Shell scripting in Kali Linux: automate repeated tasks with a safe lab script
Shell scripting in Kali Linux is an invaluable skill for cybersecurity professionals. It helps automate repetitive tasks, improves penetration testing efficiency, and allows for the integration of various tools into custom workflows. By understanding basic concepts, writing simple scripts, and automating tasks like network scanning, log analysis, and system updates, you can save time and enhance your security operations.
Quick answer: Shell scripting in Kali Linux means putting commands in a text file and running them with Bash, so repeated tasks run the same way every time. A good script uses variables, loops, checks and clear output. Build in a scope check so it only touches hosts you are authorised to test, and run it only in your own lab.
Key takeaways
- A Bash script is a text file of commands, made executable and run in a shell.
- Use variables, loops and exit codes to make scripts reliable.
- Build scope checks in so the script only touches approved lab hosts.
- Quote variables, use set -euo pipefail, and check scripts with shellcheck.
- Automate only what you understand when done by hand.
Why script in Kali?
Testers repeat the same steps: scan, save output, sort results. A script does them identically each time and records what was run. For the basics of Bash, read what shell scripting is in Linux first.
What are the building blocks?
#!/usr/bin/env bash
NAME="lab" # variable
for host in a b c; do # loop
echo "$NAME $host"
done
if [ -f targets.txt ]; then echo "found"; fi # condition
- The first line, the shebang, says which interpreter runs the script.
"$VAR"in double quotes avoids breaking on spaces.$?holds the exit status of the last command.chmod +x script.shmakes it executable.
What does a safe lab scan script look like?
This script reads a file of lab hosts you own, refuses to run if it is empty, and saves one result file per host. Run it only on your own virtual lab network.
#!/usr/bin/env bash
set -euo pipefail
TARGETS="targets.txt" # one lab IP per line
OUT="scans_$(date +%Y%m%d_%H%M)"
if [! -s "$TARGETS" ]; then
echo "No targets listed in $TARGETS" >&2
exit 1
fi
echo "Scanning ONLY the hosts in $TARGETS."
read -r -p "Do you have written permission for all of them? (yes/no) " ok
[ "$ok" = "yes" ] || { echo "Stopped."; exit 1; }
mkdir -p "$OUT"
while read -r host; do
[ -z "$host" ] && continue
echo "Scanning $host"
nmap -sV -oN "$OUT/$host.txt" "$host"
done < "$TARGETS"
echo "Done. Results in $OUT"
How does the script work?
set -euo pipefailstops on errors, unset variables and pipe failures.$(date...)builds a unique folder name.[! -s file ]checks that the file exists and is not empty.read -r -pasks for confirmation. The prompt is a reminder that scope matters.while readloops over each line of the targets file.nmap -sV -oNdetects service versions and writes a normal-format file. The Nmap reference guide explains each option.
A target file might contain 192.168.56.101, your own Metasploitable VM.
What mistakes are common?
- Forgetting to quote variables, which breaks on spaces.
- Running scripts as root when not needed.
- Hard-coding passwords or IP ranges that are not yours.
- Not testing on one host before looping over many.
- Ignoring exit codes.
How do you check your script?
Run bash -n script.sh to check syntax and install shellcheck to catch common errors. Test with a single lab host first.
What else can you automate?
Reconnaissance logs, report folder setup, package updates, backups of your notes and routine tool launches. Related reading: mastering Bash scripting with practical examples and command-line shells in Kali.
Legal note
Scanning systems without permission is illegal under India's IT Act. The script's prompt is not a legal safeguard. Written authorisation is.
Next steps
To learn Kali tooling with a trainer, see the KLCP Kali Linux course. For the Linux base, see the Linux course.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0