changes to show the new folder | you are in the right folder now |
| Get-ChildItem / ls | Desktop, Documents, Downloads | no flag file, and this is where most people stop |
| Get-ChildItem -Force / ls -la | one more row: flag.txt with h in Mode, or .flag.txt with a leading dot | it was there the whole time, just hidden |
| Get-Content .\flag.txt / cat .flag.txt | THM followed by the flag string | that string is what goes in the answer box |
The third row is the same discovery in two costumes. Windows hides a file with an attribute you can only see in the Mode column; Linux hides it with a dot at the front of the name. Both are revealed by one extra character on the listing command.
Decide the answer shape before typing
Why: The question wants the contents of a file, so the last command was always going to be Get-Content. Everything before it exists only to learn the file name.
Go to the folder rather than typing long paths
Why: Set-Location once, and then every path afterwards is short enough to type without mistakes.
Add -Force the moment a listing looks empty
Why: The word hidden in the question is a direct instruction to use it.
Verify: by checking the answer looks like an answer
Why: A flag has a recognisable shape. If Get-Content prints a wall of text, you opened the wrong file, and the fix is to go back one step rather than to reread the question.
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — the Windows PowerShell room tasks
Picture it
Three commands and their output, exactly as they appear.
Figure (svg): A PowerShell session listing a folder, listing it again with -Force so a hidden flag file appears, and then reading that file
Two things worth noticing. The prompt tells you which folder you are in, so you never have to wonder. And the run that found the file looks identical to the run that did not, apart from one word.
Concept
An error is not a failure, it is the shell answering a different question than the one you asked. Three of these five say the file does not exist, and two say it does exist but you cannot have it. Telling those apart is the most useful reading skill in this room.
| the message | what it really means | your next move |
|---|---|---|
| Cannot find path ... because it does not exist | wrong path, wrong spelling, or the file is hidden | Get-ChildItem -Force here, then retype the name using Tab |
| is not recognized as the name of a cmdlet | the command itself is misspelt or does not exist | Get-Command with a wildcard, for example Get-Command hash |
| Access to the path is denied | the file exists and you were told no | whoami, then note it for the room and move on |
| No such file or directory (Linux) | wrong name, wrong folder, or wrong capitals | ls -la, then retype with Tab |
| Permission denied (Linux) | it exists and you were told no | ls -l on the file, then id, then sudo -l |
The two access messages are progress, not defeat. They confirm the file is real and that you found it, which is often exactly what the room wanted you to discover.
Microsoft Learn — PowerShell documentation — PowerShell error records
Linux manual pages — the shell manual pages
Error analysis
PowerShell prints a lot of an error. Almost all of it is about where you typed it, which you already know.
Annotate
The habit worth building tonight: when red text appears, read only the sentence, and specifically read the path in the quotes. Nine times out of ten you are one folder away or one capital letter away.
Microsoft Learn — PowerShell documentation — PowerShell error records
Section
Section 4
Concept
This is the one idea that makes the second half of the room make sense. Other shells hand the next command a block of text. PowerShell hands it actual objects with named properties.
That is why you can filter and sort by a property name instead of cutting up text by column position.
# ---------- PowerShell: objects with names ----------
Get-ChildItem |
Where-Object { $_.Length -gt 1000 } |
Sort-Object Length -Descending |
Select-Object Name, Length
# ---------- Linux: text in columns ----------
ls -l |
awk '$5 > 1000' |
sort -k5 -n -r |
awk '{print $9, $5}'| plain English | PowerShell | Linux |
|---|---|---|
| filter | Where-Object { $_.Length -gt 1000 } | awk '$5 > 1000' |
| sort | Sort-Object Length -Descending | sort -k5 -n -r |
| choose columns | Select-Object Name, Length | awk '{print $9, $5}' or cut |
| how many | Measure-Object | wc -l |
The dollar underscore inside the braces means the current item being considered. Compare it with the Linux column: there the fields are numbered, because text has no property names and you have to count across to the fifth column to find the size.
