October 2, 2026
The Linux Disk Commands I Run First When a Server Fills Up
It started with a pager alert at 2:07 AM: โNo space left on device.โ

By Xpert4Cyber
1 min read
The on-call engineer blamed a runaway debug log. Ten minutes later, the real cause turned up: a 40 GB archive hidden under /var/tmp, created by an account that should not have been active. The disk was not full of logs. It was full of someone else's staged data.
That is the part of Linux disk management most tutorials skip. Commands like df, du, lsblk and lsof are not just sysadmin housekeeping. For SOC analysts and incident responders, they show what is on a system, what is attached to it, and how it is mounted.
In the full guide, I walk through:
- The triage order that finds a full filesystem, an exhausted inode table, or a deleted-but-open file fast
- How lsblk and blkid help you confirm the right device before you touch anything
- Mount options (noexec, nosuid, nodev) that support Linux server hardening
- fdisk, parted, mkfs, fsck and tune2fs, with clear warnings before destructive steps
- Audit rules that flag unexpected mounts and USB storage
If you work in a SOC, manage Linux servers, or are building ethical hacking skills, this is a practical reference to keep open during your next shift.
Read the full cheat sheet with copy-ready commands: https://www.xpert4cyber.com/2026/10/linux-disk-commands-cheat-sheet.html