October 9, 2026
Linux Fundamentals for SOC Analysts: Commands, File Systems & Permissions | SOC Day 7
As part of my cybersecurity learning journey, I continued strengthening my Security Operations Center (SOC) fundamentals by exploring…

By saurabh
4 min read
Linux Fundamentals for SOC Analysts: Commands, File Systems & Permissions | SOC Day 7
As part of my cybersecurity learning journey, I continued strengthening my Security Operations Center (SOC) fundamentals by exploring Linux, its file system structure, essential command-line utilities, and file permissions.
Linux is an important skill for cybersecurity professionals because it is widely used in server environments, security tools, and investigation workflows. Understanding how to navigate and analyse a Linux system can help SOC analysts investigate suspicious activity more effectively.
In this article, I'll share the key concepts I learned during SOC Day 7.
- What Is Linux?
Linux is an open-source operating system based on Unix principles. It is widely recognised for its stability, security, and flexibility.
Some commonly used Linux distributions include:
Ubuntu — General-purpose Linux distribution.
CentOS — Historically popular in server environments.
Kali Linux — Designed for penetration testing and security assessments.
Debian — A widely used Linux distribution known for stability.
Linux knowledge is useful across multiple cybersecurity domains, including SOC operations, penetration testing, digital forensics, and security research.
- Why Is Linux Important for SOC Analysts?
Linux provides powerful command-line tools that help security professionals investigate systems, analyse logs, and automate repetitive tasks.
Log Analysis
System and application logs contain information about events occurring on a machine.
A SOC analyst can examine these logs to investigate authentication failures, unusual processes, and potentially suspicious activity.
Threat Hunting
Threat hunting involves searching for suspicious behaviour that may not have been detected by existing security controls.
Linux command-line utilities can help analysts search files, filter events, and correlate relevant information.
Malware Analysis
Linux can be used in controlled malware-analysis environments to examine suspicious files and understand their behaviour.
Automation and Scripting
Shell scripting and command-line utilities can automate repetitive investigation tasks, helping analysts work more efficiently.
Linux is therefore a valuable skill for anyone preparing for a SOC analyst or security operations role.
- Understanding the Linux File System Structure
Linux organises files and directories in a hierarchical structure.
Understanding the purpose of important directories helps analysts navigate systems and locate information during investigations.
DirectoryPurpose/Root directory and starting point of the file system/homeUser-specific files and data/etcSystem and service configuration files/var/logSystem and application logs/binEssential user command binaries/sbinSystem administration binaries/tmpTemporary files used by applications and processes
Why Should SOC Analysts Know These Directories?
Imagine investigating a Linux system after detecting suspicious authentication activity.
An analyst may need to inspect logs, review configuration files, or examine user-specific data.
Knowing where these resources are generally stored makes the investigation process more efficient.
For example:
ls /var/log
This lists the contents of the log directory.
less /var/log/syslog
On systems that use /var/log/syslog, this allows you to inspect the file page by page.
Note: Log locations and filenames can vary across Linux distributions.
- Essential Linux Commands for SOC Work
During this learning session, I reviewed several useful Linux commands.
CommandPurposeExamplelsList files and directoriesls -lacdChange directorycd /var/logcatDisplay file contentscat file.txtgrepSearch for text patternsgrep "error" auth.loglessView files page by pageless /var/log/syslogwhoamiDisplay the current userwhoamidateDisplay the system date and timedatecutExtract fields or columnscut -d',' -f1 file.csvclearClear the terminal screenclearmanDisplay command documentationman ls
Practical Example: Searching Logs
Suppose you want to search an authentication log for entries containing the word Failed.
You could use:
grep "Failed" /var/log/auth.log
This searches the specified log file for matching lines.
On systems using a different authentication-log path, you would need to adjust the command accordingly.
SOC application: Searching logs for specific keywords is a useful starting point when investigating failed logins or other authentication-related events.
- Understanding Linux File Permissions
Linux uses permissions to control what users can do with files and directories.
Permissions are commonly considered for three categories:
User (owner): The owner of the file.
Group: Users belonging to the file's group.
Others: Other users on the system.
Three fundamental permission types are:
SymbolPermissionNumeric ValuerRead4wWrite2xExecute1
These numeric values can be combined to represent permission sets.
Examples of Permission Combinations
Symbolic PermissionNumeric ValueMeaningrwx7Read, write, and executerw-6Read and writer-x5Read and executer--4Read only
For example:
rwx = 4 + 2 + 1 = 7
These values are useful when interpreting numeric Linux permissions.
- Changing Permissions with chmod
The chmod command changes file permissions.
Here are examples from my notes:
Add Write Permission
chmod +w filename
Adds write permission to the applicable permission classes.
Add Write Permission for User, Group, and Others
chmod ugo+w filename
Adds write permission for the user, group, and others.
Remove Read Permission
chmod ugo-r filename
Removes read permission for the user, group, and others.
Important: Permission changes should be made carefully. Granting excessive permissions can expose sensitive files or allow unauthorised modifications.
For SOC analysts, understanding chmod helps when reviewing file access, investigating permission changes, and assessing suspicious activity.
- Understanding Directory Permissions
Directories use the same basic permission symbols, but their practical meanings differ from those for regular files.
Read (r): Allows listing directory entries, subject to other applicable access controls.
Write (w): Allows creating, deleting, or renaming directory entries, subject to other permissions and restrictions.
Execute (x): Allows traversing or accessing the directory when other access requirements are satisfied.
For example, a user may be able to read a file but still be unable to access it if they lack the necessary directory traversal permissions.
This distinction is important when investigating Linux access-control issues.
- How These Skills Apply to SOC Investigations
The concepts covered in this session provide a foundation for practical security investigations.
A SOC analyst can use Linux skills to:
Navigate the file system and locate relevant logs.
Search log files for suspicious events.
Understand user accounts and file ownership.
Review file and directory permissions.
Investigate unexpected permission changes.
Use command-line tools to filter information and support incident analysis.
These skills become even more useful when combined with SIEM platforms, endpoint telemetry, network logs, and threat-hunting techniques.
Conclusion
SOC Day 7 was focused on building a strong Linux foundation for security operations.
I explored Linux fundamentals, important file system directories, useful command-line utilities, and file permissions.
Although these concepts may appear basic, they are valuable building blocks for more advanced topics such as log investigation, threat hunting, incident response, and digital forensics.
My next step is to strengthen these concepts through hands-on Linux practice and security investigation labs.
The goal is simple: learn the fundamentals, practise consistently, and gradually build practical SOC skills.
Key Takeaways
Linux is widely used in server and cybersecurity environments.
/var/log is an important location for system and application logs.
Commands such as grep, less, and cut help analyse text and log files.
Linux permissions control access for users, groups, and others.
chmod modifies file permissions and should be used carefully.
Hands-on practice is essential for developing investigation skills.
This is another step in my ongoing cybersecurity learning journey. 🚀
SOC Learning Series — Day 7 | Linux Fundamentals & File Permissions
#CyberSecurity #SOCAnalyst #Linux #LinuxCommands #FilePermissions #LogAnalysis #ThreatHunting #BlueTeam #IncidentResponse #CyberSecurityLearning