That is the whole difference between the two shells in one slide. PowerShell is longer to type and harder to get wrong; Linux is shorter to type and depends on the columns staying where you expect them.
Microsoft Learn — PowerShell documentation — about_Objects and the *-Object cmdlets
Picture it
Each command hands its results to the next one.
Figure (svg): Four commands connected in a pipeline, from listing items through filtering and sorting to measuring
When a room asks how many files match something, the answer is almost always a pipeline ending in Measure-Object, or a dot Count on the end.
Concept
These look strange for about a day and then become normal. They are words with a dash, not symbols.
| operator | means | example |
|---|---|---|
| -eq | equals | $_.Name -eq "flag.txt" |
| -ne | not equal | $_.Extension -ne ".log" |
| -gt and -lt | greater than, less than | $_.Length -gt 1000 |
| -ge and -le | at least, at most | $_.Length -ge 500 |
| -like | wildcard match | $_.Name -like "flag*" |
| -match | regular expression match | $_.Name -match "^fl" |
The last two are the pair people mix up. Use -like with stars, and -match only when you actually want a regular expression.
Microsoft Learn — about_Comparison_Operators, and the approved verbs list — about_Comparison_Operators
Sorting
Match the job to the operator.
Sort into buckets
Wildcard, or exact, or numeric?
One surprise worth knowing: PowerShell's text comparisons ignore capital letters by default, which is the opposite of Linux.
Concept
The room asks for facts about the machine. Each one is a Get command with an obvious noun, which is the naming rule paying off.
# ---------- PowerShell ----------
Get-ComputerInfo # everything about the machine
Get-LocalUser # accounts on this machine
Get-Process # what is running
Get-Service # background services
Get-NetIPConfiguration # IP address and gateway
Get-NetTCPConnection # open network connections
# ---------- Linux ----------
uname -a # everything about the machine
cat /etc/passwd # accounts on this machine
ps aux # what is running
systemctl list-units --type=service # background services
ip a # IP address and gateway
ss -tulpn # open network connections| question the room asks | PowerShell | Linux |
|---|---|---|
| what operating system is this | Get-ComputerInfo | uname -a |
| which users exist | Get-LocalUser | cat /etc/passwd |
| what is running right now | Get-Process | ps aux |
| what services are there | Get-Service | systemctl list-units --type=service |
| what is this machine's IP address | Get-NetIPConfiguration | ip a |
| what is it connected to | Get-NetTCPConnection | ss -tulpn |
| can I reach that port | Test-NetConnection -Port | nc -zv <host> <port> |
Reading /etc/passwd surprises people: on Linux the user list is simply a text file that anyone may read, which is why cat answers a question that needs a whole cmdlet on Windows.
Microsoft Learn — PowerShell documentation — the NetTCPIP and Microsoft.PowerShell.Management modules
Concept
A hash is a short fingerprint of a file's contents. Change one byte and the fingerprint changes completely, which is how you check that a file has not been tampered with.
# ---------- PowerShell ----------
Get-FileHash -Path .\tool.exe -Algorithm SHA256
# ---------- Linux ----------
sha256sum tool.bin
md5sum tool.bin| field | meaning | where it is in Linux |
|---|---|---|
| Algorithm | which fingerprinting method, usually SHA256 | you pick the tool: sha256sum or md5sum |
| Hash | the fingerprint itself, a long hexadecimal string | the first column of the output |
| Path | which file it belongs to | the second column of the output |
PowerShell prints a labelled table; Linux prints the hash and the filename on one line with no headings. Same fingerprint, and you can compare the two directly.
In security work you compare the hash you computed against the one the publisher listed. If they differ, the file is not the one they published.
Microsoft Learn — PowerShell documentation — Get-FileHash
Discrimination
The naming rule means you can often work this out without looking anything up.
