Back to commands

Cybersecurity Triage

Dry run / preview

Review Kept-Back Packages Before Patching

A normal apt upgrade simulation reports packages kept back, and you need to capture them before choosing a broader upgrade path.

Command

apt-get -s upgrade | sed -n '/kept back:/,/^Inst/p'

Before you run this

System impact: Preview only. Still verify source and destination paths before running the real command.

When not to use it: Do not assume kept-back means safe to ignore; security fixes can be hidden behind dependency changes.

Expected output

The kept-back package section from apt simulation output.

System impact

Dry run / preview. Nothing changes. The command prints the kept-back section from simulated apt output.

Recovery / rollback: no state is changed.

When to use it

Use when kernel, agent, or dependency updates may need dist-upgrade, full-upgrade, or manual review.

When not to use it

Do not assume kept-back means safe to ignore; security fixes can be hidden behind dependency changes.

next steps

Related commands

Cybersecurity Triage Dry run

Simulate Security Package Upgrades

Security patch triage starts by seeing what apt would change, without changing it.

apt-get -s upgrade | awk '/^Inst/ && /security/ {print}'
Cybersecurity Triage Dry run

Preview Security Impact of dist-upgrade

Kernel and dependency security fixes may only appear in the broader upgrade plan.

apt-get -s dist-upgrade | awk '/^Inst/ {print}'
Cybersecurity Triage Read-only

Find Held Packages Blocking Patches

A held package can quietly keep a security update out of production.

apt-mark showhold | sed 's/^/held: /'
Cybersecurity Triage Dry run

Dry-Run Unattended Security Upgrades

Unattended upgrades can explain what they would patch before they patch it.

unattended-upgrade --dry-run --debug 2>&1 | sed -n '/Packages that will be upgraded:/,/^$/p'
Cybersecurity Triage Sensitive output

Summarize sudo Commands by User

Privilege history is easier to review when users and commands are separated.

sed -n 's/.*sudo: *\([^: ]*\).*COMMAND=\(.*\)$/\1 -> \2/p' /var/log/auth.log 2>/dev/null | sort
Study mapping

Use this as independent command practice: read the notes, predict the output, then compare it with the example before using a real shell.

  • LPIC-1 style command-line practice
  • LFCS style performance-task practice
  • Linux+ style troubleshooting review

Independent study support only. No affiliation, endorsement, exam dumps, or real exam questions.