What Is apt in Kali Linux? apt, dpkg and sudo Explained, With Every Command You Need

Logeshwaran
—

apt stands for Advanced Package Tool. It is the command Kali Linux, Debian and Ubuntu use to install, update and remove software from online repositories, and it handles every dependency for you. sudo runs a command with administrator (root) rights, which installing software needs. So sudo apt install nmap means "as administrator, install nmap and everything it needs". dpkg, the Debian package manager, is the lower-level tool underneath apt, and it installs individual .deb files. On Kali, the everyday commands are sudo apt update, which refreshes the list of available packages, and sudo apt full-upgrade, which installs all updates. Use sudo apt install name to add a tool, sudo apt remove name to remove one, and apt search word to find one. apt is the friendly, interactive command; apt-get is the older, script-stable one, and both use the same system.

Ethan's son, now deep into a cybersecurity course, had a Kali virtual machine and a page of commands from his instructor. Every one started with sudo apt, and he wanted to know what he was actually typing before running it. Ethan asked Jake, who had used Debian for years. Jake explained it with a supermarket. The repositories are the warehouse, apt update fetches the latest catalog, apt install orders an item along with everything it needs, and sudo is the manager's key that lets you put things on the shelves. Then he showed the boy the three commands that keep Kali healthy and the two mistakes that break it: adding repositories from other distributions, and running partial upgrades. This page explains apt, dpkg and sudo in plain English, every common command, how Kali's repositories work, the difference between apt and apt-get, and how to fix the errors beginners hit most.

⚡ Quick Answer

• apt → Advanced Package Tool: installs and updates software. Explained.

• Keep Kali updated → sudo apt update, then sudo apt full-upgrade. Update.

• Every command → install, remove, search, show, list. Cheat sheet.

• apt vs apt-get → same system; apt for people, apt-get for scripts. Compare.

Never add Ubuntu or Debian repositories to Kali. That is the fastest way to break it. Mistakes.

🧭 NEW HERE? READ THESE FIRST

New here? These five pages pair with this one:

📌 Read one now, or bookmark this page and come back to it.

What apt is

apt, short for Advanced Package Tool, is the package manager used by Debian and the distributions built on it, including Kali Linux, Ubuntu and Linux Mint. A package is a bundle containing a program, its files, and information about what else it needs to run. A package manager installs packages, keeps track of what is installed, updates everything when new versions arrive, and removes packages cleanly.

The key thing apt does is handle dependencies. Most programs rely on shared libraries and other programs. When you ask apt to install a tool, it works out everything that tool needs, downloads all of it from the repositories, and installs it in the right order. Without apt, you would have to find and install each piece by hand, which is how software installation used to work and why package managers were invented.

apt gets packages from repositories, online collections of packages maintained by the distribution. Kali's repositories contain thousands of packages, including the security tools that make Kali what it is, all built and signed by the Kali team. Because everything comes from a trusted, signed source, apt is the safe way to install software on Kali, much safer than downloading programs from random websites.

If you come from Windows, apt is like the Microsoft Store and Windows Update combined, but for everything on the system, from the kernel to the smallest tool, all updated together with one command.

apt, dpkg, sudo and friends: what the names mean

NameStands forWhat it does
aptAdvanced Package ToolInstalls, updates and removes packages, handling dependencies
apt-getAdvanced Package Tool, getThe older apt command, with stable output for scripts
apt-cacheAdvanced Package Tool, cacheOlder command for searching and showing package information
dpkgDebian packageLow-level tool that installs, removes and lists .deb packages
.debDebian package fileThe file format for packages
sudosuperuser do (often read as substitute user do)Runs one command with root rights
rootThe superuser accountThe all-powerful administrator account on Linux
repositoryA package sourceAn online collection of packages apt downloads from

dpkg is the foundation. It knows how to unpack a .deb file and install it, and keeps the database of installed packages, but it does not download anything or resolve dependencies; if a package needs something that is missing, dpkg simply fails. apt sits on top: it downloads packages and their dependencies from repositories, then asks dpkg to install them in the right order. That division is why some errors mention dpkg even though you ran apt.

sudo lets an ordinary user run a single command as root after entering their own password. Installing and removing software changes system files, so apt commands that modify the system need sudo, while commands that only read information, such as apt search and apt show, do not. Kali has used a standard, non-root user with sudo by default since 2020, which is safer than working as root all the time.