Sort into buckets
Which noun does each question need?
Concept
A script is a file of commands ending in dot p s 1. You will meet three things immediately, and it is worth recognising them now.
# ---------- PowerShell, saved as a .ps1 file ----------
$name = "Eden"
foreach ($f in Get-ChildItem) { Write-Output $f.Name }
# ---------- Linux, saved as a .sh file ----------
name="Eden"
for f in *; do echo "$f"; done| thing | PowerShell | Linux | the gotcha |
|---|---|---|---|
| a variable | $name = "Eden" | name="Eden" | Linux allows no spaces around the equals sign |
| do this once per item | foreach ($f in ...) { ... } | for f in *; do ... done | Linux needs the semicolons and the word done |
| reading a variable back | $f | $f | the dollar sign is on the read, not the write, in Linux |
| the script file | a .ps1 file | a .sh file | Windows blocks scripts by default; Linux needs chmod +x first |
That last row is the error everyone hits: the execution policy blocks scripts. In a lab you can allow them for the current window only, which is safer than changing the machine.
Microsoft Learn — PowerShell documentation — about_Execution_Policies
Two truths and a lie
Three claims, one survivor.
Eliminate the wrong options
Which is true?
Survives elimination: A
Why: A pipeline is a conveyor belt. Each command does one small job and passes the result along, which is why small commands are more useful than one big one.
Commit first
Answer, then rate your confidence honestly.
Predict first
In PowerShell, is the comparison "FLAG.txt" -eq "flag.txt" true or false?
Correct: True.
Why: PowerShell string comparisons ignore capital letters by default, so those two are equal. In Linux the same two names are different files entirely. That difference between the two systems is worth carrying with you, because it flips exactly when you move between rooms.
Estimation
Searching the whole C drive with a recursive listing.
Predict first
Roughly how long will that command take on a normal machine?
Correct: A few seconds to a minute.
Why: It is walking every folder on the drive, so it is not instant, but it is not slow either. Knowing this matters: if you expect it to be instant you will cancel it too early, and cancelling a search that was about to succeed is a genuinely common way to stay stuck.
Section
Section 5
Picture it
Left column is what you want. The two right columns are just spellings.
Figure (svg): A translation table pairing six tasks with their PowerShell command and their Linux command
Open Linux Fundamentals with this table beside you and the first half of the room will feel like revision.
Concept
The commands translate easily. These four do not, and between them they explain most Linux confusion for a Windows user.
Linux manual pages — the ls and bash manual pages
Prediction
The room says there is a file called Flag.txt. She types cat flag.txt and gets 'No such file or directory'.
Predict first
What is wrong?
Correct: Linux is case sensitive.
Why: Flag.txt and flag.txt are different names entirely. This is the single most common Linux stumble for someone coming from Windows, where the two would be the same file. Tab completion prevents it: type fl and press Tab, and the shell fills in the exact name.
Concept
The same two jobs as before, with different spelling and one new piece of punctuation.
# ---------- Linux ----------
find / -name "flag*" 2>/dev/null # search the whole system
grep -r "password" /home # search inside files
ls -la # list everything, including hidden
cat notes.txt # read a short file
less big.log # page through a long one, q to quit
# ---------- the same five in PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Filter "flag*" -ErrorAction SilentlyContinue
Get-ChildItem -Path C:\Users -Recurse | Select-String -Pattern "password"
Get-ChildItem -Force
Get-Content notes.txt
Get-Content big.log | more| piece | meaning | the PowerShell equivalent |
|---|---|---|
| find / -name | search from the root by filename | Get-ChildItem -Recurse -Filter |
| 2>/dev/null | throw away the error messages | -ErrorAction SilentlyContinue |
| grep -r | search inside files, recursively | Select-String |
| ls -la | long listing, including hidden | Get-ChildItem -Force |
| less | page through, q to quit | Get-Content, more or less |
Do not cat a huge file. Use less, and press q to get out, which is the thing nobody tells you and everyone needs.
