Cybersecurity Cheat Sheets Hub

    Quick-reference sheets for the commands, queries, ports, filters and concepts you use most while studying the Google Cybersecurity Certificate or working in a SOC. Open a section, or print the whole page for a desk copy.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. Content is original and simplified; verify details with official documentation before relying on them. Practise only on systems and networks you own or are authorised to use.

    1. Linux commands and permissions

    Navigate and read

    pwd                  # where am I
    ls -la               # list all, with details
    cd /var/log          # change directory
    cat file | less      # read, page through
    head -n 20 file      # first lines
    tail -f auth.log     # follow new lines
    grep -i "failed" f   # search text
    find / -name "*.conf" 2>/dev/null
    man grep             # manual

    Files, users, processes

    mkdir d; touch f; cp a b; mv a b
    rm file              # no recycle bin!
    chmod 640 file       # permissions
    chown user:group f   # ownership
    whoami; id           # who am I
    sudo cmd             # run as admin
    ps aux; top          # processes
    ss -tulpn            # listening ports
    cmd > f  /  cmd >> f  /  a | b

    Permissions

    ValueMeaningCommon use
    r=4, w=2, x=1Add per group: owner, group, others-rwxr-x--- = 750
    600Owner read/write onlyPrivate keys, secrets
    640Owner rw, group readSensitive shared files
    644Owner rw, others readNormal documents
    750 / 755Owner full; group/others read and runScripts and programs
    777Everyone full accessAvoid: breaks least privilege

    Symbolic: chmod g+w f adds group write; chmod o-rwx f removes all rights for others.

    2. SQL for log analysis
    -- failed logins
    SELECT username, login_time FROM sign_ins WHERE success = 0;
    
    -- who fails most
    SELECT username, COUNT(*) AS fails FROM sign_ins
    WHERE success = 0 GROUP BY username ORDER BY fails DESC LIMIT 5;
    
    -- outside work hours, not from expected country
    SELECT * FROM sign_ins
    WHERE (login_time < '07:00' OR login_time > '20:00')
      AND NOT country = 'India';
    
    -- pattern and range
    SELECT * FROM events WHERE message LIKE '%denied%';
    SELECT * FROM events WHERE event_date BETWEEN '2026-09-01' AND '2026-09-30';
    
    -- link two tables
    SELECT e.name, d.device_name FROM sign_ins s
    JOIN employees e ON s.emp_id = e.id
    JOIN devices d ON s.device_id = d.id;
    KeywordJob
    SELECT / FROM / WHEREPick columns, table, filter rows
    AND / OR / NOTCombine conditions
    LIKE, %Pattern match, % is any text
    ORDER BY / LIMITSort and trim
    GROUP BY / COUNTSummarise per group
    JOIN … ONCombine tables on a shared key

    Table and column names above are examples. Always include WHERE on UPDATE or DELETE.

    3. Python snippets

    Basics

    count = 7
    if count >= 5:
        print("Possible brute force")
    elif count > 0:
        print("Watch")
    else:
        print("Normal")
    
    ips = ["10.0.0.5", "10.0.0.9"]
    for ip in ips:
        print(ip)
    
    def flag(n, limit=5):
        return n >= limit

    Files, regex, counting

    import re
    from collections import Counter
    pat = r"\d{1,3}(?:\.\d{1,3}){3}"
    c = Counter()
    try:
        with open("log.txt") as f:
            for line in f:
                for ip in re.findall(pat, line):
                    c[ip] += 1
    except FileNotFoundError:
        print("Check the file path")
    print(c.most_common(5))
    TipDetail
    = vs ==Assign vs compare
    IndexLists start at 0
    Strings.strip() .lower() .split(",") .replace()
    File modes“r” read, “w” overwrite, “a” append
    TracebackRead from the bottom: last line names the error
    4. Ports and protocols
    PortProtocolNotes
    20/21FTPUnencrypted file transfer
    22SSH / SFTPEncrypted remote login
    23TelnetUnencrypted; avoid
    25SMTPSending email
    53DNSNames to IPs (UDP and TCP)
    67/68DHCPAutomatic IP assignment
    80HTTPUnencrypted web
    110 / 143POP3 / IMAPReading email
    443HTTPSWeb over TLS
    445SMBWindows file sharing
    3306MySQLDatabase
    3389RDPWindows remote desktop

    TCP: reliable, three-way handshake (SYN, SYN-ACK, ACK). UDP: fast, no handshake. ICMP: diagnostics such as ping. ARP: IP to MAC on a local network.

