Cybersecurity Cheat Sheets Hub
Quick-reference sheets for the commands, queries, ports, filters and concepts you use most while studying the Google Cybersecurity Certificate or working in a SOC. Open a section, or print the whole page for a desk copy.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. Content is original and simplified; verify details with official documentation before relying on them. Practise only on systems and networks you own or are authorised to use.
1. Linux commands and permissions
Navigate and read
pwd # where am I
ls -la # list all, with details
cd /var/log # change directory
cat file | less # read, page through
head -n 20 file # first lines
tail -f auth.log # follow new lines
grep -i "failed" f # search text
find / -name "*.conf" 2>/dev/null
man grep # manualFiles, users, processes
mkdir d; touch f; cp a b; mv a b
rm file # no recycle bin!
chmod 640 file # permissions
chown user:group f # ownership
whoami; id # who am I
sudo cmd # run as admin
ps aux; top # processes
ss -tulpn # listening ports
cmd > f / cmd >> f / a | bPermissions
| Value | Meaning | Common use |
|---|---|---|
| r=4, w=2, x=1 | Add per group: owner, group, others | -rwxr-x--- = 750 |
| 600 | Owner read/write only | Private keys, secrets |
| 640 | Owner rw, group read | Sensitive shared files |
| 644 | Owner rw, others read | Normal documents |
| 750 / 755 | Owner full; group/others read and run | Scripts and programs |
| 777 | Everyone full access | Avoid: breaks least privilege |
Symbolic: chmod g+w f adds group write; chmod o-rwx f removes all rights for others.
2. SQL for log analysis
-- failed logins
SELECT username, login_time FROM sign_ins WHERE success = 0;
-- who fails most
SELECT username, COUNT(*) AS fails FROM sign_ins
WHERE success = 0 GROUP BY username ORDER BY fails DESC LIMIT 5;
-- outside work hours, not from expected country
SELECT * FROM sign_ins
WHERE (login_time < '07:00' OR login_time > '20:00')
AND NOT country = 'India';
-- pattern and range
SELECT * FROM events WHERE message LIKE '%denied%';
SELECT * FROM events WHERE event_date BETWEEN '2026-09-01' AND '2026-09-30';
-- link two tables
SELECT e.name, d.device_name FROM sign_ins s
JOIN employees e ON s.emp_id = e.id
JOIN devices d ON s.device_id = d.id;
| Keyword | Job |
|---|---|
| SELECT / FROM / WHERE | Pick columns, table, filter rows |
| AND / OR / NOT | Combine conditions |
| LIKE, % | Pattern match, % is any text |
| ORDER BY / LIMIT | Sort and trim |
| GROUP BY / COUNT | Summarise per group |
| JOIN … ON | Combine tables on a shared key |
Table and column names above are examples. Always include WHERE on UPDATE or DELETE.
3. Python snippets
Basics
count = 7
if count >= 5:
print("Possible brute force")
elif count > 0:
print("Watch")
else:
print("Normal")
ips = ["10.0.0.5", "10.0.0.9"]
for ip in ips:
print(ip)
def flag(n, limit=5):
return n >= limitFiles, regex, counting
import re
from collections import Counter
pat = r"\d{1,3}(?:\.\d{1,3}){3}"
c = Counter()
try:
with open("log.txt") as f:
for line in f:
for ip in re.findall(pat, line):
c[ip] += 1
except FileNotFoundError:
print("Check the file path")
print(c.most_common(5))| Tip | Detail |
|---|---|
| = vs == | Assign vs compare |
| Index | Lists start at 0 |
| Strings | .strip() .lower() .split(",") .replace() |
| File modes | “r” read, “w” overwrite, “a” append |
| Traceback | Read from the bottom: last line names the error |
4. Ports and protocols
| Port | Protocol | Notes |
|---|---|---|
| 20/21 | FTP | Unencrypted file transfer |
| 22 | SSH / SFTP | Encrypted remote login |
| 23 | Telnet | Unencrypted; avoid |
| 25 | SMTP | Sending email |
| 53 | DNS | Names to IPs (UDP and TCP) |
| 67/68 | DHCP | Automatic IP assignment |
| 80 | HTTP | Unencrypted web |
| 110 / 143 | POP3 / IMAP | Reading email |
| 443 | HTTPS | Web over TLS |
| 445 | SMB | Windows file sharing |
| 3306 | MySQL | Database |
| 3389 | RDP | Windows remote desktop |
TCP: reliable, three-way handshake (SYN, SYN-ACK, ACK). UDP: fast, no handshake. ICMP: diagnostics such as ping. ARP: IP to MAC on a local network.