GNU Coreutils manual — ls, cat, chmod and friends — and the find and grep manual pages
Section
Section 6
Concept
You said getting into specific files is the problem. Half the time in a Linux room, the reason is not the command. It is that you are not allowed.
Every file and folder carries ten characters describing who may do what. Once you can read those ten characters, permission-denied stops being mysterious.
Linux manual pages — the chmod and ls manual pages
Picture it
One type character, then three groups of three.
Figure (svg): The permission string dash r w x r dash x r dash dash split into type, owner, group and everyone else, with r w and x explained
That last line is the one that unlocks things. A folder you cannot enter looks empty or refuses you, no matter what is inside it.
Worked example
The listing shows a line beginning with the ten characters for a regular file, then owner read write execute, then group read and execute, then others read only.
Split off the first character
Why: A dash means an ordinary file. A d would mean a directory, and that changes what x means.
Read the next three as the owner
Why: Read, write, execute. The owner can do everything with it.
Read the next three as the group
Why: Read and execute, but no write. Members of the file's group can run it but not change it.
Read the last three as everyone else
Why: Read only.
| who | characters | can they read | write | run or enter |
|---|---|---|---|---|
| owner | rwx | yes | yes | yes |
| group | r-x | yes | no | yes |
| everyone else | r-- | yes | no | no |
Verify: by asking who you are
Why: Run whoami and id. If you are not the owner and not in the group, you are in the last row, and the last row is what applies to you.
Picture it
Read four, write two, execute one.
Figure (svg): A table of permission numbers four two and one with their letter equivalents, and the common combinations 755 and 644
So chmod 755 means owner everything, everyone else read and enter. You will type that combination more than any other.
Concept
In a lab you are usually allowed to change permissions or to become the administrator. Outside a lab, think first.
# ---------- Linux ----------
chmod +x script.sh # make it runnable
chmod 644 notes.txt # owner read/write, everyone else read
chown eden notes.txt # change who owns it
sudo cat /root/flag.txt # run one command as the administrator
# ---------- Windows ----------
icacls notes.txt # show who may do what
icacls notes.txt /grant Eden:F # give Eden full control
takeown /F notes.txt # take ownership of it
Start-Process powershell -Verb RunAs # open a shell as administrator| when stuck, run this | it tells you | the Windows version |
|---|---|---|
| whoami | which user you currently are | whoami |
| id | which groups you belong to | whoami /groups |
| sudo -l | which commands you may run as root | net localgroup administrators |
Those three are the first thing to type on any permission-denied message, and sudo -l is frequently the whole answer to a Linux room.
Windows has no sudo. Instead of raising one command you open a whole new shell as administrator, which is why the Windows habit is to check the title bar rather than to prefix a command.
Linux manual pages — chmod, chown and sudo
Trap
Trying to read a file in another user's home directory.
Annotate
Conclude the path is wrong and go looking elsewhere
Why: And spend twenty minutes searching for a file you had already found.
Read the error message, then check who you are.
# ---------- Linux ----------
ls -l /home/bob/notes.txt # who owns it, who may read it
whoami # who am I
id # which groups am I in
sudo -l # what may I run as root
# ---------- Windows ----------
icacls C:\Users\Bob\notes.txt # who may do what to it
whoami # who am I
whoami /groups # which groups am I in
net localgroup administrators # who are the administrators| message | means | next step | the other shell says |
|---|---|---|---|
| No such file or directory | wrong name or wrong place | check spelling and case, then search | Cannot find path ... does not exist |
| Permission denied | it exists, you are not allowed | check who you are, and sudo -l | Access to the path ... is denied |
| Is a directory | you tried to read a folder | use ls, not cat | Get-Content fails on a folder too |
Treat the error text as information
Why: Error messages in both shells are short but specific. The difference between those first two rows saves the most time of anything in this deck.
