Loading date…
LinkedIn Twitter Instagram YouTube WhatsApp
Malwarebytes - Cybersecurity for Everyone

Linux fdisk Command Cheat Sheet: Partition Disks Safely (2026)

Linux terminal showing the fdisk -l command listing disk partitions, with a cheat sheet of fdisk commands for safe partitioning

Linux fdisk Command Cheat Sheet: Safe Disk Partitioning for Admins, SOC Analysts, and Forensic Responders

Picture a late-night maintenance window. A sysadmin is repurposing a spare drive for endpoint security log storage. Two disks look almost identical in the terminal, and one of them holds last quarter's evidence archive. One mistyped device name, one confident press of w, and the partition table is gone. No alert fires and no warning appears. Just silence.

Stories like this are why every analyst, admin, and incident responder should treat fdisk with respect. It is small, fast, and ships with nearly every Linux distribution. It is also one of the easiest ways to cause a self-inflicted outage. This guide walks through the commands that matter, explains when to use each one, and builds in the safety habits that experienced practitioners rely on.

Table of Contents

What fdisk Does (and Doesn't Do)

fdisk is a partition table editor. It reads and writes the structure that tells the operating system where each partition starts and ends on a disk. It supports both MBR (DOS) and GPT layouts in current versions of util-linux.

It does not create filesystems. After partitioning, you still need a tool like mkfs to format the partition, and then you mount it. Keeping those steps separate is useful, because partitioning alone does not erase the data inside existing partitions. It only changes the map that points to them.

Inspecting Disks Without Changing Anything

Start every session with read-only commands. These are safe to run and tell you exactly what the system sees.

List all disks and partitions

sudo fdisk -l

What it does: prints the partition table of every detected disk. When to use it: at the start of any storage task, or when a new device is attached. Expected output: for each disk, the model, size, sector counts, partition table type, and one row per partition.

List one specific disk

sudo fdisk -l /dev/sda

This narrows the output to a single device, which reduces the chance of confusing two disks.

Compare two disks side by side

sudo fdisk -l /dev/sda /dev/sdb

NVMe and USB devices

sudo fdisk -l /dev/nvme0n1
sudo fdisk -l /dev/sdb

NVMe drives use names like /dev/nvme0n1, with partitions named /dev/nvme0n1p1. USB drives usually appear as /dev/sdX. Always confirm the size and model against what you expect before doing anything else.

Save the layout to a text file

sudo fdisk -l /dev/sda > partition-table.txt

This gives you a human-readable record to attach to a change ticket or incident note.

Check version and help

fdisk --version
sudo fdisk --help

Behavior differs slightly between versions, so check yours when a command in a tutorial does not match what you see.

Interactive Mode: The Commands You'll Use

To edit a disk, open fdisk against a single device:

sudo fdisk /dev/sdb

You will see a Command (m for help): prompt. Changes stay in memory only until you write them. That is the safety net, and it is why you can explore freely and quit with q.

KeyActionNotes
mShow help menuLists commands for your version
pPrint partition tableRun before and after edits
nNew partitionPrompts for number, first sector, last sector
dDelete partitionNot permanent until w
tChange partition typeUse l to list type codes
lList partition typesNumbering differs between MBR and GPT
aToggle bootable flagMainly relevant to MBR/DOS layouts
FList free spaceAvailable in newer versions
xExpert modeAdvanced; use only if you understand the operation
wWrite changes and exitThis is the point of no return
qQuit without savingDiscards all pending changes

Safe inspection habit: open the disk, press p to look around, then press q. You have learned what you needed and changed nothing.

Creating a Partition Step by Step

The following walkthrough creates a roughly 10 GiB partition on /dev/sdb. Confirm the device name first, because this procedure modifies the partition table.

Warning: only run this on a disk you have verified is empty or disposable. Writing a new partition table can make existing data difficult or impossible to recover.

sudo fdisk -l /dev/sdb
sudo fdisk /dev/sdb

Inside fdisk, the workflow looks like this:

  • Press p to review the current layout.
  • Press n to start a new partition.
  • On an MBR disk, choose p for primary when prompted. On a GPT disk, this prompt does not appear.
  • Accept the default partition number or enter the one you want.
  • Accept the default first sector unless you have a specific alignment reason not to.
  • For the last sector, enter a size such as +10G to request approximately 10 GiB.
  • Press p again to review the pending change.
  • Press w to commit, or q to walk away.

Accepting the default first sector generally keeps the partition aligned, which matters for performance on modern drives. You can inspect the start sectors afterward with sudo fdisk -l /dev/sdb to confirm.

Deleting Partitions and Changing Types

Delete a partition

Press d, select the partition number, and review with p. The deletion is staged in memory only, so if you picked the wrong one, press q and start over.

Warning: once you press w after deleting, the partition entry is gone from the table. The data may still exist on disk for a while, but recovery is never guaranteed.

Change a partition type

Press t, choose the partition, then press l to see valid type codes. On MBR disks, a standard Linux partition is type 83. On GPT disks, select the "Linux filesystem" entry from the list. Its number can differ between fdisk versions, so read the list rather than copying a number from memory.

The type is a label that tools and bootloaders use to interpret the partition. It does not format anything.

