Linux parted Command Cheat Sheet: Safe Disk Partitioning for SysAdmins and SOC Analysts
It was 2:40 a.m. when the alert came in: a Linux file server had rebooted and never came back. The on-call engineer plugged in a rescue shell, ran one command, and saw a partition table that no longer matched the documentation. A partition was missing, a size looked wrong, and nobody could say whether it was a human mistake, a failed automation job, or something worse.
That moment is why every defender, not just storage admins, should know parted well. This Linux parted command cheat sheet covers the commands you need for disk partition management, plus the safety habits that separate a clean change from a very long night. It also covers how to verify what the disk actually looks like during incident response and digital forensics work.
Table of Contents
- Why parted matters beyond storage admins
- Three golden rules before you touch a disk
- Inspecting disks and partition tables
- Working with units
- Creating partition tables and partitions
- Resizing, deleting, flags, and names
- Checking partition alignment
- Script mode and machine-readable output
- End-to-end walkthrough: new data disk
- Verifying changes from Linux
- Detection and monitoring for disk-level changes
- Expert tips from the field
- FAQ
- Conclusion
Why parted matters beyond storage admins
Partition tables sit below the filesystem, so a mistake there can make perfectly healthy data unreachable. For a SOC analyst or incident responder, that creates three practical situations:
- Change validation: confirming that a maintenance window changed only what the ticket said it would.
- Incident triage: checking whether a disk layout was altered. Public reporting on destructive wiper malware has described attackers tampering with boot records and partition structures to make systems unrecoverable, which is why knowing what a normal table looks like matters.
- Recovery and forensics: inspecting a disk safely, without changing it, before deciding on a recovery path.
parted supports both GPT and MBR (msdos) tables and handles large disks, which makes it a common default on modern distributions.
Three golden rules before you touch a disk
Rule 1: parted writes changes immediately. Unlike fdisk, which holds changes in memory until you write them, parted commits each command to the disk as you run it. There is no "discard changes" step.
Rule 2: confirm the device name every time. Device names such as /dev/sda and /dev/sdb can change between boots, especially with USB drives or hot-plugged storage. Confirm with:
lsblk -o NAME,SIZE,TYPE,MODEL,SERIAL,MOUNTPOINT
This lists every block device with its size, model, and serial number so you can match the disk to your change ticket. Expected output is a tree of disks and their partitions.
Rule 3: back up the partition table first. A saved copy turns a disaster into a five-minute fix. For a GPT or MBR disk, sfdisk can dump the layout to a file:
sudo sfdisk -d /dev/sda > sda-partition-backup.txt
You can restore it later with sudo sfdisk /dev/sda < sda-partition-backup.txt. Treat that restore command as destructive too, because it overwrites the current table. Also keep a human-readable record:
sudo parted /dev/sda print > partition-table.txt
This saves the current layout to a text file in your working directory. Store both files off the disk you are about to modify.
Inspecting disks and partition tables
Inspection is safe and should always come first. Start the interactive interface:
sudo parted /dev/sda
This opens the parted prompt for that disk. Inside it, type help to list commands, help mkpart for command-specific help, and quit (or q on versions that support the shorthand) to exit.
To check the installed tool and its options:
parted --version
parted --help
| Command | What it does |
print | Shows disk size, partition table type, partition numbers, start/end, sizes, filesystem hints, and flags |
print free | Same as print, but also shows unallocated free space |
sudo parted /dev/nvme0n1 print | Shows the table of an NVMe disk without entering interactive mode |
sudo parted /dev/sdb print | Shows the layout of a USB or external storage device |
Use print free before creating partitions. It shows exactly where unallocated space begins and ends, which prevents overlap mistakes.
Working with units
parted can display boundaries in different units. Inside the interactive prompt, change the unit with a separate command, then print:
unit MiB
print
Supported display units used in this guide include B (bytes), s (sectors), MiB, and GiB. If you want a single non-interactive line, pass the commands as arguments instead of chaining with a semicolon:
sudo parted /dev/sda unit MiB print
sudo parted /dev/sda unit s print
Sector units are the most precise and are useful when comparing a table against a backup or forensic image.
Creating partition tables and partitions
Warning: the following commands change the partition table and can make existing data inaccessible. Run them only on a disk you have confirmed is the right target and that holds no data you need.
Create a partition table (label)
sudo parted /dev/sdb mklabel gpt
This creates a new GPT table and discards the existing one. GPT is the right choice for most modern systems, UEFI boot, and disks over 2 TiB.
sudo parted /dev/sdb mklabel msdos
This creates an MBR/MS-DOS table. Use it only when legacy BIOS compatibility requires it. Either way, existing partition information is replaced.
