← All cheat sheets

LSOF

Plain-text reference · 6 KB. Read it, search it (Ctrl-F) or print it.

lsof = "list open files"
Lists information about files opened by processes.
In Unix, everything is a file (sockets, pipes, devices).

BASIC USAGE#

lsof                            # All open files (huge output!)
lsof -u username                # Files opened by user
lsof -c process                 # Files opened by process name
lsof -p PID                     # Files opened by PID
lsof /path/to/file              # Processes using file
lsof +D /directory              # Files in directory (recursive)
lsof +d /directory              # Files in directory (non-recursive)

NETWORK CONNECTIONS#

lsof -i                         # All network connections
lsof -i tcp                     # TCP connections only
lsof -i udp                     # UDP connections only
lsof -i :22                     # Connections on port 22
lsof -i :80,443                 # Multiple ports
lsof -i tcp:80                  # TCP port 80
lsof -i @host                   # Connections to host
lsof -i @192.168.1.1            # Connections to IP
lsof -i @host:port              # Host and port
lsof -i 4                       # IPv4 only
lsof -i 6                       # IPv6 only

LISTENING PORTS#

lsof -i -P -n | grep LISTEN     # All listening ports
lsof -iTCP -sTCP:LISTEN         # TCP listening
lsof -i :22 -sTCP:LISTEN        # Listening on port 22

ESTABLISHED CONNECTIONS#

lsof -i -sTCP:ESTABLISHED       # Established TCP
lsof -i @192.168.1.1 -sTCP:ESTABLISHED  # To specific host

BY USER#

lsof -u username                # User's open files
lsof -u ^root                   # Not root (exclude)
lsof -u user1,user2             # Multiple users

BY PROCESS#

lsof -c nginx                   # Process name starts with
lsof -c nginx -c apache         # Multiple processes
lsof -p 1234                    # Specific PID
lsof -p 1234,5678               # Multiple PIDs
lsof -p ^1234                   # Exclude PID

BY FILE/DIRECTORY#

lsof /var/log/syslog            # Who has file open
lsof /home/user/                # Files in directory
lsof +D /var/log                # Recursive directory
lsof +d /var/log                # Non-recursive
lsof +L1                        # Deleted files still open

FILE TYPES#

lsof -d 0                       # Standard input
lsof -d 1                       # Standard output
lsof -d 2                       # Standard error
lsof -d 0-2                     # stdin, stdout, stderr
lsof -d txt                     # Program text (executable)
lsof -d cwd                     # Current working directory
lsof -d mem                     # Memory-mapped files

OUTPUT OPTIONS#

lsof -n                         # No DNS resolution
lsof -P                         # No port name resolution
lsof -nP                        # Both (faster output)
lsof -t                         # PIDs only (terse)
lsof -F                         # Machine-parseable output
lsof +fg                        # Show file flags
lsof -r 2                       # Repeat every 2 seconds

COMBINING OPTIONS#

# OR logic (default between -u, -c, -p)
lsof -u user -c nginx           # User OR process

# AND logic (use -a)
lsof -a -u user -c nginx        # User AND process
lsof -a -i tcp -u user          # TCP AND user

COMMON EXAMPLES#

# Find what's using a port
lsof -i :8080

# Find deleted files still in use
lsof +L1

# Find who's writing to a log
lsof /var/log/messages

# Network connections for a process
lsof -i -a -c firefox

# All listening services
lsof -i -P -n | grep LISTEN

# Find large deleted files (disk space)
lsof +L1 | grep deleted

# All connections to a remote host
lsof -i @192.168.1.100

# Files opened by process and children
lsof -p $(pgrep -d, processname)

# User's network activity
lsof -a -i -u username

# NFS files
lsof -N

# Unix sockets
lsof -U

# Files on specific filesystem
lsof /dev/sda1

SECURITY/TROUBLESHOOTING#

# Find unauthorized listeners
lsof -i -P -n | grep LISTEN | grep -v "127.0.0.1"

# Find connections to suspicious IPs
lsof -i @malicious.com

# Find processes with open files in /tmp
lsof +D /tmp

# Check for files opened by root
lsof -u root -c suspicious_process

# Find what's preventing unmount
lsof +D /mnt/usb
fuser -m /mnt/usb

# Connections by process tree
lsof -R -i tcp

INTERPRETING OUTPUT#

COMMAND  PID  USER   FD   TYPE  DEVICE  SIZE/OFF  NODE  NAME

FD (File Descriptor):
cwd     Current working directory
txt     Program text (code and data)
mem     Memory-mapped file
rtd     Root directory
0       Standard input
1       Standard output
2       Standard error
3-n     Other file descriptors
u       Read and write
r       Read only
w       Write only

TYPE:
REG     Regular file
DIR     Directory
FIFO    Named pipe
CHR     Character device
BLK     Block device
UNIX    Unix domain socket
IPv4    IPv4 socket
IPv6    IPv6 socket

NODE:
TCP     TCP socket
UDP     UDP socket
(number) Inode number

PERFORMANCE TIPS#

# Always use -n and -P for faster output
lsof -nP -i :80

# Use -t when you just need PIDs
kill $(lsof -t -i :8080)

# Limit scope when possible
lsof -c nginx -n -P
fuser /path/to/file             # Simpler file usage check
fuser -k /path/to/file          # Kill processes using file
ss -tulpn                       # Socket statistics
netstat -tulpn                  # Network statistics (older)

QUICK REFERENCE#

lsof -i                 All network
lsof -i :80             Port 80
lsof -i tcp             TCP only
lsof -u user            By user
lsof -c process         By process
lsof -p PID             By PID
lsof /path              Who has file open
lsof +D /dir            Files in directory
lsof -t                 PIDs only
lsof -nP                Fast (no DNS)
lsof -i -sTCP:LISTEN    Listening ports

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.