Run whoami first, in either shell
Why: It is the one command spelt the same on both systems, and on a permission message it is always the right next thing to type.
Check
Solve it on paper before you click.
Check your understanding
A directory shows the characters d r w x, then six dashes. Who can enter it?
Answer: A
Why: The d says directory. The owner has read, write and execute, and execute on a directory means permission to enter. Both the group and everyone else have no permissions at all, so neither can go in.
Section
Section 7
Concept
Everything from here on is meant to be typed, not read. Every slide gives the PowerShell block and the Linux block for the same jobs, and the table underneath lines them up one against one. Nothing here changes anything on the machine.
# ---------- PowerShell ----------
Get-Location # where am I
Set-Location C:\Users\Public # go there
Set-Location .. # up one level
Get-ChildItem # what is here
Get-ChildItem -Force # including hidden items
Get-ChildItem -Recurse # and everything below here
Get-ChildItem -Directory # folders only
Get-ChildItem -File # files only
# ---------- Linux ----------
pwd # where am I
cd /home/eden # go there
cd .. # up one level
ls # what is here
ls -la # including hidden items
ls -R # and everything below here
ls -d */ # folders only
find . -maxdepth 1 -type f # files only| the job | PowerShell | Linux |
|---|---|---|
| which folder am I standing in | Get-Location | pwd |
| go into a folder | Set-Location <path> | cd <path> |
| go up one level | Set-Location .. | cd .. |
| list this folder | Get-ChildItem | ls |
| list hidden items as well | Get-ChildItem -Force | ls -la |
| list everything below here too | Get-ChildItem -Recurse | ls -R |
| folders only | Get-ChildItem -Directory | ls -d */ |
| files only | Get-ChildItem -File | find . -maxdepth 1 -type f |
Run the highlighted line in a folder where the plain listing looked empty. In both shells that one change is the answer to most of the room's early questions.
Microsoft Learn — PowerShell documentation — Get-ChildItem and Set-Location
Linux manual pages — the ls manual page
Concept
Get-Content and cat are the only two you strictly need. The rest exist so that a large file does not fill your screen.
# ---------- PowerShell ----------
Get-Content .\notes.txt # print the whole file
Get-Content .\big.log -TotalCount 20 # the first 20 lines
Get-Content .\big.log -Tail 20 # the last 20 lines
Get-Content .\big.log | more # one screen at a time
(Get-Content .\notes.txt).Count # how many lines is it
Get-Item .\notes.txt | Format-List * # everything about the file
# ---------- Linux ----------
cat notes.txt # print the whole file
head -n 20 big.log # the first 20 lines
tail -n 20 big.log # the last 20 lines
less big.log # one screen at a time, q to quit
wc -l notes.txt # how many lines is it
stat notes.txt # everything about the file| the job | PowerShell | Linux |
|---|---|---|
| print the whole file | Get-Content notes.txt | cat notes.txt |
| the first twenty lines | Get-Content big.log -TotalCount 20 | head -n 20 big.log |
| the last twenty lines | Get-Content big.log -Tail 20 | tail -n 20 big.log |
| a screen at a time | Get-Content big.log | more | less big.log |
| count the lines | (Get-Content notes.txt).Count | wc -l notes.txt |
| size, dates and attributes | Get-Item notes.txt | Format-List * | stat notes.txt |
The brackets in the PowerShell counting line matter: they tell it to finish reading the file first and then ask the result how many lines it has, the same idea as brackets in arithmetic. Linux uses a separate small tool instead, and that difference between the two shells is the whole of the next section.
Microsoft Learn — PowerShell documentation — Get-Content
GNU Coreutils manual — ls, cat, chmod and friends — cat, head, tail and wc
Concept
Two different jobs that beginners mix up constantly. Finding a file by its name is one command in both shells. Finding text inside files is a different command in both shells.
