FIND COMMAND
BASIC SYNTAX#
find [path] [options] [expression] find . # Find all files in current directory find /home # Find all files in /home find . -name "file.txt" # Find by exact name find . -name "*.txt" # Find by pattern
SEARCH BY NAME#
find . -name "file.txt" # Exact name (case sensitive) find . -iname "file.txt" # Case insensitive find . -name "*.log" # Wildcard pattern find . -name "file?.txt" # Single character wildcard find . -name "[abc]*" # Character class find . -not -name "*.txt" # Exclude pattern find . ! -name "*.txt" # Same as above find . -name "*.txt" -o -name "*.md" # OR condition
SEARCH BY TYPE#
find . -type f # Regular files only find . -type d # Directories only find . -type l # Symbolic links find . -type b # Block devices find . -type c # Character devices find . -type p # Named pipes (FIFO) find . -type s # Sockets
SEARCH BY SIZE#
find . -size 100c # Exactly 100 bytes find . -size 100k # Exactly 100 KB find . -size 100M # Exactly 100 MB find . -size 1G # Exactly 1 GB find . -size +100M # Greater than 100 MB find . -size -100M # Less than 100 MB find . -size +10M -size -100M # Between 10 and 100 MB find . -empty # Empty files and directories
SEARCH BY TIME#
# Modification time (-mtime) find . -mtime 0 # Modified in last 24 hours find . -mtime 1 # Modified 24-48 hours ago find . -mtime +7 # Modified more than 7 days ago find . -mtime -7 # Modified within last 7 days # Access time (-atime) find . -atime 0 # Accessed in last 24 hours find . -atime +30 # Accessed more than 30 days ago # Change time (-ctime) - metadata changes find . -ctime -1 # Changed within last 24 hours # Minutes instead of days find . -mmin -60 # Modified in last 60 minutes find . -mmin +60 # Modified more than 60 min ago find . -amin -30 # Accessed in last 30 minutes # Newer than reference file find . -newer reference.txt # Newer than reference.txt find . -anewer reference.txt # Accessed more recently find . -cnewer reference.txt # Changed more recently
SEARCH BY PERMISSIONS#
find . -perm 644 # Exact permissions find . -perm -644 # At least these permissions find . -perm /644 # Any of these permissions find . -perm -u+x # User executable find . -perm -g+w # Group writable find . -perm -o+r # Others readable find . -perm /u+x,g+x # User OR group executable # Security-related searches find . -perm -4000 # SUID files find . -perm -2000 # SGID files find . -perm -1000 # Sticky bit find . -perm -0002 # World writable find / -perm -4000 -type f 2>/dev/null # Find all SUID executables
SEARCH BY OWNER#
find . -user username # Owned by user find . -group groupname # Owned by group find . -uid 1000 # Owned by UID 1000 find . -gid 1000 # Owned by GID 1000 find . -nouser # No owner (orphaned) find . -nogroup # No group (orphaned)
SEARCH BY DEPTH#
find . -maxdepth 1 # Current directory only find . -maxdepth 2 # Max 2 levels deep find . -mindepth 2 # Start 2 levels deep find . -mindepth 1 -maxdepth 3 # Levels 1-3
COMBINING CONDITIONS#
find . -name "*.txt" -type f # AND (implicit) find . -name "*.txt" -a -type f # AND (explicit) find . -name "*.txt" -o -name "*.md" # OR find . ! -name "*.txt" # NOT find . -not -name "*.txt" # NOT (alternative) # Complex conditions with parentheses find . \( -name "*.txt" -o -name "*.md" \) -type f find . -type f \( -name "*.log" -o -name "*.tmp" \)
ACTIONS#
# Print (default)
find . -name "*.txt" -print # Print paths (default)
find . -name "*.txt" -print0 # Null-terminated (for xargs)
