What Is the File System Hierarchy in Kali Linux?

The file system hierarchy in Kali Linux organizes files and directories under the root directory (/). Key directories like /bin, /etc, /home, and /var serve specific purposes, from storing system binaries to user data and logs. Understanding this structure helps users navigate, secure, and maintain their systems effectively.

Jan 17, 2025 - 15:06
Updated: 2 days ago
104.6k
What Is the File System Hierarchy in Kali Linux?

Quick answer: Kali Linux follows the Filesystem Hierarchy Standard, so everything hangs off one root directory, /. Configuration lives in /etc, user files in /home, logs in /var/log, programs in /usr, devices in /dev, and boot files in /boot. Kali's pentest tools and wordlists sit mostly under /usr/share.

Key takeaways

  • Linux has no drive letters. Every disk, USB stick and virtual file is mounted somewhere under /.
  • The layout is the same as Debian, because Kali is built on Debian. If you know one, you know the other.
  • Kali-specific material (wordlists, Nmap scripts, Metasploit) lives under /usr/share, and your own work belongs in your home directory.
  • On current Kali, /bin, /sbin and /lib are symbolic links into /usr. Run ls -l / to see it.

What is the Filesystem Hierarchy Standard?

The Filesystem Hierarchy Standard (FHS) is an agreed layout for Linux directories, so that software and administrators know where to look. It is published by the Linux Foundation at refspecs.linuxfoundation.org. Kali follows it through its Debian base, with a few extra locations for security tools.

The top of the tree is the root directory, written /. Do not confuse it with /root, which is the home directory of the root user.

The directories you will actually use

DirectoryWhat it holdsExample on Kali
/etcSystem and service configuration, plain text/etc/passwd, /etc/ssh/sshd_config, /etc/apt/sources.list
/homeOne folder per normal user/home/kali
/rootHome of the root userRoot's shell history and config
/varData that changes: logs, caches, spools/var/log/auth.log, /var/log/apache2
/usrInstalled programs, libraries, shared data/usr/bin/nmap, /usr/share/wordlists
/optSelf-contained third-party softwareTools installed by hand
/tmpTemporary files, may be cleared on rebootScratch output from tools
/devDevice files for hardware/dev/sda, /dev/null
/proc, /sysVirtual views of processes and kernel/proc/cpuinfo, /proc/meminfo
/bootKernel, initramfs, bootloader filesvmlinuz-*, grub/
/mnt, /mediaMount points: manual and automaticA USB stick appears under /media
/runRuntime state since boot, such as PID files/run/user/1000
/srvData served by this machineWeb or FTP content, if you choose to use it

Binaries and libraries: /bin, /sbin, /lib and the /usr merge

The original FHS split commands between /bin and /sbin (needed early in boot) and /usr/bin and /usr/sbin (everything else). Modern Debian-based systems, Kali included, have merged them. /bin, /sbin and /lib are now symbolic links to their /usr counterparts. You can confirm it yourself:

ls -l / | head -20
# lrwxrwxrwx... bin -> usr/bin

In practice, nothing changes for you. Commands still work from either path. It matters when you read an older tutorial that says /sbin holds admin tools, because that is now only a convention.

Where Kali keeps its security tools and wordlists

Kali's tools are ordinary packages, so their binaries go to /usr/bin and their support files to /usr/share. A few places are worth memorising:

  • /usr/share/wordlists holds wordlists such as rockyou.txt.gz, which you must decompress before use.
  • /usr/share/nmap/scripts holds the Nmap Scripting Engine scripts.
  • /usr/share/metasploit-framework holds Metasploit modules.
  • /usr/share/seclists appears if you install the seclists package.
  • Your own notes, captures and scripts should live under /home/<user>, not under system directories.

Package contents under /usr can be overwritten by updates. Keep anything you want to keep in your home directory.

Commands to explore the tree

ls -l / # top level, shows symlinks
tree -L 1 / # one-level overview (sudo apt install tree)
df -h # mounted filesystems and free space
du -sh /var/log # how big are the logs
findmnt # what is mounted where
file /bin # confirm it is a symlink
which nmap # where a command lives
dpkg -L nmap | head # files a package installed

Permissions and safety

  • Recent Kali releases log you in as a normal user by default. Use sudo only when needed.
  • Be careful with recursive commands as root, especially rm -rf and chmod -R near /, /etc or /usr.
  • /etc is where mistakes break services. Back up a file before editing, for example sudo cp sshd_config sshd_config.bak.
  • /var/log is where you look first when something fails, and where a defender looks for traces of your testing. Authorised testing leaves logs. That is expected.

Common mistakes

  • Confusing / with /root.
  • Installing tools by hand into /usr/bin, which the package manager may later overwrite. Use /opt or your home directory.
  • Storing project files in /tmp and losing them after a reboot.
  • Editing files in /proc or /sys without knowing the effect. They change live kernel settings.

Next steps

The same layout applies to RHEL and Rocky Linux, with small differences in package paths, so practising here carries over to Red Hat exams. For a structured path, see the Linux course. For the general view, read what the Linux file system hierarchy is and why it matters.

Related reading

Frequently Asked Questions

The root directory is /, the top of the whole tree. Every file and mounted disk sits below it. It is different from /root, which is the home directory of the root user.

System and service configuration files are in /etc, for example /etc/ssh/sshd_config and /etc/apt/sources.list. Per-user settings are usually hidden files or folders in the user's home directory, such as ~/.config.

Tool binaries are normally in /usr/bin, and their supporting data in /usr/share. Wordlists are in /usr/share/wordlists, Nmap scripts in /usr/share/nmap/scripts, and Metasploit modules in /usr/share/metasploit-framework.

Logs are in /var/log. Authentication events usually go to /var/log/auth.log where rsyslog is installed, and the systemd journal can be read with journalctl. Service logs, such as Apache's, have their own subfolders.

Yes, in structure. Kali is Debian-based and follows the same FHS layout. The differences are the extra pentest tools and their data under /usr/share, plus Kali-specific defaults.

Debian-based systems merged them into /usr, so /bin points to /usr/bin and /sbin to /usr/sbin. It simplifies packaging and updates, and commands still work from either path.

What's Your Reaction?

Like Like 1
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.