# ---------- PowerShell ----------
Get-ChildItem -Path C:\ -Recurse -Filter "flag*" -ErrorAction SilentlyContinue
Get-ChildItem -Path C:\Users -Recurse -Force -Include "*.txt"
Select-String -Path .\notes.txt -Pattern "password"
Select-String -Path .\notes.txt -Pattern "admin" -Context 2
Get-ChildItem -Recurse -Filter "*.txt" | Select-String -Pattern "flag"
# ---------- Linux ----------
find / -name "flag*" 2>/dev/null
find /home -name "*.txt"
grep "password" notes.txt
grep -C 2 "admin" notes.txt
grep -r "flag" --include="*.txt" .| the job | PowerShell | Linux |
|---|---|---|
| find a file by name, anywhere below here | Get-ChildItem -Recurse -Filter "flag*" | find / -name "flag*" |
| narrow to one kind of file | -Include "*.txt" | -name "*.txt" |
| hide the access-denied complaints | -ErrorAction SilentlyContinue | 2>/dev/null |
| find text inside one file | Select-String -Pattern "password" | grep "password" notes.txt |
| show two lines either side of a hit | -Context 2 | grep -C 2 |
| find text inside every file below here | listing piped into Select-String | grep -r |
The two highlighted lines are the ones to memorise. Both answer 'the file is somewhere on this machine and I do not know where', and both are the same four pieces: where to start, go downwards, match this name, be quiet about what you cannot open.
Microsoft Learn — PowerShell documentation — Select-String and Get-ChildItem
Linux manual pages — the find and grep manual pages
Concept
This group turns a listing into an answer. A room almost never wants the listing; it wants one number or one name out of it.
# ---------- PowerShell ----------
Get-ChildItem | Measure-Object # how many items
Get-ChildItem | Measure-Object -Property Length -Sum # total size in bytes
Get-ChildItem | Sort-Object Length -Descending # biggest first
Get-ChildItem | Select-Object Name, Length # only these two columns
Get-ChildItem | Select-Object -First 5 # only the first five
Get-ChildItem | Where-Object { $_.Length -gt 1000 } # only ones over 1000 bytes
# ---------- Linux ----------
ls | wc -l # how many items
du -sh . # total size of this folder
ls -lS # biggest first
ls -l | awk '{print $9, $5}' # only name and size
ls | head -n 5 # only the first five
find . -maxdepth 1 -size +1k # only ones over 1000 bytes| the room question | PowerShell | Linux |
|---|---|---|
| how many files are in... | Get-ChildItem | Measure-Object | ls | wc -l |
| what is the total size of... | Measure-Object -Property Length -Sum | du -sh . |
| what is the largest file in... | Sort-Object Length -Descending | ls -lS |
| the output is too wide to read | Select-Object Name, Length | ls -l | awk '{print $9, $5}' |
| list the top five... | Select-Object -First 5 | ls | head -n 5 |
| which files are bigger than... | Where-Object { test } | find . -size +1k |
Read the last PowerShell line as 'give me the items, then keep only the ones whose Length is greater than 1000'. The dollar-underscore is just the word 'it', meaning the item currently coming down the belt. Linux has no equivalent because find does its own filtering.
Microsoft Learn — about_Comparison_Operators, and the approved verbs list — Where-Object and the comparison operators
GNU Coreutils manual — ls, cat, chmod and friends — wc, du and head
Concept
Seven questions a room asks over and over, with the answer in each shell. None of them needs an option.