# Execute commands
find . -name "*.txt" -exec cat {} \; # Execute for each file
find . -name "*.txt" -exec cat {} + # Execute with multiple files
find . -name "*.log" -exec rm {} \; # Delete files
find . -type f -exec chmod 644 {} \; # Change permissions
# Execute with confirmation
find . -name "*.tmp" -ok rm {} \; # Ask before each action
# Delete directly (faster than -exec rm)
find . -name "*.tmp" -delete # Delete files
find . -empty -type d -delete # Delete empty directories
# Print with format
find . -printf "%p %s\n" # Path and size
find . -printf "%p %u %g\n" # Path, user, group
find . -printf "%T+ %p\n" # Timestamp and path
PRINTF FORMAT SPECIFIERS#
%p Full path %f Filename only %h Directory path %s Size in bytes %k Size in KB %u Username %g Group name %U UID %G GID %m Permissions (octal) %M Permissions (symbolic) %T+ Modification time %A+ Access time %C+ Change time %d Depth in directory tree
PRACTICAL EXAMPLES#
# Find large files
find / -type f -size +100M 2>/dev/null
# Find recently modified files
find . -type f -mmin -30
# Find and delete old log files
find /var/log -name "*.log" -mtime +30 -delete
# Find files and show with details
find . -type f -exec ls -lh {} \;
# Count files by extension
find . -type f -name "*.py" | wc -l
# Find duplicate filenames
find . -type f -printf "%f\n" | sort | uniq -d
# Find files with specific content
find . -type f -name "*.txt" -exec grep -l "pattern" {} \;
# Find and replace in files
find . -type f -name "*.txt" -exec sed -i 's/old/new/g' {} \;
# Find broken symlinks
find . -type l ! -exec test -e {} \; -print
# Find files modified today
find . -type f -daystart -mtime 0
# Find executable files
find . -type f -executable
# Archive found files
find . -name "*.log" -exec tar -rvf logs.tar {} \;
# Find files excluding directories
find . -type f -not -path "./node_modules/*"
find . -type f -not -path "./.git/*"
# Find with multiple exclusions
find . -type f \
-not -path "./.git/*" \
-not -path "./node_modules/*" \
-not -name "*.pyc"
SECURITY AUDITING#
# World-writable files find / -type f -perm -0002 2>/dev/null # World-writable directories find / -type d -perm -0002 2>/dev/null # SUID executables find / -type f -perm -4000 2>/dev/null # SGID executables find / -type f -perm -2000 2>/dev/null # Files without owner find / -nouser 2>/dev/null # Files without group find / -nogroup 2>/dev/null # Recently modified system files find /etc -type f -mtime -1 # Find config files find /etc -name "*.conf" -type f
PERFORMANCE TIPS#
# Use -type early to filter faster find . -type f -name "*.txt" # Good find . -name "*.txt" -type f # Works but slower # Use -maxdepth to limit search find . -maxdepth 3 -name "*.log" # Use -prune to skip directories find . -path "./node_modules" -prune -o -name "*.js" -print # Redirect errors find / -name "file" 2>/dev/null # Use with xargs for efficiency find . -name "*.txt" -print0 | xargs -0 grep "pattern"
COMBINING WITH OTHER TOOLS#
# With xargs
find . -name "*.txt" -print0 | xargs -0 wc -l
# With grep
find . -name "*.py" -exec grep -H "import" {} \;
# With sort
find . -type f -printf "%s %p\n" | sort -n
# With head/tail
find . -type f -printf "%T+ %p\n" | sort -r | head -10
# With tar
find . -name "*.log" | tar -cvf logs.tar -T -
# With rsync
find . -name "*.jpg" -print0 | rsync -av --files-from=- --from0 . /backup/
FIND COMMAND CHEATSHEET
=======================
Source: https://cheatsheet.johlem.net
BASIC SYNTAX
------------
find [path] [options] [expression]
find . # Find all files in current directory
