According to W3Techs, Linux is used by 62.6% of all the websites whose operating system W3Techs knows. The Linux commands below are therefore the working vocabulary of most web servers, as well as the laptop in front of you. Every entry is grouped by task, gives the syntax and a one-line purpose, and was checked against the command’s own man page or its project’s manual, current as of September 2026.
The groups follow the order you meet them at a terminal: files, networking, packages, permissions, search, processes, disks, archives and admin rights. Deprecated tools are flagged from their own documentation. The netstat manual describes that program as mostly obsolete, so the networking group teaches ip and ss first and maps each older tool to its successor.
Key Takeaways
- Linux runs 62.6% of websites whose operating system W3Techs can identify, and Ubuntu is used by 15.1% of the websites that use Linux.
- Linux stood at 3.90%, per Valve’s Steam Hardware & Software Survey for August 2026.
- A numeric
chmodmode adds up bit values of 4, 2 and 1 for read, write and execute. killsends TERM when no signal is named, and the KILL signal is number 9.- Section 1 of the manual holds executable programs or shell commands, which is where
man lslooks first. df -hprints sizes in powers of 1024, so disk space reads as a human-readable size rather than a block count.
What Is a Linux Command?
A Linux command is a program or shell builtin you run by name at a prompt, followed by options and arguments. Per Linux man-pages documentation, the man page’s section 1 covers executable programs or shell commands. By contrast, cd is documented as a shell builtin, per GNU’s Bash manual, rather than as a separate program.
Almost everything below takes the same shape: the command name, then options, then the files or targets it works on.
ls -l -h /var/log
# command options argumentThe GNU utilities documented in the coreutils manual are mostly compatible with the POSIX standard, which is why ls, cp and rm behave the same way on Ubuntu, Fedora and Arch. Most modern shells have a built-in kill command, with a usage rather similar to that of the kill program, so type kill is the quick way to see which one you are calling.
Builtin or program: Run
type cdandtype ls. A builtin prints as a shell builtin, and a program prints its path, which tells you whethermanor your shell’shelpis the right place to look.
For a first pass through installing a distribution and running these basics, the Linux installation and basic commands walkthrough covers the same ground with screenshots.
How do I get help for a Linux command?
Use man followed by the command name. man is the system’s manual pager, and a section number directs it to look only in that section of the manual. Most programs also accept --help, and builtins answer to help.
man ls
man 8 ip # section 8 only
ls --help
help cdNavigation and File Management Commands
According to Linux man-pages entries for each, pwd prints the full filename of the current working directory, ls lists information about the files, the current directory by default, and cp copies files and directories. Those three and seven more cover everyday file work at the prompt.
Command | Syntax | What it does |
|---|---|---|
pwd | pwd | Prints the full path of the current working directory |
cd | cd [directory] | Changes the working directory, or goes to $HOME with no argument |
ls | ls [options] [file...] | Lists directory contents, the current directory by default |
cp | cp source dest | Copies files and directories |
mv | mv source dest | Moves or renames files |
mkdir | mkdir [-p] directory | Creates directories if they do not already exist |
touch | touch file | Creates an empty file or updates its timestamps |
cat | cat file... | Concatenates files and prints them on standard output |
ln | ln -s target link | Makes links between files |
rm | rm [-r] file... | Removes files, and directories with -r |
Source: Linux man-pages project (man7.org), GNU Bash manual, September 2026
mv renames SOURCE to DEST, or moves SOURCE(s) to DIRECTORY, so the same command renames a file in place and moves it elsewhere. touch updates the access and modification times of each FILE, and a FILE argument that does not exist is created empty, which makes it the quickest way to create a placeholder file.
pwd # where am I?
cd ~/projects # go to a directory
mkdir -p notes/drafts # create nested folders in one step
touch notes/todo.txt # create an empty file
cp notes/todo.txt notes/todo.bak
mv notes/todo.bak archive/ # move into another folder
cat notes/todo.txt # print the filerm has no undo:
rmremoves files outright rather than moving them to a desktop trash folder. GNU rm fails any attempt to remove the root directory, /, when used with the--recursiveoption, and this is the default behavior, but that guard covers only/itself, so check the path before anyrm -r.
