LSOF
lsof = "list open files" Lists information about files opened by processes. In Unix, everything is a file (sockets, pipes, devices).
BASIC USAGE#
lsof # All open files (huge output!) lsof -u username # Files opened by user lsof -c process # Files opened by process name lsof -p PID # Files opened by PID lsof /path/to/file # Processes using file lsof +D /directory # Files in directory (recursive) lsof +d /directory # Files in directory (non-recursive)
NETWORK CONNECTIONS#
lsof -i # All network connections lsof -i tcp # TCP connections only lsof -i udp # UDP connections only lsof -i :22 # Connections on port 22 lsof -i :80,443 # Multiple ports lsof -i tcp:80 # TCP port 80 lsof -i @host # Connections to host lsof -i @192.168.1.1 # Connections to IP lsof -i @host:port # Host and port lsof -i 4 # IPv4 only lsof -i 6 # IPv6 only
LISTENING PORTS#
lsof -i -P -n | grep LISTEN # All listening ports lsof -iTCP -sTCP:LISTEN # TCP listening lsof -i :22 -sTCP:LISTEN # Listening on port 22
ESTABLISHED CONNECTIONS#
lsof -i -sTCP:ESTABLISHED # Established TCP lsof -i @192.168.1.1 -sTCP:ESTABLISHED # To specific host
BY USER#
lsof -u username # User's open files lsof -u ^root # Not root (exclude) lsof -u user1,user2 # Multiple users
BY PROCESS#
lsof -c nginx # Process name starts with lsof -c nginx -c apache # Multiple processes lsof -p 1234 # Specific PID lsof -p 1234,5678 # Multiple PIDs lsof -p ^1234 # Exclude PID
BY FILE/DIRECTORY#
lsof /var/log/syslog # Who has file open lsof /home/user/ # Files in directory lsof +D /var/log # Recursive directory lsof +d /var/log # Non-recursive lsof +L1 # Deleted files still open
FILE TYPES#
lsof -d 0 # Standard input lsof -d 1 # Standard output lsof -d 2 # Standard error lsof -d 0-2 # stdin, stdout, stderr lsof -d txt # Program text (executable) lsof -d cwd # Current working directory lsof -d mem # Memory-mapped files
OUTPUT OPTIONS#
lsof -n # No DNS resolution lsof -P # No port name resolution lsof -nP # Both (faster output) lsof -t # PIDs only (terse) lsof -F # Machine-parseable output lsof +fg # Show file flags lsof -r 2 # Repeat every 2 seconds
COMBINING OPTIONS#
# OR logic (default between -u, -c, -p) lsof -u user -c nginx # User OR process # AND logic (use -a) lsof -a -u user -c nginx # User AND process lsof -a -i tcp -u user # TCP AND user
COMMON EXAMPLES#
# Find what's using a port lsof -i :8080 # Find deleted files still in use lsof +L1 # Find who's writing to a log lsof /var/log/messages # Network connections for a process lsof -i -a -c firefox # All listening services lsof -i -P -n | grep LISTEN # Find large deleted files (disk space) lsof +L1 | grep deleted # All connections to a remote host lsof -i @192.168.1.100 # Files opened by process and children lsof -p $(pgrep -d, processname) # User's network activity lsof -a -i -u username # NFS files lsof -N # Unix sockets lsof -U # Files on specific filesystem lsof /dev/sda1
SECURITY/TROUBLESHOOTING#
# Find unauthorized listeners lsof -i -P -n | grep LISTEN | grep -v "127.0.0.1" # Find connections to suspicious IPs lsof -i @malicious.com # Find processes with open files in /tmp lsof +D /tmp # Check for files opened by root lsof -u root -c suspicious_process # Find what's preventing unmount lsof +D /mnt/usb fuser -m /mnt/usb # Connections by process tree lsof -R -i tcp
INTERPRETING OUTPUT#
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME FD (File Descriptor): cwd Current working directory txt Program text (code and data) mem Memory-mapped file rtd Root directory 0 Standard input 1 Standard output 2 Standard error 3-n Other file descriptors u Read and write r Read only w Write only TYPE: REG Regular file DIR Directory FIFO Named pipe CHR Character device BLK Block device UNIX Unix domain socket IPv4 IPv4 socket IPv6 IPv6 socket NODE: TCP TCP socket UDP UDP socket (number) Inode number
PERFORMANCE TIPS#
# Always use -n and -P for faster output lsof -nP -i :80 # Use -t when you just need PIDs kill $(lsof -t -i :8080) # Limit scope when possible lsof -c nginx -n -P
RELATED COMMANDS#
fuser /path/to/file # Simpler file usage check fuser -k /path/to/file # Kill processes using file ss -tulpn # Socket statistics netstat -tulpn # Network statistics (older)
QUICK REFERENCE#
lsof -i All network lsof -i :80 Port 80 lsof -i tcp TCP only lsof -u user By user lsof -c process By process lsof -p PID By PID lsof /path Who has file open lsof +D /dir Files in directory lsof -t PIDs only lsof -nP Fast (no DNS) lsof -i -sTCP:LISTEN Listening ports