How apt works behind the scenes

When you run sudo apt update, apt contacts each repository in your sources and downloads its index files, which list every package available, its version, its dependencies and a checksum. apt verifies the index signatures with the repository's key, so it knows the lists are genuine, and stores them in /var/lib/apt/lists. That is why update is needed before installing: without fresh indexes, apt does not know about new versions.

When you run sudo apt install, apt reads those indexes, works out the full set of packages needed, including dependencies of dependencies, and checks for conflicts with what is installed. It shows you the plan and asks for confirmation. Then it downloads the .deb files into /var/cache/apt/archives, checks each file's checksum against the signed index, and hands them to dpkg, which unpacks and configures them in the right order.

This chain, signed index, checksummed packages, dependency resolution, is what makes apt both safe and convenient. Every package can be traced back to a repository you trust, and every installation leaves the system consistent. Understanding it also explains most errors: signature problems are about the index, locate problems are about what the index contains, and dpkg problems are about the final installation step.

The supermarket analogy, in full

Jake's supermarket picture is worth spelling out, because it makes every command memorable. The repositories are the warehouse, full of goods, each checked and sealed by the store. The package lists are the catalog of what the warehouse holds today; apt update fetches a fresh catalog, which is why you do it first, or you might order something that has been replaced. apt install is placing an order: the store gathers the item and everything it needs to work, such as batteries for a toy, and delivers it all together.

apt full-upgrade is swapping everything on your shelves for the newest versions, including discontinuing items that no longer fit. apt remove returns an item, purge returns it with its instruction manual, and autoremove clears out the batteries you no longer need. dpkg is the worker who actually stacks the shelves, and sudo is the manager's key, needed whenever the shelves change but not for browsing the catalog with apt search or apt show.

And adding another distribution's repository is like stocking your shelves from a different chain whose parts do not fit yours, which is why it causes so much trouble.

Keeping Kali updated: update and full-upgrade

Kali is a rolling release: instead of big version upgrades, packages are updated continuously, and the quarterly version numbers, such as 2026.3, are snapshots for new installs. Keeping an installed Kali current is a matter of running two commands regularly.

  1. Open a terminal.
  2. Run sudo apt update and enter your password. apt downloads the latest package lists from the repositories, so it knows what new versions exist. It does not install anything yet.
  3. Run sudo apt full-upgrade. apt shows what it will upgrade, install or remove, and asks for confirmation. Press Y and Enter.
  4. Wait for downloads and installation to finish. Read any messages that ask you questions, such as whether to keep a configuration file.
  5. Restart if the kernel or major system components were updated.

The two steps are often combined as sudo apt update && sudo apt full-upgrade -y, where -y answers yes automatically. Kali's documentation recommends full-upgrade rather than plain upgrade, because a rolling distribution regularly needs packages to be added or removed during updates, which plain upgrade refuses to do.

If you have not updated for months, the first update can be large and may take a while. Make sure you have enough disk space and a stable connection, and on a virtual machine, take a snapshot first so you can roll back if anything goes wrong. Our guide to upgrading an old Kali install covers very old systems.

apt and Kali's quarterly releases

Kali publishes numbered releases four times a year, such as 2026.1, 2026.2 and 2026.3, with new installer images, desktop changes and highlighted tools. On an installed system, there is nothing special to do when a release comes out: the packages that make up the release arrive through the normal rolling updates, so a system updated with full-upgrade is already on the latest release. Our guide to checking your Kali version shows how to confirm it.

Occasionally a release changes something that needs a manual step, such as a new signing key, a default shell change or a desktop update; the release notes on Kali's site and blog mention these, and they are worth a quick read after each release.

Mirrors and download speed

The address http.kali.org in the sources line is a redirector: when apt asks it for a file, it sends apt to a nearby mirror chosen for your location. That usually gives good speed without any configuration. If downloads are slow or a mirror is having problems, simply retrying often gets a different mirror.

You can pin a specific mirror by replacing http.kali.org with a mirror's address from Kali's official mirror list, which some universities and companies host. Mirrors carry the same signed packages, and apt verifies signatures regardless of which mirror delivered them, so using an official mirror is safe. Avoid unofficial mirrors and proxies offered on forums.