The bootable flag

The a command toggles the bootable flag where supported. It matters mostly for legacy MBR boot setups. Modern UEFI systems rely on an EFI System Partition instead.

Verifying Changes After Writing

After pressing w, confirm that both the disk and the kernel agree on the new layout.

sudo fdisk -l /dev/sdb

Rechecks the partition table as written to disk.

sudo partprobe /dev/sdb

Asks the kernel to reread the partition table. This is needed when fdisk reports that the kernel is still using the old table, which can happen if a partition on the disk is mounted or in use.

lsblk

Shows whether the new partition is visible to the operating system as a block device.

lsblk -f

Adds filesystem type, label, UUID, and mount point. A new partition will show no filesystem until you format it.

sudo blkid /dev/sdb1

Displays the filesystem type and UUID once a filesystem exists. Use the UUID in /etc/fstab rather than the device name, because names like /dev/sdb can change between boots.

Before mounting any newly attached device, run sudo fdisk -l /dev/sdb one more time. It takes seconds and prevents mistakes.

Why Partition Layout Matters for Digital Forensics

For SOC analysts and responders, fdisk -l is more than an admin tool. It is a fast triage step when you receive a disk or USB device during an investigation. A quick listing can reveal:

  • Unexpected partitions: a small partition with an unfamiliar type on a laptop that should have a standard layout deserves a closer look.
  • Unallocated gaps: unexplained free space between partitions can be benign, but it is worth noting in your documentation.
  • Layout mismatches: a server built from a standard image that no longer matches its baseline may have been modified.

None of these are proof of compromise on their own. Treat them as leads to investigate with proper forensic tooling, not as conclusions.

Important: in a real forensic case, do not open the original evidence disk with an editing tool. Work from a verified image or use a hardware write blocker, and keep to read-only commands such as fdisk -l. Interactive editing on evidence can alter it and undermine your chain of custody.

Data Backup and Recovery Before You Touch a Disk

Experienced admins treat partition edits as change-controlled operations. A sensible routine is:

  • Confirm the target disk by size, model, and existing partitions.
  • Back up any data you care about to a separate device and verify the backup can be read.
  • Save the current layout so you have a record of the original state.
sudo fdisk -l /dev/sdb > sdb-layout-before.txt

This is a text record for reference. For a restorable copy of the partition table itself, the related sfdisk tool can dump the layout in a re-importable format, but restoring one overwrites the table, so treat that step as destructive as well. A table backup protects the map, not the data inside, so it never replaces a real data backup and recovery plan.

Expert Tips

  • Double-check the device name every time. Compare size and model in lsblk and fdisk -l before opening a disk for editing.
  • Use p before and after. Reviewing the pending table before w catches most mistakes.
  • Remember that q is your friend. If anything feels off, quit and reopen. Nothing is written.
  • Avoid expert mode casually. The x menu offers advanced operations that are easy to misuse.
  • Never repartition a mounted disk. Unmount first, or expect kernel reread errors.
  • Prefer UUIDs in fstab. Device letters can shift when disks are added or removed.
  • Document changes. A saved layout and a short note in your ticket make audits and troubleshooting far easier.

FAQ

Does fdisk erase my data when I create a partition?

Creating a partition changes the partition table, not the contents of existing data areas. However, if the new layout overlaps or replaces old partitions, the old filesystems become inaccessible and may be overwritten once you format. Back up first.

What happens if I quit without pressing w?

Nothing is saved. Pressing q discards all pending changes and leaves the disk exactly as it was.

Why does fdisk say the kernel is still using the old partition table?

This usually means a partition on that disk is in use. Unmount it, then run sudo partprobe /dev/sdX, or reboot if needed.

Should I use fdisk or another partitioning tool?

fdisk handles both MBR and GPT in current versions and is ideal for quick, scriptable-by-hand work. Tools like parted or gdisk are alternatives. Pick whichever you can use confidently, and use the same one consistently within a team.

Can I recover a deleted partition?

Sometimes. If you have not written new data or reformatted, recovery tools may be able to restore the entry, but success is not guaranteed. A saved copy of the old layout makes recovery much easier.

How do I find the right device name for a USB drive?

Run lsblk before and after plugging it in, and compare. Confirm the size with sudo fdisk -l. Never rely on the device letter alone.

Is fdisk safe to run for inspection only?

Yes. fdisk -l only reads the partition table. Opening interactive mode and pressing p then q is also safe because nothing is written without w.

Conclusion

fdisk rewards habits more than memorization. Inspect first, confirm the exact device, stage your changes, review them with p, and only then commit with w. For SOC and forensic work, the same read-only commands double as a quick triage tool. The commands themselves are simple. The discipline around them is what separates a routine task from a long night of recovery work.

Analysis based on hands-on Linux administration, SOC monitoring practice, and review of public util-linux documentation.

Shubham Chaudhary

Shubham Chaudhary is a cybersecurity specialist and founder of Xpert4Cyber. He shares practical tutorials, guides and the latest news on Networking, Windows Server, Linux Server, Ethical Hacking, Digital Forensics, Malware Analysis, Threat Hunting and Monitoring, OSINT, Cloud Computing and AI, with a focus on defense and security awareness. Educational and defensive use only.

Post a Comment

Previous Post Next Post