Remote Shell Commands for Linux Endpoints

Use the available remote shell commands to investigate Linux endpoints.

Command

Description

Syntax

Example

Supported on

bashhistory

List command/bash history (/root/.bash_history)

bashhistory

bashhistory

  • Deep Security Agent (managed by Cloud One - Workload Security)

cat

Output the specified content of the selected file (max size 1MB)

cat [--offset <offset> <size>] [--hex] <file_location_and_extension>

Note:

For the <file_location_and_extension>, specify the absolute or relative path to the file, the file name, and the file extension.

Important:

The following optional parameters are only available on endpoints with the Trend Micro Endpoint Basecamp agent installed.

  • --offset: Optional parameter to specify the start location in the file (in bytes)

  • --size: Optional parameter to specify the size of the output from the start location (in bytes).

  • --hex: Optional parameter to output binary file content in hexadecimal format.

  • To output the content of the example.txt file located in the current directory (/root/Downloads):

    Downloads>cat example.txt

  • To output the content of the example.txt file located in the /root/temp directory:

    Downloads>cat /root/temp/example.txt

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

cd

Change the current working directory

cd <path>

Note:

For the <path>, specify the absolute or relative path.

cd /root

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

clear

Clear screen

clear

clear

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

env

List environment variables

env

env

  • Deep Security Agent (managed by Cloud One - Workload Security)

fileinfo

List detailed file properties

fileinfo <file_location_and_extension>

  • To list the file properties of the example.txt file located in the current directory (/root/Downloads):

    Downloads>fileinfo example.txt

  • To list the file properties of the example.txt file located in the /root/temp directory:

    Downloads>fileinfo /root/temp/example.txt

  • Deep Security Agent (managed by Cloud One - Workload Security)

group list

List local group information

group list

group list

  • Deep Security Agent (managed by Cloud One - Workload Security)

help

Display help information

help

help

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

ipconfig

Display network configuration information

ipconfig

ipconfig

  • Trend Micro Endpoint Basecamp

kill

Terminate a running process

kill <PID>

kill 1234

  • Trend Micro Endpoint Basecamp

listenports

List listening ports

listenports

listenports

  • Deep Security Agent (managed by Cloud One - Workload Security)

ls

List contents of the directory

ls [-a] [-l] [path]

  • -a: Optional parameter that includes entries starting with .

  • -l: Optional parameter that displays output in long list format

Note:

For the <path>, specify the absolute or relative path.

ls

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

netstat

List network statistics and active connections

netstat

netstat

  • Trend Micro Endpoint Basecamp

ps

List running process information

ps

ps

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

pwd

Display current directory

pwd

pwd

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

scheduletasks

List scheduled tasks

scheduletasks

scheduletasks

  • Deep Security Agent (managed by Cloud One - Workload Security)

service list

List service information

service list

service list

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)

systeminfo

List system information

systeminfo

systeminfo

  • Trend Micro Endpoint Basecamp

user info

List account properties

user info <username>

Note:

<username> supports the use of the UID (for example, "0" for the root account).

user info john_doe

  • Trend Micro Endpoint Basecamp

user list

List local user accounts

user list

user list

  • Trend Micro Endpoint Basecamp

  • Deep Security Agent (managed by Cloud One - Workload Security)