Shell scripting in Kali Linux: automate repeated tasks with a safe lab script

Shell scripting in Kali Linux is an invaluable skill for cybersecurity professionals. It helps automate repetitive tasks, improves penetration testing efficiency, and allows for the integration of various tools into custom workflows. By understanding basic concepts, writing simple scripts, and automating tasks like network scanning, log analysis, and system updates, you can save time and enhance your security operations.

Jan 18, 2025 - 10:30
Updated: 7 days ago
105.9k
Shell scripting in Kali Linux: automate repeated tasks with a safe lab script

Quick answer: Shell scripting in Kali Linux means putting commands in a text file and running them with Bash, so repeated tasks run the same way every time. A good script uses variables, loops, checks and clear output. Build in a scope check so it only touches hosts you are authorised to test, and run it only in your own lab.

Key takeaways

  • A Bash script is a text file of commands, made executable and run in a shell.
  • Use variables, loops and exit codes to make scripts reliable.
  • Build scope checks in so the script only touches approved lab hosts.
  • Quote variables, use set -euo pipefail, and check scripts with shellcheck.
  • Automate only what you understand when done by hand.

Why script in Kali?

Testers repeat the same steps: scan, save output, sort results. A script does them identically each time and records what was run. For the basics of Bash, read what shell scripting is in Linux first.

What are the building blocks?

#!/usr/bin/env bash
NAME="lab" # variable
for host in a b c; do # loop
 echo "$NAME $host"
done
if [ -f targets.txt ]; then echo "found"; fi # condition
  • The first line, the shebang, says which interpreter runs the script.
  • "$VAR" in double quotes avoids breaking on spaces.
  • $? holds the exit status of the last command.
  • chmod +x script.sh makes it executable.

What does a safe lab scan script look like?

This script reads a file of lab hosts you own, refuses to run if it is empty, and saves one result file per host. Run it only on your own virtual lab network.

#!/usr/bin/env bash
set -euo pipefail

TARGETS="targets.txt" # one lab IP per line
OUT="scans_$(date +%Y%m%d_%H%M)"

if [! -s "$TARGETS" ]; then
 echo "No targets listed in $TARGETS" >&2
 exit 1
fi

echo "Scanning ONLY the hosts in $TARGETS."
read -r -p "Do you have written permission for all of them? (yes/no) " ok
[ "$ok" = "yes" ] || { echo "Stopped."; exit 1; }

mkdir -p "$OUT"
while read -r host; do
 [ -z "$host" ] && continue
 echo "Scanning $host"
 nmap -sV -oN "$OUT/$host.txt" "$host"
done < "$TARGETS"

echo "Done. Results in $OUT"

How does the script work?

  • set -euo pipefail stops on errors, unset variables and pipe failures.
  • $(date...) builds a unique folder name.
  • [! -s file ] checks that the file exists and is not empty.
  • read -r -p asks for confirmation. The prompt is a reminder that scope matters.
  • while read loops over each line of the targets file.
  • nmap -sV -oN detects service versions and writes a normal-format file. The Nmap reference guide explains each option.

A target file might contain 192.168.56.101, your own Metasploitable VM.

What mistakes are common?

  • Forgetting to quote variables, which breaks on spaces.
  • Running scripts as root when not needed.
  • Hard-coding passwords or IP ranges that are not yours.
  • Not testing on one host before looping over many.
  • Ignoring exit codes.

How do you check your script?

Run bash -n script.sh to check syntax and install shellcheck to catch common errors. Test with a single lab host first.

What else can you automate?

Reconnaissance logs, report folder setup, package updates, backups of your notes and routine tool launches. Related reading: mastering Bash scripting with practical examples and command-line shells in Kali.

Legal note

Scanning systems without permission is illegal under India's IT Act. The script's prompt is not a legal safeguard. Written authorisation is.

Next steps

To learn Kali tooling with a trainer, see the KLCP Kali Linux course. For the Linux base, see the Linux course.

Frequently Asked Questions

A shell script is a text file of commands that Bash runs in order. It automates repeated tasks, so they run the same way each time, and it can use variables, loops and conditions.

Save it as script.sh, make it executable with chmod +x script.sh, and run it with./script.sh. You can also run bash script.sh. Use the shebang line to name the interpreter.

It makes the script stop on errors, on use of unset variables and on failures inside pipes. This prevents a script from carrying on with bad data and causing unexpected results.

Read targets from a list of hosts you own, refuse to run when it is empty, require explicit confirmation of authorisation, log what was scanned and test on a single lab host first.

Shellcheck is a static analysis tool that finds common mistakes such as unquoted variables. You can also run bash -n script.sh to check syntax without executing the script.

Automation does not change the law. Scanning systems without written permission is illegal under India's IT Act. Run scripts only against your own lab or in-scope hosts with documented authorisation.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.