Create partitions
sudo parted /dev/sdb mkpart primary ext4 1MiB 5GiB
This creates a partition from 1 MiB to 5 GiB. Starting at 1 MiB is a widely used convention that helps with alignment. Two important details:
- The
ext4value is only a filesystem type hint. mkpart does not create a filesystem. You still needmkfsafterward. - On a GPT disk, the second word (
primaryhere) is used as the partition name, not a partition type. On MBR, it really means a primary partition.
| Pattern | Result |
mkpart primary 1MiB 5GiB | Partition without a filesystem hint |
mkpart primary ext4 20GiB 100% | Partition from 20 GiB to the end of the disk |
mkpart primary ext4 10% 50% | Percentage-based boundaries |
mkpart primary ext4 1MiB 10241MiB | Exact start and end in MiB |
After creating anything, run print again to confirm the layout matches what you intended.
Resizing, deleting, flags, and names
Delete a partition
Always run print first and read the partition number carefully.
sudo parted /dev/sdb rm 1
This removes partition 1 from the table immediately. The data blocks may still exist on disk, but the filesystem is no longer addressable through that partition entry. Recovery is sometimes possible if you act quickly and have a backup of the table, but never count on it.
Resize a partition
sudo parted /dev/sdb resizepart 1 10GiB
sudo parted /dev/sdb resizepart 1 100%
The first command changes the end of partition 1 to 10 GiB. The second extends it to the end of the available space. This is the most misunderstood part of parted:
- resizepart changes only the partition boundary, not the filesystem inside it. After growing, you must also grow the filesystem with a tool such as
resize2fsfor ext4. - Shrinking is high risk. Shrink the filesystem first, then the partition. Reversing that order can cut off live data.
- Take a verified backup before any resize on a production disk.
Flags and names
| Command | Purpose |
set 1 boot on / set 1 boot off | Toggles the boot flag where the table type supports it (on GPT it is treated like the ESP flag) |
set 1 esp on | Marks partition 1 as an EFI System Partition |
set 1 bios_grub on | Marks a small partition for BIOS boot loaders on a GPT disk |
name 1 "Linux Data" | Assigns a human-readable name where the table supports names (GPT) |
Changing boot-related flags on the wrong partition can stop a system from booting, so treat them with the same caution as deletion.
Checking partition alignment
Misaligned partitions can hurt performance on SSDs and advanced-format drives. Check any partition by number:
sudo parted /dev/sda align-check optimal 1
sudo parted /dev/sda align-check minimal 1
Expected output is 1 aligned when the check passes. Optimal checks against the device's preferred alignment, while minimal checks the bare minimum requirement. If a partition fails, recreating it with a 1 MiB start usually resolves the issue for new layouts.
Script mode and machine-readable output
For automation and audits, two options matter:
sudo parted -s /dev/sda print
sudo parted -m /dev/sda print
-sruns in script mode and suppresses interactive prompts. It is excellent for read-only listing, but dangerous when combined with write commands because confirmation questions are skipped.-mproduces machine-readable output that is easier to parse in scripts and inventory tools.
For compliance evidence and configuration drift checks, a scheduled -m print compared against a known-good baseline is a simple, low-risk control.
If parted reports a problem (for example, a GPT backup header not at the end of the disk), it may offer a Fix or Ignore prompt. Review the situation before choosing Fix, especially on a disk that is evidence or that you do not fully understand.
End-to-end walkthrough: new data disk
Warning: this walkthrough destroys all data on the target disk. Replace /dev/sdb with your verified device.
# 1. Identify the disk and confirm it is the right one
lsblk -o NAME,SIZE,MODEL,SERIAL,MOUNTPOINT
# 2. Back up the current table
sudo sfdisk -d /dev/sdb > sdb-backup.txt
# 3. Create a GPT label and one partition using all space
sudo parted -s /dev/sdb mklabel gpt
sudo parted -s /dev/sdb mkpart data ext4 1MiB 100%
# 4. Confirm the result
sudo parted /dev/sdb print
# 5. Ask the kernel to reread the table
sudo partprobe /dev/sdb
# 6. Create the filesystem (destroys data on that partition)
sudo mkfs.ext4 /dev/sdb1
# 7. Mount and check space
sudo mount /dev/sdb1 /mnt
df -h /mnt
Each step has a purpose: identify, back up, partition, verify, refresh the kernel view, format, and mount. Skipping the verification steps is how most mistakes slip through.
Verifying changes from Linux
After a change, confirm the kernel and filesystem layers agree with parted:
| Command | What it confirms |
sudo partprobe /dev/sda | Requests that the kernel reread the modified partition table |
lsblk / lsblk -f | Shows the disk and partition hierarchy, and whether a filesystem is present |
sudo blkid /dev/sda1 | Shows the filesystem type and UUID |
findmnt /dev/sda1 | Shows mount information for the partition |
df -h /mnt | Shows used and available space after mounting |
If partprobe cannot update a disk that is in use, a reboot may be needed before the kernel sees the new layout. Do not assume the change is live until lsblk shows it.