To clear out old files on a schedule rather than by hand, the guide to deleting files older than a set number of days pairs find with rm safely.
What is the difference between ls and ls -l?
Plain ls prints names only, while ls -l adds a line of detail per file. The -l option uses a long listing format, and -h with -l prints human-readable sizes. -a does not ignore entries starting with a dot, which reveals hidden files.
ls -l # permissions, owner, size, date
ls -lh # human-readable sizes
ls -la ~ # include hidden dotfilesNetworking Commands: ip and ss Replace ifconfig and netstat
On the Linux man-pages site, the netstat manual calls the program mostly obsolete and names ss as its replacement, with ip route replacing netstat -r. That makes ip and ss the current tools for addresses, routes and open connections. ip shows and manipulates routing, network devices, interfaces and tunnels, and section 8 of the manual holds system administration commands, which is where ip, ss and ping live.
Older command | Current replacement | What it shows |
|---|---|---|
netstat | ss | Open sockets and connections |
netstat -r | ip route | The kernel routing table |
netstat -i | ip -s link | Per-interface statistics |
netstat -g | ip maddr | Multicast group membership |
ifconfig | ip addr, ip link | Addresses and interface state |
Source: Linux man-pages project netstat(8), ip(8) and ifconfig(8) pages, September 2026
ss is used to dump socket statistics and can display more TCP and state information than other tools. ifconfig comes from the net-tools project, the same package as netstat. The ifconfig page itself points to ip link from iproute2 for link-layer details, and ip addr covers the address side.
ip addr # IP addresses on every interface
ip route # routing table and default gateway
ss -tuln # listening TCP and UDP ports, numeric
ping -c 4 techlila.com # four echo requests, then stop
ssh user@server.example # log in to a remote machineping sends ICMP ECHO_REQUEST to network hosts, which makes it the first check when a site will not load, and ssh is the OpenSSH remote login client for working on another machine’s shell.
Why it matters: The netstat manual maps netstat -i to ip -s link and netstat -g to ip maddr, so every common netstat habit has a direct successor. Retraining those habits takes an afternoon, and it removes a dependency on a tool its own manual has already written off.
Package Management Commands by Distribution
The package command you need depends on the distribution, and on servers the Debian family leads. Ubuntu is used by 15.1% of all the websites who use Linux, ahead of Debian at 5.8% and CentOS at 1.2%, according to W3Techs, which makes apt the package tool most server readers meet first.
apt provides a high-level commandline interface for the package management system on Debian and Ubuntu, and update downloads package information from all configured sources, which is why apt update comes before any install. dnf install makes sure that the given packages and their dependencies are installed on the system, and pacman -S installs packages directly from the remote repositories, including all dependencies required to run the packages. Pacman is the front-end to libalpm, the Arch Linux Package Management library.
Desktop gaming machines tell a different story from servers. Linux stood at 3.90% of Steam’s combined survey, with SteamOS Holo at 0.82%, CachyOS at 0.60% and Arch Linux at 0.34%, a mix where pacman matters as much as apt.
Task | apt | dnf | pacman |
|---|---|---|---|
Refresh package lists | sudo apt update | sudo dnf makecache | sudo pacman -Sy |
Install a package | sudo apt install pkg | sudo dnf install pkg | sudo pacman -S pkg |
Remove a package | sudo apt remove pkg | sudo dnf remove pkg | sudo pacman -R pkg |
Upgrade everything | sudo apt upgrade | sudo dnf upgrade | sudo pacman -Syu |
Search for a package | apt search term | dnf search term | pacman -Ss term |
Source: Debian apt(8), DNF command reference, pacman(8), September 2026
upgrade installs available upgrades of all packages currently installed, and existing packages will never be removed, which makes it the safe routine update on Debian and Ubuntu. Adding a third-party source is its own task, covered step by step in the guide to creating a repository in Linux, and the trade-offs between families are laid out in choosing a Linux distro.
