Loading date…
LinkedIn Twitter Instagram YouTube WhatsApp
Malwarebytes - Cybersecurity for Everyone

Linux parted Command Cheat Sheet: Partition Disks Safely

Terminal window showing the Linux parted command printing a GPT disk partition table for a cheat sheet guide

Linux parted Command Cheat Sheet: Safe Disk Partitioning for SysAdmins and SOC Analysts

It was 2:40 a.m. when the alert came in: a Linux file server had rebooted and never came back. The on-call engineer plugged in a rescue shell, ran one command, and saw a partition table that no longer matched the documentation. A partition was missing, a size looked wrong, and nobody could say whether it was a human mistake, a failed automation job, or something worse.

That moment is why every defender, not just storage admins, should know parted well. This Linux parted command cheat sheet covers the commands you need for disk partition management, plus the safety habits that separate a clean change from a very long night. It also covers how to verify what the disk actually looks like during incident response and digital forensics work.

Table of Contents

Why parted matters beyond storage admins

Partition tables sit below the filesystem, so a mistake there can make perfectly healthy data unreachable. For a SOC analyst or incident responder, that creates three practical situations:

  • Change validation: confirming that a maintenance window changed only what the ticket said it would.
  • Incident triage: checking whether a disk layout was altered. Public reporting on destructive wiper malware has described attackers tampering with boot records and partition structures to make systems unrecoverable, which is why knowing what a normal table looks like matters.
  • Recovery and forensics: inspecting a disk safely, without changing it, before deciding on a recovery path.

parted supports both GPT and MBR (msdos) tables and handles large disks, which makes it a common default on modern distributions.

Three golden rules before you touch a disk

Rule 1: parted writes changes immediately. Unlike fdisk, which holds changes in memory until you write them, parted commits each command to the disk as you run it. There is no "discard changes" step.

Rule 2: confirm the device name every time. Device names such as /dev/sda and /dev/sdb can change between boots, especially with USB drives or hot-plugged storage. Confirm with:

lsblk -o NAME,SIZE,TYPE,MODEL,SERIAL,MOUNTPOINT

This lists every block device with its size, model, and serial number so you can match the disk to your change ticket. Expected output is a tree of disks and their partitions.

Rule 3: back up the partition table first. A saved copy turns a disaster into a five-minute fix. For a GPT or MBR disk, sfdisk can dump the layout to a file:

sudo sfdisk -d /dev/sda > sda-partition-backup.txt

You can restore it later with sudo sfdisk /dev/sda < sda-partition-backup.txt. Treat that restore command as destructive too, because it overwrites the current table. Also keep a human-readable record:

sudo parted /dev/sda print > partition-table.txt

This saves the current layout to a text file in your working directory. Store both files off the disk you are about to modify.

Inspecting disks and partition tables

Inspection is safe and should always come first. Start the interactive interface:

sudo parted /dev/sda

This opens the parted prompt for that disk. Inside it, type help to list commands, help mkpart for command-specific help, and quit (or q on versions that support the shorthand) to exit.

To check the installed tool and its options:

parted --version
parted --help
CommandWhat it does
printShows disk size, partition table type, partition numbers, start/end, sizes, filesystem hints, and flags
print freeSame as print, but also shows unallocated free space
sudo parted /dev/nvme0n1 printShows the table of an NVMe disk without entering interactive mode
sudo parted /dev/sdb printShows the layout of a USB or external storage device

Use print free before creating partitions. It shows exactly where unallocated space begins and ends, which prevents overlap mistakes.

Working with units

parted can display boundaries in different units. Inside the interactive prompt, change the unit with a separate command, then print:

unit MiB
print

Supported display units used in this guide include B (bytes), s (sectors), MiB, and GiB. If you want a single non-interactive line, pass the commands as arguments instead of chaining with a semicolon:

sudo parted /dev/sda unit MiB print
sudo parted /dev/sda unit s print

Sector units are the most precise and are useful when comparing a table against a backup or forensic image.

Creating partition tables and partitions

Warning: the following commands change the partition table and can make existing data inaccessible. Run them only on a disk you have confirmed is the right target and that holds no data you need.

Create a partition table (label)

sudo parted /dev/sdb mklabel gpt

This creates a new GPT table and discards the existing one. GPT is the right choice for most modern systems, UEFI boot, and disks over 2 TiB.

sudo parted /dev/sdb mklabel msdos

This creates an MBR/MS-DOS table. Use it only when legacy BIOS compatibility requires it. Either way, existing partition information is replaced.