find /home # Find all files in /home
find . -name "file.txt" # Find by exact name
find . -name "*.txt" # Find by pattern
SEARCH BY NAME
--------------
find . -name "file.txt" # Exact name (case sensitive)
find . -iname "file.txt" # Case insensitive
find . -name "*.log" # Wildcard pattern
find . -name "file?.txt" # Single character wildcard
find . -name "[abc]*" # Character class
find . -not -name "*.txt" # Exclude pattern
find . ! -name "*.txt" # Same as above
find . -name "*.txt" -o -name "*.md" # OR condition
SEARCH BY TYPE
--------------
find . -type f # Regular files only
find . -type d # Directories only
find . -type l # Symbolic links
find . -type b # Block devices
find . -type c # Character devices
find . -type p # Named pipes (FIFO)
find . -type s # Sockets
SEARCH BY SIZE
--------------
find . -size 100c # Exactly 100 bytes
find . -size 100k # Exactly 100 KB
find . -size 100M # Exactly 100 MB
find . -size 1G # Exactly 1 GB
find . -size +100M # Greater than 100 MB
find . -size -100M # Less than 100 MB
find . -size +10M -size -100M # Between 10 and 100 MB
find . -empty # Empty files and directories
SEARCH BY TIME
--------------
# Modification time (-mtime)
find . -mtime 0 # Modified in last 24 hours
find . -mtime 1 # Modified 24-48 hours ago
find . -mtime +7 # Modified more than 7 days ago
find . -mtime -7 # Modified within last 7 days
# Access time (-atime)
find . -atime 0 # Accessed in last 24 hours
find . -atime +30 # Accessed more than 30 days ago
# Change time (-ctime) - metadata changes
find . -ctime -1 # Changed within last 24 hours
# Minutes instead of days
find . -mmin -60 # Modified in last 60 minutes
find . -mmin +60 # Modified more than 60 min ago
find . -amin -30 # Accessed in last 30 minutes
# Newer than reference file
find . -newer reference.txt # Newer than reference.txt
find . -anewer reference.txt # Accessed more recently
find . -cnewer reference.txt # Changed more recently
SEARCH BY PERMISSIONS
---------------------
find . -perm 644 # Exact permissions
find . -perm -644 # At least these permissions
find . -perm /644 # Any of these permissions
find . -perm -u+x # User executable
find . -perm -g+w # Group writable
find . -perm -o+r # Others readable
find . -perm /u+x,g+x # User OR group executable
# Security-related searches
find . -perm -4000 # SUID files
find . -perm -2000 # SGID files
find . -perm -1000 # Sticky bit
find . -perm -0002 # World writable
find / -perm -4000 -type f 2>/dev/null # Find all SUID executables
SEARCH BY OWNER
---------------
find . -user username # Owned by user
find . -group groupname # Owned by group
find . -uid 1000 # Owned by UID 1000
find . -gid 1000 # Owned by GID 1000
find . -nouser # No owner (orphaned)
find . -nogroup # No group (orphaned)
SEARCH BY DEPTH
---------------
find . -maxdepth 1 # Current directory only
find . -maxdepth 2 # Max 2 levels deep
find . -mindepth 2 # Start 2 levels deep
find . -mindepth 1 -maxdepth 3 # Levels 1-3
COMBINING CONDITIONS
--------------------
find . -name "*.txt" -type f # AND (implicit)
find . -name "*.txt" -a -type f # AND (explicit)
find . -name "*.txt" -o -name "*.md" # OR
find . ! -name "*.txt" # NOT
find . -not -name "*.txt" # NOT (alternative)
# Complex conditions with parentheses
find . \( -name "*.txt" -o -name "*.md" \) -type f
find . -type f \( -name "*.log" -o -name "*.tmp" \)
ACTIONS
-------
# Print (default)
find . -name "*.txt" -print # Print paths (default)
find . -name "*.txt" -print0 # Null-terminated (for xargs)
