Cybersecurity Triage
Dry run / previewSimulate Security Package Upgrades
You need to identify pending security updates on a Debian or Ubuntu host before a maintenance window.
Command
apt-get -s upgrade | awk '/^Inst/ && /security/ {print}'
Before you run this
System impact: Preview only. Still verify source and destination paths before running the real command.
When not to use it: Do not treat simulation output as a completed patch; it only describes what apt would try to do.
Expected output
Inst rows for packages whose candidate version comes from a security repository.
System impact
Dry run / preview. Nothing changes. apt-get runs in simulation mode and awk prints only install lines from security pockets.
Recovery / rollback: no state is changed.
When to use it
Use before patch windows, incident response, or compliance notes when you need a read-only security update list.
When not to use it
Do not treat simulation output as a completed patch; it only describes what apt would try to do.
Simulation is not a patch
The `-s` flag previews what apt would do. It does not download, install, restart services, or satisfy compliance by itself. Use it to plan a maintenance window and then validate the real package state after patching.
apt-get -s upgradedpkg-query -W -f='${Package} ${Version}\n' openssl
next steps
Related commands
Preview Security Impact of dist-upgrade
Kernel and dependency security fixes may only appear in the broader upgrade plan.
apt-get -s dist-upgrade | awk '/^Inst/ {print}'
Review Kept-Back Packages Before Patching
Kept-back packages are where simple upgrade plans stop being simple.
apt-get -s upgrade | sed -n '/kept back:/,/^Inst/p'
Build a Recent Apt Patch Timeline
Apt history turns patch claims into timestamps and package names.
awk '/^(Start-Date|Commandline|Upgrade|End-Date)/ {print}' /var/log/apt/history.log
Find Password-Enabled Accounts
A shell account with an unlocked password hash deserves extra attention.
sudo awk -F: '$2 !~ /^(!|\*)/ {print $1}' /etc/shadow
Find SSH Key Users with sudo
The highest-priority access review starts where SSH keys and sudo overlap.
comm -12 <(find /home -path '*/.ssh/authorized_keys' -printf '%h\n' 2>/dev/null | awk -F/ '{print $(NF-1)}' | sort) <(awk -F: '$1=="sudo" {gsub(",","\n",$4); print $4}' /etc/group | sort)
next diagnostic step
Where to go from this command
- Package lock held hub Use if apt cannot proceed because a lock is held.
- APT/dpkg repair hub Use when dpkg state is interrupted or broken.
Study mapping
Use this as independent command practice: read the notes, predict the output, then compare it with the example before using a real shell.
Independent study support only. No affiliation, endorsement, exam dumps, or real exam questions.