# ---------- PowerShell ----------
whoami # which account am I using
Get-LocalUser # who has an account on this machine
Get-ComputerInfo # OS name, version and build
Get-Process # what is running right now
Get-Service # background services
Get-NetIPConfiguration # IP address and gateway
Get-FileHash .\tool.exe -Algorithm SHA256
# ---------- Linux ----------
whoami # which account am I using
cat /etc/passwd # who has an account on this machine
uname -a # OS name, version and build
ps aux # what is running right now
systemctl list-units --type=service # background services
ip a # IP address and gateway
sha256sum tool.bin # the file's fingerprint| the question | PowerShell | Linux |
|---|---|---|
| which account am I | whoami | whoami |
| who has an account here | Get-LocalUser | cat /etc/passwd |
| what operating system is this | Get-ComputerInfo | uname -a |
| what is running right now | Get-Process | ps aux |
| what services are running | Get-Service | systemctl list-units --type=service |
| what is my IP address | Get-NetIPConfiguration | ip a |
| what is this file's fingerprint | Get-FileHash -Algorithm SHA256 | sha256sum |
whoami is the one command spelt identically in both, which is why it is the safest thing to type when you are unsure which shell you are even looking at. Get-ComputerInfo prints a great deal, so pipe it into Select-Object with the property names you want.
Microsoft Learn — PowerShell documentation — the CimCmdlets and NetTCPIP modules
Linux manual pages — uname, ps and ip
Concept
The commands translate cleanly. Two things about Linux itself do not, and both of them look exactly like a missing file.
# ---------- PowerShell ----------
Get-Content .\Flag.txt # works
Get-Content .\flag.txt # also works, Windows ignores capitals
Get-ChildItem # hidden files do not appear
Get-ChildItem -Force # now they do
# ---------- Linux ----------
cat Flag.txt # works
cat flag.txt # No such file or directory
ls # does not show .flag.txt
ls -la # does show it, because of the leading dot| the difference | Windows | Linux |
|---|---|---|
| capital letters in a name | ignored, Flag.txt is flag.txt | different files entirely |
| what makes a file hidden | the h attribute, in the Mode column | a dot at the front of the name |
| how you reveal hidden files | Get-ChildItem -Force | ls -la |
| the folder separator | a backslash, C:\Users | a forward slash, /home |
Both differences produce the same complaint, which is why 'No such file or directory' is the least informative message you will meet. Before believing it, retype the name with Tab and list the folder with hidden items showing.
Linux manual pages — the ls and bash manual pages
Pattern
A safe drill that touches every idea in this deck. It makes one file, reads it, counts, hashes it and deletes it again, so nothing is left behind on the machine. Run whichever block matches the box you are on, and the numbers line up one to one.
# ---------- PowerShell ----------
Get-Location # 1
Get-ChildItem # 2
Get-ChildItem -Force # 3
Get-Help Get-ChildItem -Examples # 4
Get-Alias ls # 5
New-Item -ItemType File -Name test.txt # 6
Set-Content .\test.txt "hello from the room" # 7
Get-Content .\test.txt # 8
Get-ChildItem | Measure-Object # 9
Get-FileHash .\test.txt -Algorithm SHA256 # 10
Remove-Item .\test.txt # 11
# ---------- Linux ----------
pwd # 1
ls # 2
ls -la # 3
man ls # 4 (q to quit)
type ls # 5
touch test.txt # 6
echo "hello from the room" > test.txt # 7
cat test.txt # 8
ls | wc -l # 9
sha256sum test.txt # 10
rm test.txt # 11| line | what you should see | what it proves you can do |
|---|---|---|
| 1 and 2 | a path, then a list of names | you can tell where you are and what is around you |
| 3 | the same list, possibly with extra rows | you can see hidden files, the first beginner wall |
| 4 and 5 | worked examples, then the real name behind ls | you can answer your own question without leaving the shell |
| 6 and 7 | no output, or a single new row | you can create a file and put text in it |
| 8 | hello from the room | you can read a file back |
| 9 | Count : some number, or just a number | you can turn a listing into a number |
| 10 | a long string of letters and digits | you can fingerprint a file, which the hashing tasks want |
| 11 | no output | you cleaned up after yourself |
Line 11 is worth noticing in both shells: a successful delete prints nothing at all. Silence after a command is usually success, and beginners often retype a line because they were waiting for a message that was never coming.