LSOF CHEATSHEET =============== Source: https://cheatsheet.johlem.net lsof = "list open files" Lists information about files opened by processes. In Unix, everything is a file (sockets, pipes, devices). BASIC USAGE ----------- lsof # All open files (huge output!) lsof -u username # Files opened by user lsof -c process # Files opened by process name lsof -p PID # Files opened by PID lsof /path/to/file # Processes using file lsof +D /directory # Files in directory (recursive) lsof +d /directory # Files in directory (non-recursive) NETWORK CONNECTIONS ------------------- lsof -i # All network connections lsof -i tcp # TCP connections only lsof -i udp # UDP connections only lsof -i :22 # Connections on port 22 lsof -i :80,443 # Multiple ports lsof -i tcp:80 # TCP port 80 lsof -i @host # Connections to host lsof -i @192.168.1.1 # Connections to IP lsof -i @host:port # Host and port lsof -i 4 # IPv4 only lsof -i 6 # IPv6 only LISTENING PORTS --------------- lsof -i -P -n | grep LISTEN # All listening ports lsof -iTCP -sTCP:LISTEN # TCP listening lsof -i :22 -sTCP:LISTEN # Listening on port 22 ESTABLISHED CONNECTIONS ----------------------- lsof -i -sTCP:ESTABLISHED # Established TCP lsof -i @192.168.1.1 -sTCP:ESTABLISHED # To specific host BY USER ------- lsof -u username # User's open files lsof -u ^root # Not root (exclude) lsof -u user1,user2 # Multiple users BY PROCESS ---------- lsof -c nginx # Process name starts with lsof -c nginx -c apache # Multiple processes lsof -p 1234 # Specific PID lsof -p 1234,5678 # Multiple PIDs lsof -p ^1234 # Exclude PID BY FILE/DIRECTORY ----------------- lsof /var/log/syslog # Who has file open lsof /home/user/ # Files in directory lsof +D /var/log # Recursive directory lsof +d /var/log # Non-recursive lsof +L1 # Deleted files still open FILE TYPES ---------- lsof -d 0 # Standard input lsof -d 1 # Standard output lsof -d 2 # Standard error lsof -d 0-2 # stdin, stdout, stderr lsof -d txt # Program text (executable) lsof -d cwd # Current working directory lsof -d mem # Memory-mapped files OUTPUT OPTIONS -------------- lsof -n # No DNS resolution lsof -P # No port name resolution lsof -nP # Both (faster output) lsof -t # PIDs only (terse) lsof -F # Machine-parseable output lsof +fg # Show file flags lsof -r 2 # Repeat every 2 seconds COMBINING OPTIONS ----------------- # OR logic (default between -u, -c, -p) lsof -u user -c nginx # User OR process # AND logic (use -a) lsof -a -u user -c nginx # User AND process lsof -a -i tcp -u user # TCP AND user COMMON EXAMPLES --------------- # Find what's using a port lsof -i :8080 # Find deleted files still in use lsof +L1 # Find who's writing to a log lsof /var/log/messages # Network connections for a process lsof -i -a -c firefox # All listening services lsof -i -P -n | grep LISTEN # Find large deleted files (disk space) lsof +L1 | grep deleted # All connections to a remote host lsof -i @192.168.1.100 # Files opened by process and children lsof -p $(pgrep -d, processname) # User's network activity lsof -a -i -u username # NFS files lsof -N # Unix sockets lsof -U # Files on specific filesystem lsof /dev/sda1 SECURITY/TROUBLESHOOTING ------------------------ # Find unauthorized listeners lsof -i -P -n | grep LISTEN | grep -v "127.0.0.1" # Find connections to suspicious IPs lsof -i @malicious.com # Find processes with open files in /tmp lsof +D /tmp # Check for files opened by root lsof -u root -c suspicious_process # Find what's preventing unmount lsof +D /mnt/usb fuser -m /mnt/usb # Connections by process tree lsof -R -i tcp INTERPRETING OUTPUT ------------------- COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME FD (File Descriptor): cwd Current working directory txt Program text (code and data) mem Memory-mapped file rtd Root directory 0 Standard input 1 Standard output 2 Standard error 3-n Other file descriptors u Read and write r Read only w Write only TYPE: REG Regular file DIR Directory FIFO Named pipe CHR Character device BLK Block device UNIX Unix domain socket IPv4 IPv4 socket IPv6 IPv6 socket NODE: TCP TCP socket UDP UDP socket (number) Inode number PERFORMANCE TIPS ---------------- # Always use -n and -P for faster output lsof -nP -i :80 # Use -t when you just need PIDs kill $(lsof -t -i :8080) # Limit scope when possible lsof -c nginx -n -P RELATED COMMANDS ---------------- fuser /path/to/file # Simpler file usage check fuser -k /path/to/file # Kill processes using file ss -tulpn # Socket statistics netstat -tulpn # Network statistics (older) QUICK REFERENCE --------------- lsof -i All network lsof -i :80 Port 80 lsof -i tcp TCP only lsof -u user By user lsof -c process By process lsof -p PID By PID lsof /path Who has file open lsof +D /dir Files in directory lsof -t PIDs only lsof -nP Fast (no DNS) lsof -i -sTCP:LISTEN Listening ports
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.