File Permission Commands: chmod and chown
According to the chmod man page, a numeric mode is from one to four octal digits (0-7), derived by adding up the bits with values 4, 2, and 1. chmod uses those digits to set who can read, write and execute a file, and chown sets who owns it.
Octal value | Permission | Symbol |
|---|---|---|
4 | Read | r |
2 | Write | w |
1 | Execute | x |
Source: man7.org chmod(1), September 2026
The second digit selects permissions for the user who owns the file, the third for other users in the file’s group, and the fourth for other users not in the file’s group. In practice you type three digits, because the leading special-bits digit is assumed to be zero when omitted. Owner read, write and execute plus read and execute for everyone else adds up to 755, and owner read and write plus read-only for the rest adds up to 644.
chmod 755 deploy.sh # owner rwx, group r-x, others r-x
chmod 644 notes.txt # owner rw-, group r--, others r--
chmod u+x script.sh # symbolic form: add execute for the owner
sudo chown alice:staff report.pdf # new owner and groupchown changes the user and/or group ownership of each given file, and it usually needs sudo because only an administrator can hand a file to another account.
Text Search Commands: grep and find
According to the Linux man-pages project, grep searches for patterns in each FILE, while GNU find searches the directory tree rooted at each given starting-point by evaluating the given expression from left to right. So grep searches inside files and find searches for the files themselves, and with head, tail, wc and sort they cover most text work.
Command | Syntax | What it does |
|---|---|---|
grep | grep [options] pattern file | Prints lines that match a pattern |
find | find path -name "*.log" | Searches a directory tree for files |
head | head -n 20 file | Prints the first lines of a file |
tail | tail -f file | Prints the last lines, or follows a growing file |
less | less file | Pages through a file in the terminal |
wc | wc -l file | Counts newlines, words and bytes |
sort | sort file | Sorts lines of text |
Source: man7.org Linux man pages, September 2026
head prints the first 10 lines of each FILE to standard output and tail prints the last 10 lines unless you pass a different count. less does not have to read the entire input file before starting, so with large input files it starts up faster than text editors like vi.
grep -rn "error" /var/log/nginx/ # recursive search with line numbers
find ~/Downloads -name "*.iso" # every ISO file under Downloads
tail -f /var/log/syslog # watch a log as it grows
grep -c "error" access.log # count matching linesThe takeaway: If no starting-point is specified,
.is assumed, so a barefind -namesearches the current directory and everything below it. Pair that withgrep -rfor contents, and the two commands answer nearly every “where is it” question without leaving the terminal.
More filters and one-liners built on these two are in the guide to Linux commands for intermediate users.
Process Management Commands: ps, top and kill
According to the kill(1) man page, if no signal is specified, kill sends the TERM signal, which should be used in preference to the KILL signal (number 9). A process can catch TERM and clean up first. In short, ps lists running processes once, top watches them live, and kill stops one.
Command | Syntax | What it does |
|---|---|---|
ps | ps aux | Shows a snapshot of running processes |
top | top | Shows a live, updating view of processes and load |
kill | kill PID | Sends a signal, TERM by default, to a process |
kill -9 | kill -9 PID | Sends KILL, which the process cannot catch |
Source: man7.org ps(1), top(1) and kill(1) pages, September 2026
ps displays information about a selection of the active processes, and for a repetitive update of the selection, top is the tool to use instead. The top program provides a dynamic real-time view of a running system.
ps aux | grep firefox # find the process ID (second column)
kill PID # use the PID from ps; asks it to exit cleanly (TERM)
kill -9 PID # force it if TERM did not work (KILL)
top # live view; press q to quitThe KILL signal cannot be caught, and so does not give the target process the opportunity to perform any clean-up before terminating. Treat kill -9 as the second step, never the first, especially on anything that writes to disk.