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — run these on the room's attached machine
Concept
One line each. You do not need to learn them tonight; you need to recognise them when a room mentions one.
| command | what it is for |
|---|---|
| file mystery | what kind of file is this really |
| strings binary | grep flag | pull readable text out of a non-text file |
| base64 -d encoded.txt | decode base64, which rooms use constantly |
| tar -xzf archive.tar.gz | unpack an archive; unzip for zip files |
| history | what commands were run on this machine before |
| python3 -m http.server | serve the current folder over HTTP, for moving files |
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — these appear throughout the Cyber Security 101 path
Pattern
Six questions, in this order. Between them they cover almost every reason a beginner cannot complete a task.
Work down the list rather than trying things. Trying things is what makes an hour disappear.
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — and see the room's own hints as a last resort, not a first one
Picture it
Screenshot this, or write it on a sticky note.
Figure (svg): A six step checklist from where am I, through what is here including hidden, verb and noun, path type, permission, and the help command
Ranking
Same six questions, shuffled. The order is what makes it fast.
Put in order
Why: The first two are free and answer most cases. Permission comes after the path questions because a wrong path also produces a confusing error, and you want to rule out the cheap explanations first. Help is last because it is the slowest, not because it is least useful.
Elimination
A room says there is a flag in your home directory. ls shows nothing.
Eliminate the wrong options
What do you do first?
Survives elimination: A
Why: Hidden files start with a dot and plain ls does not show them. This is step two of the checklist, it costs three characters, and in a Cyber Security 101 room it is right a large fraction of the time.
Explain it
Two sentences, out loud.
Discussion prompt
What does the vertical bar actually do?
Hint: Think of it as a conveyor belt between two machines.
Answer:
It takes whatever the command on the left produced and hands it straight to the command on the right, instead of printing it to the screen.
So you can chain small commands into one job: list the files, keep the big ones, sort them, count them. Each command does one thing and the pipe joins them up.
Microsoft Learn — PowerShell documentation — about_Pipelines
Real world
You are learning this for a reason, so it is worth seeing where it lands.
Discussion prompt
Almost every security task starts with the same two questions you practised tonight. Which two, and why do they come first?
Hint: What did you type first in every example tonight?
Answer:
Where am I, and what is here. On your own machine those are orientation; on someone else's machine they are the first steps of understanding what you are looking at.
Everything later in the path — reading logs, finding credentials left in files, spotting a process that should not be running — is a longer version of tonight's find and read.
Which is why the checklist is worth more than the individual commands. The commands change between rooms; the six questions do not.
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — the rest of the Cyber Security 101 path
Exit ticket
One honest answer, and it decides what we open with next time.
Predict first
Which of these still feels least solid?
Correct: Whichever you picked is where we start next session.
Why: If it is the last one, that is the highest-value thing to fix, because permissions come up in nearly every room from here on and the same ten characters explain all of it.
Connect it up
As you finish the room this week.
Draw it
Keep a running list of every command you had to look up, with one line on what it does in your own words. Do not copy the room's wording.
Send me the list before next session. It is a better plan for the hour than anything I would choose in advance.
Recap
One model, one naming rule, three lifelines, and a checklist. That is the whole of tonight.
| you want to | PowerShell | Linux |
|---|---|---|
| find a file anywhere | Get-ChildItem -Recurse -Force -Filter | find / -name |
| hide error noise | -ErrorAction SilentlyContinue | 2>/dev/null |
| show hidden items | -Force | ls -a |
| search inside files | Select-String -Pattern | grep -r |
| read a long file safely | Get-Content -Tail 10 | less, then q |
| find out why you were denied | - | whoami, id, sudo -l |
TryHackMe — Cyber Security 101 learning path, including the Windows PowerShell and Linux Fundamentals rooms — finish the PowerShell room, then start Linux Fundamentals Part 1
Want this taught 1-on-1? Alexander tutors Cyber Security 101 — $55/session, free consultation.