← All cheat sheets

FIND COMMAND

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

BASIC SYNTAX#

find [path] [options] [expression]
find .                               # Find all files in current directory
find /home                           # Find all files in /home
find . -name "file.txt"              # Find by exact name
find . -name "*.txt"                 # Find by pattern

SEARCH BY NAME#

find . -name "file.txt"              # Exact name (case sensitive)
find . -iname "file.txt"             # Case insensitive
find . -name "*.log"                 # Wildcard pattern
find . -name "file?.txt"             # Single character wildcard
find . -name "[abc]*"                # Character class
find . -not -name "*.txt"            # Exclude pattern
find . ! -name "*.txt"               # Same as above
find . -name "*.txt" -o -name "*.md" # OR condition

SEARCH BY TYPE#

find . -type f                       # Regular files only
find . -type d                       # Directories only
find . -type l                       # Symbolic links
find . -type b                       # Block devices
find . -type c                       # Character devices
find . -type p                       # Named pipes (FIFO)
find . -type s                       # Sockets

SEARCH BY SIZE#

find . -size 100c                    # Exactly 100 bytes
find . -size 100k                    # Exactly 100 KB
find . -size 100M                    # Exactly 100 MB
find . -size 1G                      # Exactly 1 GB
find . -size +100M                   # Greater than 100 MB
find . -size -100M                   # Less than 100 MB
find . -size +10M -size -100M        # Between 10 and 100 MB
find . -empty                        # Empty files and directories

SEARCH BY TIME#

# Modification time (-mtime)
find . -mtime 0                      # Modified in last 24 hours
find . -mtime 1                      # Modified 24-48 hours ago
find . -mtime +7                     # Modified more than 7 days ago
find . -mtime -7                     # Modified within last 7 days

# Access time (-atime)
find . -atime 0                      # Accessed in last 24 hours
find . -atime +30                    # Accessed more than 30 days ago

# Change time (-ctime) - metadata changes
find . -ctime -1                     # Changed within last 24 hours

# Minutes instead of days
find . -mmin -60                     # Modified in last 60 minutes
find . -mmin +60                     # Modified more than 60 min ago
find . -amin -30                     # Accessed in last 30 minutes

# Newer than reference file
find . -newer reference.txt          # Newer than reference.txt
find . -anewer reference.txt         # Accessed more recently
find . -cnewer reference.txt         # Changed more recently

SEARCH BY PERMISSIONS#

find . -perm 644                     # Exact permissions
find . -perm -644                    # At least these permissions
find . -perm /644                    # Any of these permissions
find . -perm -u+x                    # User executable
find . -perm -g+w                    # Group writable
find . -perm -o+r                    # Others readable
find . -perm /u+x,g+x                # User OR group executable

# Security-related searches
find . -perm -4000                   # SUID files
find . -perm -2000                   # SGID files
find . -perm -1000                   # Sticky bit
find . -perm -0002                   # World writable
find / -perm -4000 -type f 2>/dev/null  # Find all SUID executables

SEARCH BY OWNER#

find . -user username                # Owned by user
find . -group groupname              # Owned by group
find . -uid 1000                     # Owned by UID 1000
find . -gid 1000                     # Owned by GID 1000
find . -nouser                       # No owner (orphaned)
find . -nogroup                      # No group (orphaned)

SEARCH BY DEPTH#

find . -maxdepth 1                   # Current directory only
find . -maxdepth 2                   # Max 2 levels deep
find . -mindepth 2                   # Start 2 levels deep
find . -mindepth 1 -maxdepth 3       # Levels 1-3

COMBINING CONDITIONS#

find . -name "*.txt" -type f         # AND (implicit)
find . -name "*.txt" -a -type f      # AND (explicit)
find . -name "*.txt" -o -name "*.md" # OR
find . ! -name "*.txt"               # NOT
find . -not -name "*.txt"            # NOT (alternative)

# Complex conditions with parentheses
find . \( -name "*.txt" -o -name "*.md" \) -type f
find . -type f \( -name "*.log" -o -name "*.tmp" \)