Detection and monitoring for disk-level changes
Partition changes are rare on stable servers, which makes them a high-signal event when they occur. A few practical monitoring ideas for enterprise Linux fleets:
- Audit tool execution. With auditd, you can watch execution of the binary. The path varies by distribution, so confirm it first with
which parted.
sudo auditctl -w /usr/sbin/parted -p x -k disk_partition_tool
This logs executions of parted under the key disk_partition_tool. Add a similar rule for other partitioning tools in your environment, and make the rule persistent in your audit rules files if it fits your policy.
- Review privileged command history. On Debian-based systems, sudo activity commonly lands in
/var/log/auth.log, while RHEL-based systems typically use/var/log/secure.
sudo grep -i parted /var/log/auth.log
- Compare against a baseline. Store a machine-readable
parted -m printoutput per server and alert on differences. - Check kernel messages after unexpected reboots.
dmesgoutput at boot shows which partitions the kernel detected on each disk.
None of these is a complete control on its own, but together they give an analyst a timeline to work with. They also support the change-management and audit-logging expectations found in common frameworks such as NIST guidance and enterprise compliance programs.
Expert tips from the field
- Read-only first on evidence. If a disk may be evidence, avoid modifying it at all. Use a hardware write blocker where possible, or mark the device read-only with
sudo blockdev --setro /dev/sdb, and prefer-swithprintonly so no repair prompt can alter anything. Work from an image when you can. - Prefer percent for "rest of disk." Using
100%avoids arithmetic errors at the end boundary. - Name your GPT partitions. A name like
dataorbackupmakesprintoutput far easier to audit later. - Use UUIDs in fstab, not device names. Get them with
blkid. Device letters can change; UUIDs do not. - Keep the backup file with the ticket. The table dump from
sfdisk -dis tiny and can save hours. - Test on a throwaway disk. A loop device or a spare USB stick is a safe place to practice commands before production use.
- Never run write commands in script mode without reviewing them first. Script mode skips the safety questions.
Related Cybersecurity Topics You Should Explore
- Linux fdisk Command Cheat Sheet: Partition Disks Safely (2026)
- Linux lsblk Command: Cheat Sheet for Disks, USB & Encryption
- Linux umount Command Cheat Sheet: Safe Unmount Without Data Loss
- Linux Mount Commands Cheat Sheet: Secure Mounts (2026)
- Linux du Command Cheat Sheet: Find Disk Space Hogs Fast
- Linux df Command Cheat Sheet: Fix Full Disk & Missing Logs
- Linux Disk Commands Cheat Sheet: df, du, mount, fsck (2026)
- Linux umask Cheat Sheet: 022 vs 027 vs 077 Explained
- Linux chgrp Cheat Sheet (2026): Commands, Examples & Audit Tips
FAQ
Does parted apply changes immediately?
Yes. Each write command updates the partition table as soon as it runs. There is no separate save step, so verify the target device before every change.
Does mkpart create a filesystem?
No. The filesystem type you provide is only a hint stored with the partition. Use a tool such as mkfs.ext4 to create the actual filesystem.
Does resizepart resize the data inside the partition?
No. It changes only the partition boundary. You must resize the filesystem separately, and shrink the filesystem before shrinking the partition.
Should I choose GPT or MBR?
GPT is the better default for modern hardware, UEFI systems, and disks larger than 2 TiB. Choose MBR (msdos) only for legacy BIOS compatibility needs.
What is the difference between parted and fdisk?
Both manage partition tables. The key behavioral difference is that parted commits changes immediately, while fdisk holds changes until you explicitly write them.
How do I see free space on a disk?
Run sudo parted /dev/sda print free. Unallocated regions appear as Free Space rows in the output.
Can I recover a deleted partition?
Sometimes, if the data has not been overwritten and you have a record of the original start and end positions. A saved table backup makes recovery far more reliable, and it is best done by working carefully from a disk image.
Conclusion
parted is simple to use and unforgiving when used carelessly. The commands themselves are short: print, mklabel, mkpart, resizepart, and align-check cover most real work. The habits around them are what keep production systems alive: confirm the device, back up the table, change one thing at a time, and verify from the kernel's point of view with partprobe and lsblk.
For defenders, the same knowledge pays off in a second way. A baseline of what each server's partition layout should look like turns an unexplained disk change into a quick, evidence-based investigation rather than a guessing game at 2:40 a.m.
Analysis based on SOC monitoring experience and public vendor documentation review.