Should Kali update automatically?

Kali does not install updates automatically by default, and for most users that is the right choice. Security tools change quickly, and an update in the middle of a lab exercise or assessment could change a tool's behavior unexpectedly. Updating deliberately, before starting work, gives you control over when things change.

For machines that are always on and used for general purposes, the Debian unattended-upgrades package can install updates automatically, but on Kali's rolling repository that means accepting frequent changes without review. Most people are better served by a habit: update and full-upgrade at the start of each week, or before each project, after taking a snapshot on virtual machines.

upgrade vs full-upgrade vs dist-upgrade

These three are a common source of confusion. apt upgrade installs newer versions of installed packages, and may install new dependencies, but never removes packages; if an update requires removing something, it holds that update back. apt full-upgrade does everything upgrade does, and also removes packages when that is needed to complete the upgrade. apt-get dist-upgrade is the older name for the same behavior as full-upgrade.

On Kali, full-upgrade is the right choice, because the rolling distribution changes regularly, and a plain upgrade can leave the system with held-back packages, partly updated and inconsistent. Before confirming a full-upgrade, read the list of packages to be removed; if something important to you is listed, find out why before continuing.

On a stable distribution such as Debian stable, plain upgrade is usually enough between releases. That difference is why advice copied from Debian or Ubuntu guides does not always fit Kali.

Reading apt's output

Before apt changes anything, it prints a summary, and learning to read it prevents most surprises. The following NEW packages will be installed lists packages being added, usually dependencies. The following packages will be upgraded lists updates. The following packages will be REMOVED is the line to read most carefully, since it lists what will disappear. The following packages have been kept back means some updates could not be applied with the current command, typically because they need packages added or removed, which full-upgrade allows.

The final line, such as 25 upgraded, 3 newly installed, 1 to remove and 0 not upgraded, summarizes the plan, followed by the download size and the disk space that will be used or freed. Then apt asks Do you want to continue? [Y/n]; the capital Y means pressing Enter accepts. If anything looks wrong, press n and investigate.

After update, apt also prints how many packages can be upgraded and suggests running apt list --upgradable to see them, which is a quick way to preview what full-upgrade will do.

Configuration file questions during upgrades

During upgrades, apt sometimes stops and asks what to do about a configuration file, with a message that the package maintainer has a newer version of a file you, or a tool, modified. The choices are usually to keep your currently installed version, to install the package maintainer's version, or to see the differences.

If you changed the file yourself and know why, keep your version. If you never touched it, installing the maintainer's version is usually right, since it contains the updates the new version expects. When unsure, choosing to see the differences shows exactly what changed, and keeping your version is the safer default for files you customized, since the new version is saved alongside it, typically with a .dpkg-dist extension, for you to compare later.

Some questions appear in a blue text-mode dialog, for example about restarting services during the upgrade. Use the arrow keys, Space and Enter to answer; the defaults are sensible for most desktop and virtual machine installs.

The apt commands you will actually use

CommandWhat it doesNeeds sudo
apt updateRefresh package lists from the repositoriesYes
apt full-upgradeInstall all available updates, adding or removing packages as neededYes
apt install nmapInstall a package and its dependenciesYes
apt install ./tool.debInstall a local .deb file, resolving dependenciesYes
apt remove nmapRemove a package, keeping its configuration filesYes
apt purge nmapRemove a package and its system configuration filesYes
apt autoremoveRemove dependencies no longer needed by anythingYes
apt search scannerSearch package names and descriptionsNo
apt show nmapShow a package's details, version and dependenciesNo
apt list --installedList installed packagesNo
apt list --upgradableList packages with updates availableNo
apt cleanDelete downloaded package files to free spaceYes

You can install several packages at once, such as sudo apt install nmap wireshark gobuster. Package names are case-sensitive and usually lowercase. If you are not sure of a name, apt search finds it, and apt show tells you what a package contains before you install it.

Removing a package with remove keeps its configuration files in /etc, so reinstalling restores your settings; purge removes them too. Neither touches files in your home folder. After removing packages, autoremove cleans up dependencies that were only installed for them; it is generally safe, but read the list before confirming, as with any removal.