ACTIONS#

# Print (default)
find . -name "*.txt" -print          # Print paths (default)
find . -name "*.txt" -print0         # Null-terminated (for xargs)

# Execute commands
find . -name "*.txt" -exec cat {} \; # Execute for each file
find . -name "*.txt" -exec cat {} +  # Execute with multiple files
find . -name "*.log" -exec rm {} \;  # Delete files
find . -type f -exec chmod 644 {} \; # Change permissions

# Execute with confirmation
find . -name "*.tmp" -ok rm {} \;    # Ask before each action

# Delete directly (faster than -exec rm)
find . -name "*.tmp" -delete         # Delete files
find . -empty -type d -delete        # Delete empty directories

# Print with format
find . -printf "%p %s\n"             # Path and size
find . -printf "%p %u %g\n"          # Path, user, group
find . -printf "%T+ %p\n"            # Timestamp and path

PRINTF FORMAT SPECIFIERS#

%p      Full path
%f      Filename only
%h      Directory path
%s      Size in bytes
%k      Size in KB
%u      Username
%g      Group name
%U      UID
%G      GID
%m      Permissions (octal)
%M      Permissions (symbolic)
%T+     Modification time
%A+     Access time
%C+     Change time
%d      Depth in directory tree

PRACTICAL EXAMPLES#

# Find large files
find / -type f -size +100M 2>/dev/null

# Find recently modified files
find . -type f -mmin -30

# Find and delete old log files
find /var/log -name "*.log" -mtime +30 -delete

# Find files and show with details
find . -type f -exec ls -lh {} \;

# Count files by extension
find . -type f -name "*.py" | wc -l

# Find duplicate filenames
find . -type f -printf "%f\n" | sort | uniq -d

# Find files with specific content
find . -type f -name "*.txt" -exec grep -l "pattern" {} \;

# Find and replace in files
find . -type f -name "*.txt" -exec sed -i 's/old/new/g' {} \;

# Find broken symlinks
find . -type l ! -exec test -e {} \; -print

# Find files modified today
find . -type f -daystart -mtime 0

# Find executable files
find . -type f -executable

# Archive found files
find . -name "*.log" -exec tar -rvf logs.tar {} \;

# Find files excluding directories
find . -type f -not -path "./node_modules/*"
find . -type f -not -path "./.git/*"

# Find with multiple exclusions
find . -type f \
    -not -path "./.git/*" \
    -not -path "./node_modules/*" \
    -not -name "*.pyc"

SECURITY AUDITING#

# World-writable files
find / -type f -perm -0002 2>/dev/null

# World-writable directories
find / -type d -perm -0002 2>/dev/null

# SUID executables
find / -type f -perm -4000 2>/dev/null

# SGID executables
find / -type f -perm -2000 2>/dev/null

# Files without owner
find / -nouser 2>/dev/null

# Files without group
find / -nogroup 2>/dev/null

# Recently modified system files
find /etc -type f -mtime -1

# Find config files
find /etc -name "*.conf" -type f

PERFORMANCE TIPS#

# Use -type early to filter faster
find . -type f -name "*.txt"         # Good
find . -name "*.txt" -type f         # Works but slower

# Use -maxdepth to limit search
find . -maxdepth 3 -name "*.log"

# Use -prune to skip directories
find . -path "./node_modules" -prune -o -name "*.js" -print

# Redirect errors
find / -name "file" 2>/dev/null

# Use with xargs for efficiency
find . -name "*.txt" -print0 | xargs -0 grep "pattern"

COMBINING WITH OTHER TOOLS#

# With xargs
find . -name "*.txt" -print0 | xargs -0 wc -l

# With grep
find . -name "*.py" -exec grep -H "import" {} \;

# With sort
find . -type f -printf "%s %p\n" | sort -n

# With head/tail
find . -type f -printf "%T+ %p\n" | sort -r | head -10

# With tar
find . -name "*.log" | tar -cvf logs.tar -T -

# With rsync
find . -name "*.jpg" -print0 | rsync -av --files-from=- --from0 . /backup/

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.