    5. OSI model
    #LayerJobExamples
    7ApplicationServices users’ programs useHTTP, DNS, SMTP
    6PresentationFormat, encryptionTLS, encoding
    5SessionOpen, manage, close conversationsSession control
    4TransportDelivery between programsTCP, UDP, ports
    3NetworkAddressing and routingIP, routers
    2Data linkLocal deliveryMAC, switches, ARP
    1PhysicalSignals over a mediumCables, Wi-Fi

    Top-down memory aid: All People Seem To Need Data Processing. TCP/IP groups these into four layers: network access, internet, transport, application.

    6. Wireshark display filters
    FilterShows
    ip.addr == 10.0.0.5Traffic to or from a host
    ip.src == 10.0.0.5 / ip.dst == ...One direction only
    tcp.port == 443TCP traffic on a port
    udp.port == 53 or dnsDNS traffic
    http.request.method == "POST"HTTP POST requests
    tls.handshakeTLS handshakes
    tcp.flags.syn == 1 && tcp.flags.ack == 0New connection attempts (SYN scan or flood)
    tcp.analysis.retransmissionRetransmitted packets
    icmp / arpPing and ARP traffic
    dns.qry.name contains "example"DNS queries containing text
    !(arp or dns)Hide noise

    Combine with && (and), || (or), ! (not). Display filters work on captured packets; capture filters (BPF, e.g. port 53) limit what is recorded. Command line: tcpdump -nn -r capture.pcap port 53. Capture only on networks you are authorised to monitor.

    7. Common attacks and defenses
    AttackWhat it doesMain defenses
    Phishing / social engineeringTricks people into sharing data or clickingTraining, email filtering, MFA, reporting
    Malware / ransomwareHarmful code; may lock dataPatching, EDR, offline backups, least privilege
    Brute force / credential stuffingGuessing or reusing passwordsMFA, lockouts, long unique passwords, salted hashes
    SQL injectionInput becomes database commandsParameterised queries, input validation
    XSSScript runs in other users’ browsersOutput encoding, content security policy
    DoS / DDoS / SYN floodOverwhelms a serviceRate limits, scrubbing, redundancy, SYN cookies
    On-path (MITM) / ARP, DNS spoofingIntercepts or redirects trafficTLS, VPN, ARP inspection, DNSSEC
    Insider threatMisuse of legitimate accessLeast privilege, logging, separation of duties
    Supply chainCompromised vendor or updateVendor review, signed updates, monitoring
    Zero-dayFlaw with no patch yetDefense in depth, segmentation, monitoring
    8. Hashing vs encryption
    HashingSymmetric encryptionAsymmetric encryption
    DirectionOne-wayTwo-way with keyTwo-way with key pair
    KeysNone (salt optional)One shared keyPublic and private key
    OutputFixed-length digestCiphertextCiphertext or signature
    Main goalIntegrity, password storageConfidentiality of bulk dataKey exchange, signatures
    ExamplesSHA-256AESRSA, ECC
    SpeedFastFastSlower
    • Salt: random data added before hashing so identical passwords differ.
    • Digital signature: proves who signed and that data was not changed. TLS combines these for HTTPS.
    • Avoid old algorithms such as MD5 for security and never invent your own cryptography.
    9. Incident response steps
    PhaseKey actions
    1. PreparationPlaybooks, contacts, tools, logging, training, backups
    2. Detection and analysisReview alerts, triage, scope affected systems, collect evidence, decide severity, escalate
    3. Containment, eradication, recoveryIsolate hosts, block indicators, remove malware, patch, restore from clean backups, monitor
    4. Post-incident activityRoot cause, lessons learned, update playbooks and controls, final report
    • Evidence: collect volatile data first (memory, connections), work on copies, record hashes, keep a chain of custody.
    • Escalation note: what happened, when, systems affected, evidence, actions taken, what you need, next update time.
    • Terms: event vs incident, IoC vs IoA, false positive vs false negative.

    Video searches: IR lifecycle · Wireshark filters · Linux commands

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official documentation. Last reviewed: October 2026.