Install a tool safely, step by step

Here is the routine Jake taught Ethan's son for adding any tool from his course notes, which avoids most beginner problems.

  1. Refresh the lists: sudo apt update.
  2. Find the exact package name: apt search toolname, or check the name in the course notes.
  3. Read about it before installing: apt show packagename, checking the description, version and size.
  4. Install it: sudo apt install packagename, reading the list of extra packages apt plans to install.
  5. Confirm it works: run the tool with its help option, often packagename --help or -h.
  6. If the tool is not in Kali's repositories, look for its official installation instructions rather than adding other distributions' repositories.

Two minutes of reading at steps 3 and 4 prevents surprises such as installing a huge package by mistake or a similarly named but different tool. It also builds the habit of knowing what is on your system, which matters on a security distribution.

Find which package provides a command

Course notes sometimes say "run xyz" without saying which package provides it. Kali helps: if you type a command that is not installed, Kali's command-not-found handler often suggests the package to install, such as "Command 'xyz' not found, but can be installed with: sudo apt install xyz-tools".

For a more thorough search, install apt-file with sudo apt install apt-file, run sudo apt-file update, and then apt-file search bin/xyz lists packages containing a file with that name. For a command that is installed, dpkg -S $(which xyz) shows which package it came from.

These tools also help when a guide names a package from another distribution: search for the program's file name, and you will usually find the equivalent Kali package without adding foreign repositories.

dpkg commands worth knowing

You will rarely need dpkg directly, but a few commands are useful. dpkg -l lists installed packages with their versions; pipe it to grep to find one, such as dpkg -l | grep nmap. dpkg -L nmap lists the files a package installed, which answers "where did it put the program?". dpkg -S /usr/bin/nmap tells you which package a file belongs to.

sudo dpkg -i tool.deb installs a downloaded .deb file directly, but it does not fetch dependencies; if any are missing, the installation stops with errors. In that case, sudo apt -f install fixes it by installing the missing dependencies. Simpler still, sudo apt install ./tool.deb, with the ./ in front, installs a local file and resolves dependencies in one step.

The most important dpkg command is the repair one: sudo dpkg --configure -a, which finishes configuring packages left half-installed after an interrupted update. If apt ever tells you dpkg was interrupted, that is the command to run; our guide to "dpkg was interrupted" walks through it.

Other ways to install software alongside apt

Not every tool is in Kali's repositories, and many security tools are distributed in other ways. Each has its place, as long as you know where things come from. pipx installs Python command-line tools into their own isolated environments, which avoids conflicts with Kali's system Python; install it with sudo apt install pipx, then pipx install toolname. Python virtual environments, created with python3 -m venv, are the right place for Python libraries for your own projects.

Go and Rust tools are often installed with go install or cargo install, which place binaries in your home folder without touching system packages. Docker or Podman containers run tools in isolation and are popular for tools with complex dependencies. Flatpak and AppImage packages work for desktop apps. And some vendors offer their own .deb packages or repositories, which apt handles safely when added with a signed key.

The guiding rule is simple: use apt for anything Kali provides, isolated tools for anything else, and never use sudo pip or foreign repositories to force things into the system. That keeps apt's view of the system accurate, which is what keeps updates working.

apt vs apt-get: which should you use?

apt and apt-get use the same package system, the same repositories and the same database; installing with one and removing with the other is fine. The difference is in how they present themselves. apt, introduced later, is designed for people typing commands: it shows a progress bar, colored output and friendlier messages, and combines the most common functions of apt-get and apt-cache into one command. apt-get is the older command whose output and behavior are kept stable between versions, which matters for scripts that parse its output.

Use apt at the keyboard and apt-get in scripts and Dockerfiles. apt even prints a warning, that it does not have a stable command-line interface, when its output is piped to another command, as a reminder of that distinction. The older apt-cache search and apt-cache show map to apt search and apt show.

Guides written years ago often use apt-get everywhere, which still works perfectly. There is no need to rewrite them; just know that apt-get install and apt install do the same job.