Create partitions

sudo parted /dev/sdb mkpart primary ext4 1MiB 5GiB

This creates a partition from 1 MiB to 5 GiB. Starting at 1 MiB is a widely used convention that helps with alignment. Two important details:

  • The ext4 value is only a filesystem type hint. mkpart does not create a filesystem. You still need mkfs afterward.
  • On a GPT disk, the second word (primary here) is used as the partition name, not a partition type. On MBR, it really means a primary partition.
PatternResult
mkpart primary 1MiB 5GiBPartition without a filesystem hint
mkpart primary ext4 20GiB 100%Partition from 20 GiB to the end of the disk
mkpart primary ext4 10% 50%Percentage-based boundaries
mkpart primary ext4 1MiB 10241MiBExact start and end in MiB

After creating anything, run print again to confirm the layout matches what you intended.

Resizing, deleting, flags, and names

Delete a partition

Always run print first and read the partition number carefully.

sudo parted /dev/sdb rm 1

This removes partition 1 from the table immediately. The data blocks may still exist on disk, but the filesystem is no longer addressable through that partition entry. Recovery is sometimes possible if you act quickly and have a backup of the table, but never count on it.

Resize a partition

sudo parted /dev/sdb resizepart 1 10GiB
sudo parted /dev/sdb resizepart 1 100%

The first command changes the end of partition 1 to 10 GiB. The second extends it to the end of the available space. This is the most misunderstood part of parted:

  • resizepart changes only the partition boundary, not the filesystem inside it. After growing, you must also grow the filesystem with a tool such as resize2fs for ext4.
  • Shrinking is high risk. Shrink the filesystem first, then the partition. Reversing that order can cut off live data.
  • Take a verified backup before any resize on a production disk.

Flags and names

CommandPurpose
set 1 boot on / set 1 boot offToggles the boot flag where the table type supports it (on GPT it is treated like the ESP flag)
set 1 esp onMarks partition 1 as an EFI System Partition
set 1 bios_grub onMarks a small partition for BIOS boot loaders on a GPT disk
name 1 "Linux Data"Assigns a human-readable name where the table supports names (GPT)

Changing boot-related flags on the wrong partition can stop a system from booting, so treat them with the same caution as deletion.

Checking partition alignment

Misaligned partitions can hurt performance on SSDs and advanced-format drives. Check any partition by number:

sudo parted /dev/sda align-check optimal 1
sudo parted /dev/sda align-check minimal 1

Expected output is 1 aligned when the check passes. Optimal checks against the device's preferred alignment, while minimal checks the bare minimum requirement. If a partition fails, recreating it with a 1 MiB start usually resolves the issue for new layouts.

Script mode and machine-readable output

For automation and audits, two options matter:

sudo parted -s /dev/sda print
sudo parted -m /dev/sda print
  • -s runs in script mode and suppresses interactive prompts. It is excellent for read-only listing, but dangerous when combined with write commands because confirmation questions are skipped.
  • -m produces machine-readable output that is easier to parse in scripts and inventory tools.

For compliance evidence and configuration drift checks, a scheduled -m print compared against a known-good baseline is a simple, low-risk control.

If parted reports a problem (for example, a GPT backup header not at the end of the disk), it may offer a Fix or Ignore prompt. Review the situation before choosing Fix, especially on a disk that is evidence or that you do not fully understand.

End-to-end walkthrough: new data disk

Warning: this walkthrough destroys all data on the target disk. Replace /dev/sdb with your verified device.

# 1. Identify the disk and confirm it is the right one
lsblk -o NAME,SIZE,MODEL,SERIAL,MOUNTPOINT

# 2. Back up the current table
sudo sfdisk -d /dev/sdb > sdb-backup.txt

# 3. Create a GPT label and one partition using all space
sudo parted -s /dev/sdb mklabel gpt
sudo parted -s /dev/sdb mkpart data ext4 1MiB 100%

# 4. Confirm the result
sudo parted /dev/sdb print

# 5. Ask the kernel to reread the table
sudo partprobe /dev/sdb

# 6. Create the filesystem (destroys data on that partition)
sudo mkfs.ext4 /dev/sdb1

# 7. Mount and check space
sudo mount /dev/sdb1 /mnt
df -h /mnt

Each step has a purpose: identify, back up, partition, verify, refresh the kernel view, format, and mount. Skipping the verification steps is how most mistakes slip through.