# Execute commands
find . -name "*.txt" -exec cat {} \; # Execute for each file
find . -name "*.txt" -exec cat {} + # Execute with multiple files
find . -name "*.log" -exec rm {} \; # Delete files
find . -type f -exec chmod 644 {} \; # Change permissions
# Execute with confirmation
find . -name "*.tmp" -ok rm {} \; # Ask before each action
# Delete directly (faster than -exec rm)
find . -name "*.tmp" -delete # Delete files
find . -empty -type d -delete # Delete empty directories
# Print with format
find . -printf "%p %s\n" # Path and size
find . -printf "%p %u %g\n" # Path, user, group
find . -printf "%T+ %p\n" # Timestamp and path
PRINTF FORMAT SPECIFIERS
------------------------
%p Full path
%f Filename only
%h Directory path
%s Size in bytes
%k Size in KB
%u Username
%g Group name
%U UID
%G GID
%m Permissions (octal)
%M Permissions (symbolic)
%T+ Modification time
%A+ Access time
%C+ Change time
%d Depth in directory tree
PRACTICAL EXAMPLES
------------------
# Find large files
find / -type f -size +100M 2>/dev/null
# Find recently modified files
find . -type f -mmin -30
# Find and delete old log files
find /var/log -name "*.log" -mtime +30 -delete
# Find files and show with details
find . -type f -exec ls -lh {} \;
# Count files by extension
find . -type f -name "*.py" | wc -l
# Find duplicate filenames
find . -type f -printf "%f\n" | sort | uniq -d
# Find files with specific content
find . -type f -name "*.txt" -exec grep -l "pattern" {} \;
# Find and replace in files
find . -type f -name "*.txt" -exec sed -i 's/old/new/g' {} \;
# Find broken symlinks
find . -type l ! -exec test -e {} \; -print
# Find files modified today
find . -type f -daystart -mtime 0
# Find executable files
find . -type f -executable
# Archive found files
find . -name "*.log" -exec tar -rvf logs.tar {} \;
# Find files excluding directories
find . -type f -not -path "./node_modules/*"
find . -type f -not -path "./.git/*"
# Find with multiple exclusions
find . -type f \
-not -path "./.git/*" \
-not -path "./node_modules/*" \
-not -name "*.pyc"
SECURITY AUDITING
-----------------
# World-writable files
find / -type f -perm -0002 2>/dev/null
# World-writable directories
find / -type d -perm -0002 2>/dev/null
# SUID executables
find / -type f -perm -4000 2>/dev/null
# SGID executables
find / -type f -perm -2000 2>/dev/null
# Files without owner
find / -nouser 2>/dev/null
# Files without group
find / -nogroup 2>/dev/null
# Recently modified system files
find /etc -type f -mtime -1
# Find config files
find /etc -name "*.conf" -type f
PERFORMANCE TIPS
----------------
# Use -type early to filter faster
find . -type f -name "*.txt" # Good
find . -name "*.txt" -type f # Works but slower
# Use -maxdepth to limit search
find . -maxdepth 3 -name "*.log"
# Use -prune to skip directories
find . -path "./node_modules" -prune -o -name "*.js" -print
# Redirect errors
find / -name "file" 2>/dev/null
# Use with xargs for efficiency
find . -name "*.txt" -print0 | xargs -0 grep "pattern"
COMBINING WITH OTHER TOOLS
--------------------------
# With xargs
find . -name "*.txt" -print0 | xargs -0 wc -l
# With grep
find . -name "*.py" -exec grep -H "import" {} \;
# With sort
find . -type f -printf "%s %p\n" | sort -n
# With head/tail
find . -type f -printf "%T+ %p\n" | sort -r | head -10
# With tar
find . -name "*.log" | tar -cvf logs.tar -T -
# With rsync
find . -name "*.jpg" -print0 | rsync -av --files-from=- --from0 . /backup/
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.