Kali's repositories and the sources list

apt reads its list of repositories from configuration files under /etc/apt/. On a standard Kali install, the main file is /etc/apt/sources.list, containing a single line for the main rolling repository:

deb http://http.kali.org/kali kali-rolling main contrib non-free non-free-firmware

This means: download binary packages (deb) from Kali's mirror service, for the kali-rolling branch, from the main, contrib, non-free and non-free-firmware sections. Kali's mirror service redirects you to a fast mirror automatically. Kali also has a kali-last-snapshot branch, which follows the quarterly releases instead of rolling continuously, and a kali-experimental branch for testing; most people should stay on kali-rolling.

Repositories are signed with Kali's archive key, which apt checks on every update, so tampered packages are rejected. When Kali changes its signing key, as it did in 2025, systems that do not have the new key installed show signature errors until it is added; our guides to signature and NO_PUBKEY errors and the missing key error show the fix.

Third-party software, such as some browsers and editors, adds its own repository files in /etc/apt/sources.list.d/ with their own signing keys. The modern method stores those keys in /etc/apt/keyrings or /usr/share/keyrings and references them with a signed-by option, rather than the deprecated apt-key command; our guide to "apt-key: command not found" explains the change.

kali-rolling or kali-last-snapshot?

Most Kali users should stay on kali-rolling, the default, which receives updates continuously, including new tool versions within days. kali-last-snapshot follows the quarterly releases instead, so the system changes only four times a year, when a new snapshot is published. It suits lab machines, classrooms and demonstrations where everyone needs the same versions and surprises are unwelcome.

Switching is a matter of changing kali-rolling to kali-last-snapshot in the sources line and running update and full-upgrade; switching back is the reverse. Do not mix both lines in the sources at once. For a student following a course, kali-rolling is usually best, since course materials tend to assume current tools, but if an instructor requires a specific snapshot, follow their setup.

Kali metapackages: installing tool collections

Kali groups its tools into metapackages, packages that contain no programs of their own but depend on a collection of tools, so installing one installs the whole set. The main ones are kali-linux-default, the standard selection installed by default; kali-linux-large, a broader set; and kali-linux-everything, every tool Kali packages, which is very large. There are also focused metapackages such as kali-tools-wireless, kali-tools-web and kali-tools-forensics.

Install them like any package, for example sudo apt install kali-tools-web. Check the size apt reports before confirming: kali-linux-everything needs tens of gigabytes. For a course or a specific task, a focused metapackage or individual tools are usually a better fit than installing everything.

The mistakes that break Kali

Adding repositories from other distributions. Adding Ubuntu, Debian stable or other distributions' repositories to Kali, often to get a single program, mixes packages built for different systems and can break dependencies across the whole system. The Debian community has a name for this result: a FrankenDebian. If a program is not in Kali's repositories, look for an official .deb or repository from its developer, a Flatpak, or a container instead.

Partial upgrades. Running apt upgrade without update, or upgrading only some packages on a rolling distribution, can leave mismatched versions. Always update, then full-upgrade, and do it regularly rather than after long gaps.

Interrupting updates. Closing the terminal or shutting down during an upgrade leaves packages half configured. If it happens, run sudo dpkg --configure -a, then update and full-upgrade again.

Using pip as root for system packages. Installing Python packages with sudo pip can overwrite files that apt manages. Kali now blocks this by default, following Debian, with an "externally managed environment" message; use apt for Python packages that Kali provides, or a virtual environment or pipx for others.

Running everything as root. Logging in as root and running all commands with full rights makes mistakes more damaging. Use your normal user and sudo when needed; if you have trouble with sudo or su, our guides to su authentication failure and sudo unable to resolve host help.

Copying commands without reading them. Course notes and forum posts sometimes include commands that remove packages, add repositories or change keys. Reading each command, and running apt show or checking the man page for anything unfamiliar, takes seconds and prevents most self-inflicted damage. It is also good practice for security work generally, where understanding exactly what a command does is part of the job.

Common apt errors and what they mean

E: Unable to locate package. apt cannot find a package by that name: the lists are not updated, the name is wrong, or the package is in a repository you do not have. Run sudo apt update first, check the name with apt search, and see our guide to "Unable to locate package" for the rest.

Could not get lock /var/lib/dpkg/lock-frontend. Another package process is running, such as an automatic update or another terminal. Wait a few minutes and try again. If no other apt or dpkg process is running and the lock remains after a crash, restart the PC rather than deleting lock files.