Verifying changes from Linux

After a change, confirm the kernel and filesystem layers agree with parted:

CommandWhat it confirms
sudo partprobe /dev/sdaRequests that the kernel reread the modified partition table
lsblk / lsblk -fShows the disk and partition hierarchy, and whether a filesystem is present
sudo blkid /dev/sda1Shows the filesystem type and UUID
findmnt /dev/sda1Shows mount information for the partition
df -h /mntShows used and available space after mounting

If partprobe cannot update a disk that is in use, a reboot may be needed before the kernel sees the new layout. Do not assume the change is live until lsblk shows it.

Detection and monitoring for disk-level changes

Partition changes are rare on stable servers, which makes them a high-signal event when they occur. A few practical monitoring ideas for enterprise Linux fleets:

  • Audit tool execution. With auditd, you can watch execution of the binary. The path varies by distribution, so confirm it first with which parted.
sudo auditctl -w /usr/sbin/parted -p x -k disk_partition_tool

This logs executions of parted under the key disk_partition_tool. Add a similar rule for other partitioning tools in your environment, and make the rule persistent in your audit rules files if it fits your policy.

  • Review privileged command history. On Debian-based systems, sudo activity commonly lands in /var/log/auth.log, while RHEL-based systems typically use /var/log/secure.
sudo grep -i parted /var/log/auth.log
  • Compare against a baseline. Store a machine-readable parted -m print output per server and alert on differences.
  • Check kernel messages after unexpected reboots. dmesg output at boot shows which partitions the kernel detected on each disk.

None of these is a complete control on its own, but together they give an analyst a timeline to work with. They also support the change-management and audit-logging expectations found in common frameworks such as NIST guidance and enterprise compliance programs.

Expert tips from the field

  • Read-only first on evidence. If a disk may be evidence, avoid modifying it at all. Use a hardware write blocker where possible, or mark the device read-only with sudo blockdev --setro /dev/sdb, and prefer -s with print only so no repair prompt can alter anything. Work from an image when you can.
  • Prefer percent for "rest of disk." Using 100% avoids arithmetic errors at the end boundary.
  • Name your GPT partitions. A name like data or backup makes print output far easier to audit later.
  • Use UUIDs in fstab, not device names. Get them with blkid. Device letters can change; UUIDs do not.
  • Keep the backup file with the ticket. The table dump from sfdisk -d is tiny and can save hours.
  • Test on a throwaway disk. A loop device or a spare USB stick is a safe place to practice commands before production use.
  • Never run write commands in script mode without reviewing them first. Script mode skips the safety questions.

FAQ

Does parted apply changes immediately?

Yes. Each write command updates the partition table as soon as it runs. There is no separate save step, so verify the target device before every change.

Does mkpart create a filesystem?

No. The filesystem type you provide is only a hint stored with the partition. Use a tool such as mkfs.ext4 to create the actual filesystem.

Does resizepart resize the data inside the partition?

No. It changes only the partition boundary. You must resize the filesystem separately, and shrink the filesystem before shrinking the partition.

Should I choose GPT or MBR?

GPT is the better default for modern hardware, UEFI systems, and disks larger than 2 TiB. Choose MBR (msdos) only for legacy BIOS compatibility needs.

What is the difference between parted and fdisk?

Both manage partition tables. The key behavioral difference is that parted commits changes immediately, while fdisk holds changes until you explicitly write them.

How do I see free space on a disk?

Run sudo parted /dev/sda print free. Unallocated regions appear as Free Space rows in the output.

Can I recover a deleted partition?

Sometimes, if the data has not been overwritten and you have a record of the original start and end positions. A saved table backup makes recovery far more reliable, and it is best done by working carefully from a disk image.

Conclusion

parted is simple to use and unforgiving when used carelessly. The commands themselves are short: print, mklabel, mkpart, resizepart, and align-check cover most real work. The habits around them are what keep production systems alive: confirm the device, back up the table, change one thing at a time, and verify from the kernel's point of view with partprobe and lsblk.

For defenders, the same knowledge pays off in a second way. A baseline of what each server's partition layout should look like turns an unexplained disk change into a quick, evidence-based investigation rather than a guessing game at 2:40 a.m.

Analysis based on SOC monitoring experience and public vendor documentation review.

Shubham Chaudhary

Shubham Chaudhary is a cybersecurity specialist and founder of Xpert4Cyber. He shares practical tutorials, guides and the latest news on Networking, Windows Server, Linux Server, Ethical Hacking, Digital Forensics, Malware Analysis, Threat Hunting and Monitoring, OSINT, Cloud Computing and AI, with a focus on defense and security awareness. Educational and defensive use only.

Post a Comment

Previous Post Next Post