Disk, Memory and Service Commands
According to its Linux man-pages entry, df displays the amount of space available on the file system containing each file name argument. Space is shown in blocks by default, which is why -h is worth adding every time. df, du and free answer the three questions behind most slowdowns: which disk is full, which folder filled it, and how much memory is left.
Command | Syntax | What it does |
|---|---|---|
df | df -h | Reports file system space usage |
du | du -sh folder | Estimates the space a folder uses |
free | free -h | Shows free and used memory and swap |
uname | uname -a | Prints kernel and system information |
systemctl | systemctl status name | Inspects and controls systemd services |
Source: man7.org Linux man pages, September 2026
free displays the total amount of free and used physical and swap memory in the system, as well as the buffers and caches used by the kernel. systemctl may be used to introspect and control the state of the systemd system and service manager, and its start, stop and enable verbs manage individual services.
free -h # memory and swap, human-readable
systemctl status ssh # is the SSH service running?
sudo systemctl restart nginxLonger fixes for full disks and misbehaving services are in the collection of Linux tweaks and troubleshooting commands.
How do I check disk space in Linux?
Run df -h for free space per drive and du -sh for the size of one folder. -h prints sizes in powers of 1024, and du -s displays only a total for each argument, so du -sh ~/Downloads returns one readable number instead of a line per file.
df -h
du -sh ~/DownloadsArchive and Compression Commands: tar and gzip
According to the Linux man-pages project, tar is an archiving utility, and the GNU manual states that gzip reduces the size of the named files using Lempel-Ziv coding (LZ77), replacing each file with one ending in .gz where possible. tar bundles many files into one archive and gzip shrinks it, so the two usually travel together as a .tar.gz.
tar -czf backup.tar.gz ~/projects # create a gzip-compressed archive
tar -tzf backup.tar.gz # list what is inside
tar -xzf backup.tar.gz -C /tmp # extract into /tmp
gzip big.log # compress to big.log.gz
gunzip big.log.gz # decompressThe letters: c creates, x extracts, t lists, z adds gzip, and f names the archive file, which must come last before the filename.
Running Commands as Root With sudo
According to the sudo manual, sudo and sudoedit execute a command as another user, and that user is root unless you name a different one with -u. sudo is how every package, service and ownership change above is done on a desktop system.
sudo apt update # one command as root
sudo -u www-data ls /var/www # one command as another user
sudo useradd -m alex # create a user with a home folder
sudo passwd alex # set that user's passwordWhen invoked without the -D option, the useradd command creates a new user account using the values specified on the command line plus the default values from the system. Keep sudo for the one command that needs it rather than opening a root shell, so a typo in the next command cannot touch system files. The next tier of administration tools is in the walkthrough of advanced Linux terminal commands.
What are the basic Linux commands every beginner should know?
Start with 10 core Linux commands: pwd, cd, ls, cp, mv, mkdir, rm, cat, man and sudo. They cover moving around, handling files, reading them, getting help and making system changes.
cat concatenates FILE(s) to standard output, which is why it doubles as the quickest file viewer, and mkdir creates the DIRECTORY(ies), if they do not already exist. Once those feel routine, the lighter side of the terminal is collected in Linux terminal Easter eggs and tricks.
Conclusion
Linux is used by 62.6% of all the websites whose operating system W3Techs knows, and each of those servers answers to the commands in the tables above. Learn the file and navigation group first, then ip, ss and your distribution’s package manager, and keep man open for everything else.
The netstat manual already names ss and ip route as its replacements, so the next change to watch is which older habits your distribution stops shipping. Checking a command’s own man page before trusting a tutorial, including this one, is the habit that keeps a cheat sheet from going stale.


Leave a comment
Have something to say about this article? Add your comment and start the discussion.