5. OSI model
| # | Layer | Job | Examples |
|---|---|---|---|
| 7 | Application | Services users’ programs use | HTTP, DNS, SMTP |
| 6 | Presentation | Format, encryption | TLS, encoding |
| 5 | Session | Open, manage, close conversations | Session control |
| 4 | Transport | Delivery between programs | TCP, UDP, ports |
| 3 | Network | Addressing and routing | IP, routers |
| 2 | Data link | Local delivery | MAC, switches, ARP |
| 1 | Physical | Signals over a medium | Cables, Wi-Fi |
Top-down memory aid: All People Seem To Need Data Processing. TCP/IP groups these into four layers: network access, internet, transport, application.
6. Wireshark display filters
| Filter | Shows |
|---|---|
ip.addr == 10.0.0.5 | Traffic to or from a host |
ip.src == 10.0.0.5 / ip.dst == ... | One direction only |
tcp.port == 443 | TCP traffic on a port |
udp.port == 53 or dns | DNS traffic |
http.request.method == "POST" | HTTP POST requests |
tls.handshake | TLS handshakes |
tcp.flags.syn == 1 && tcp.flags.ack == 0 | New connection attempts (SYN scan or flood) |
tcp.analysis.retransmission | Retransmitted packets |
icmp / arp | Ping and ARP traffic |
dns.qry.name contains "example" | DNS queries containing text |
!(arp or dns) | Hide noise |
Combine with && (and), || (or), ! (not). Display filters work on captured packets; capture filters (BPF, e.g. port 53) limit what is recorded. Command line: tcpdump -nn -r capture.pcap port 53. Capture only on networks you are authorised to monitor.
7. Common attacks and defenses
| Attack | What it does | Main defenses |
|---|---|---|
| Phishing / social engineering | Tricks people into sharing data or clicking | Training, email filtering, MFA, reporting |
| Malware / ransomware | Harmful code; may lock data | Patching, EDR, offline backups, least privilege |
| Brute force / credential stuffing | Guessing or reusing passwords | MFA, lockouts, long unique passwords, salted hashes |
| SQL injection | Input becomes database commands | Parameterised queries, input validation |
| XSS | Script runs in other users’ browsers | Output encoding, content security policy |
| DoS / DDoS / SYN flood | Overwhelms a service | Rate limits, scrubbing, redundancy, SYN cookies |
| On-path (MITM) / ARP, DNS spoofing | Intercepts or redirects traffic | TLS, VPN, ARP inspection, DNSSEC |
| Insider threat | Misuse of legitimate access | Least privilege, logging, separation of duties |
| Supply chain | Compromised vendor or update | Vendor review, signed updates, monitoring |
| Zero-day | Flaw with no patch yet | Defense in depth, segmentation, monitoring |
8. Hashing vs encryption
| Hashing | Symmetric encryption | Asymmetric encryption | |
|---|---|---|---|
| Direction | One-way | Two-way with key | Two-way with key pair |
| Keys | None (salt optional) | One shared key | Public and private key |
| Output | Fixed-length digest | Ciphertext | Ciphertext or signature |
| Main goal | Integrity, password storage | Confidentiality of bulk data | Key exchange, signatures |
| Examples | SHA-256 | AES | RSA, ECC |
| Speed | Fast | Fast | Slower |
- Salt: random data added before hashing so identical passwords differ.
- Digital signature: proves who signed and that data was not changed. TLS combines these for HTTPS.
- Avoid old algorithms such as MD5 for security and never invent your own cryptography.
9. Incident response steps
| Phase | Key actions |
|---|---|
| 1. Preparation | Playbooks, contacts, tools, logging, training, backups |
| 2. Detection and analysis | Review alerts, triage, scope affected systems, collect evidence, decide severity, escalate |
| 3. Containment, eradication, recovery | Isolate hosts, block indicators, remove malware, patch, restore from clean backups, monitor |
| 4. Post-incident activity | Root cause, lessons learned, update playbooks and controls, final report |
- Evidence: collect volatile data first (memory, connections), work on copies, record hashes, keep a chain of custody.
- Escalation note: what happened, when, systems affected, evidence, actions taken, what you need, next update time.
- Terms: event vs incident, IoC vs IoA, false positive vs false negative.
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Verify details against official documentation. Last reviewed: October 2026.