The following signatures were invalid or NO_PUBKEY. The repository's signing key is missing or outdated, typically after Kali rotates its key. Install the current archive keyring as described in our signature error guide.

dpkg was interrupted. Run sudo dpkg --configure -a.

Held back packages or unmet dependencies. Usually fixed by sudo apt update followed by sudo apt full-upgrade. If unmet dependencies persist, check for third-party or other-distribution repositories in /etc/apt/sources.list.d/ and remove those that do not belong.

Temporary failure resolving http.kali.org. The system has no working network or DNS. Check your connection; in a virtual machine, check its network adapter settings.

See what apt has done

apt keeps a log of everything it installs, upgrades and removes, which helps when something changes unexpectedly. The file /var/log/apt/history.log lists each apt command with its date and the packages affected; older logs are compressed alongside it. /var/log/dpkg.log records the lower-level details. Viewing them is simple: less /var/log/apt/history.log.

To stop a particular package from being upgraded, for example while you test something, run sudo apt-mark hold packagename, and sudo apt-mark unhold packagename to release it. On a rolling distribution, keep holds short, since a held package can block other updates.

Free disk space with apt

Kali installs, especially virtual machines with small disks, fill up surprisingly quickly, and apt keeps some things you may not need. sudo apt clean deletes the cached .deb files in /var/cache/apt/archives, which can be several gigabytes after big updates; apt downloads them again if ever needed. sudo apt autoclean removes only cached files for versions that are no longer available, a gentler option.

sudo apt autoremove removes dependencies that are no longer needed, and on a long-lived system, old kernels are often among them, freeing hundreds of megabytes each. Removing large tools or metapackages you no longer use, with apt remove or purge, frees the most space. du -sh /var/cache/apt/archives shows how much the cache holds before you clean it.

On virtual machines, freeing space inside Kali does not automatically shrink the virtual disk file on the host; the virtualization software has its own compact or trim option for that.

Updating on a slow or limited connection

A large Kali update can be several gigabytes, which is a problem on slow, metered or mobile connections. Several habits help. Update regularly, so each update is small, rather than after months. Check the download size apt reports before confirming, and postpone large updates to a better connection. Install only the tools you need, since kali-linux-everything multiplies update sizes.

apt can also download now and install later: sudo apt full-upgrade --download-only fetches all packages into the cache, and running full-upgrade again later installs them without downloading. If a download is interrupted, rerunning the command resumes from the packages that are already complete.

Remove a tool completely

To remove a tool and everything it brought with it, run sudo apt purge packagename, which removes the package and its system configuration files, then sudo apt autoremove --purge to remove dependencies nothing else needs, along with their configuration. Files the tool created in your home folder, such as hidden configuration folders starting with a dot, are not touched; delete those by hand if you want a completely clean slate.

If you installed a tool with a metapackage, removing a single tool may also mark the metapackage for removal, since it no longer has all its parts. That is normal and removes nothing else by itself, though a later autoremove may remove other tools that were only installed as part of the metapackage. Read the list before confirming.

apt in WSL, Docker and the cloud

apt works the same wherever Kali runs. In Kali on WSL, installed from the Microsoft Store or with wsl --install, apt manages the Kali environment inside Windows; the minimal WSL image includes few tools, so installing a metapackage such as kali-linux-default, or individual tools, is the usual first step. Updates work with the same update and full-upgrade commands.

In Docker, the official Kali images are minimal too, and Dockerfiles use apt-get, with update and install in the same RUN line, and often --no-install-recommends to keep images small. In cloud images, run update and full-upgrade after launching, since images may be weeks old. The commands and repositories are identical; only the starting set of packages differs.

One difference worth knowing in WSL: Kali there shares the PC with Windows, so heavy tools that need direct hardware access, such as wireless adapters in monitor mode, may not work the same way as on a full installation or virtual machine, regardless of how they were installed with apt. For those, a virtual machine with USB passthrough or a full installation is the better platform.

Frequently asked questions

What is apt in Kali Linux?

apt, the Advanced Package Tool, is the command that installs, updates and removes software from Kali's repositories, handling dependencies automatically.

What does sudo apt update do?

It downloads the latest package lists from the repositories so apt knows which versions are available. It does not install anything.

What is the difference between apt update and apt upgrade?

update refreshes the package lists; upgrade installs newer versions. Run update first, then upgrade.

Should I use apt upgrade or full-upgrade on Kali?

full-upgrade. Kali is a rolling release, and full-upgrade can add or remove packages as updates require.

What is the difference between apt and apt-get?

Same system and packages. apt is friendlier for people; apt-get has stable output for scripts.

What is dpkg?

The Debian package manager, the low-level tool that installs .deb files. apt uses it underneath and adds downloading and dependency handling.

What does sudo mean?

It runs a single command with root (administrator) rights after you enter your password.

What is the full form of apt?

Advanced Package Tool.

How do I install a .deb file on Kali?

Run sudo apt install ./file.deb from the file's folder. apt resolves dependencies automatically.

Is sudo apt autoremove safe?

Generally yes. It removes dependencies nothing needs any more. Read the list before confirming.

How often should I update Kali?

At least weekly if you use it regularly, and always before starting a new project or course module.

Can I add Ubuntu repositories to Kali?

No. Mixing repositories from other distributions breaks dependencies. Use official developer packages, Flatpak or containers instead.

Why does apt say Unable to locate package?

The package lists are outdated, the name is wrong, or the package is not in your repositories. Run apt update and check the name with apt search.

How do I fix "Could not get lock"?

Wait for the other package process to finish. If none is running, restart rather than deleting lock files.

What is kali-linux-everything?

A metapackage that installs every tool Kali packages. It is very large; smaller metapackages suit most needs.

Where is the Kali sources list?

/etc/apt/sources.list, with extra repository files in /etc/apt/sources.list.d/.

How do I see what apt installed recently?

Read /var/log/apt/history.log, which lists every apt command and the packages affected.

Do I need sudo for apt search?

No. Commands that only read information, such as search, show and list, work without sudo.

What does kept back mean in apt?

Some upgrades need packages added or removed, which plain upgrade will not do. Run sudo apt full-upgrade.

Should I keep my configuration file or install the maintainer's version?

Keep yours if you customized it; otherwise install the maintainer's. When unsure, view the differences first.

How do I download updates now and install later?

Run sudo apt full-upgrade --download-only, then run full-upgrade again later to install from the cache.

How do I completely remove a tool from Kali?

Run sudo apt purge packagename, then sudo apt autoremove --purge, and delete its dot folders in your home directory if needed.

Do I need to reinstall Kali for each new release?

No. Running sudo apt update and sudo apt full-upgrade brings an installed system up to the latest release.

Does Kali update automatically?

No, not by default. Update deliberately with apt before starting work, so tools do not change unexpectedly.

Is apt the same on Kali, Debian and Ubuntu?

Yes, the tool is the same. The repositories differ, which is why packages and versions differ between them.

What does apt clean do?

It deletes cached package files in /var/cache/apt/archives to free disk space. apt downloads them again if needed.

How do I find which package provides a command?

Install apt-file, run sudo apt-file update, then apt-file search with the command's path, such as bin/xyz.

Can I use apt on Windows?

Not directly. Install Kali or another Linux distribution in WSL, and apt works inside it exactly as on a full installation.

What is the difference between apt remove and apt purge?

remove keeps the package's system configuration files; purge deletes them too. Neither touches files in your home folder.

apt is the heart of Kali's software management: it fetches packages from signed repositories, resolves dependencies, and keeps the whole system updated with two commands, sudo apt update and sudo apt full-upgrade. dpkg does the low-level work underneath, and sudo gives the commands the rights they need. Install with apt install, search with apt search, keep to Kali's own repositories, and update regularly, and Kali stays healthy. Ethan's son now reads every command before he runs it, which his instructor says is the most important skill of all.

📌 If you keep one line from this page

sudo apt update && sudo apt full-upgrade, regularly, and only Kali's own repositories.

apt for typing, apt-get for scripts: same packages either way.

Revision note. Written October 3, 2026, expanding our 2019 explainer of apt, dpkg and sudo into a complete guide for Kali Linux. It covers what apt is, the full forms, updating with full-upgrade, upgrade variants, a command cheat sheet, dpkg, apt versus apt-get, repositories and keys, metapackages, mistakes that break Kali, common errors and apt's history log. May every update finish cleanly.

Related