A practical reference for sysadmins using lsof to detect data exfiltration, unauthorized connections, and suspicious file descriptor usage on Linux servers.
What is lsof?
lsof (List Open Files) reports every file descriptor currently open across all processes on a Linux system. In Unix systems, nearly everything is treated as a file — regular files, directories, network sockets, pipes, and device nodes. This makes lsof uniquely powerful for security investigations: it can show you which process is connected to which network endpoint, which process has a deleted file still open (a common malware persistence technique), and which files a specific process or user is actively reading or writing. For incident response, lsof is often more informative than netstat or ss because it directly correlates network connections to the owning process and its full command path. A process holding an open socket to an unfamiliar IP address, combined with its executable path, is often enough to confirm an active data exfiltration or command-and-control channel.
Syntax
lsof
lsof -i
lsof -i :443
lsof -i TCP -s TCP:ESTABLISHED
lsof -u www-data
lsof -p 1234
lsof +D /var/www/htmlWith no arguments, lsof lists all open files system-wide — output is large. Use -i to filter to network connections only. Append a port with -i :<port> to scope to a specific service. The +D flag recursively lists all open files under a directory, useful for auditing a web root.
Key Options and Flags
| Flag / Parameter | Description | Security Note |
|---|---|---|
-i | List all network files (sockets) — includes TCP, UDP, listening and established | First flag to use when looking for unauthorized outbound connections |
-i TCP -s TCP:ESTABLISHED | Show only established TCP connections, excluding listening sockets | Filters out server noise to focus on active outbound connections — key for C2 detection |
-i :<port> | Filter to connections on a specific port number | — |
-u <user> | Show all files opened by a specific user | Audit a compromised service account to see all files and sockets it has open |
-p <pid> | Show all files opened by a specific process ID | — |
+D <dir> | Recursively list all processes with open files under the specified directory | Use on /var/www or /tmp to find processes actively reading or writing to those paths |
-n | Do not resolve hostnames — faster output, avoids DNS leaks during investigation | Always use -n during incident response to avoid alerting an attacker via reverse DNS lookups |
-P | Do not resolve port names — shows raw port numbers instead of service names | — |
Common Use Cases
Find Which Process Holds an Open Socket to an Unknown IP
When network monitoring detects unexpected outbound traffic, lsof -i TCP -s TCP:ESTABLISHED -n -P maps every active TCP connection to its owning process and full executable path. A connection to an unfamiliar IP from a process in /tmp or with a generic name is a strong indicator of a C2 channel.
lsof -i TCP -s TCP:ESTABLISHED -n -PDetect Processes Holding Deleted Files Open
Malware commonly deletes its executable from disk after launching to hinder forensic recovery, but the process continues to run and the file descriptor remains open. lsof will show these as entries with (deleted) in the NAME column. The file contents can be recovered from /proc/<PID>/fd/<FD> while the process is still running.
lsof | grep deletedAudit All Network Activity of a Specific Service Account
Service accounts should have predictable, limited network activity. Querying lsof by user shows every socket open under that account — revealing any unexpected outbound connections that might indicate a compromised service making data exfiltration calls.
lsof -u www-data -i -n -PSecurity Relevance: Mapping Open File Descriptors to Detect Data Exfiltration
Data exfiltration and command-and-control channels both require an active network connection. lsof is the most direct tool for mapping those connections to the exact process responsible, including its full executable path and owning user. This is faster and more precise than correlating PID information from netstat or ss separately. The deleted file pattern is particularly important: sophisticated malware routinely deletes its binary from disk immediately after execution, leaving only the running process and an open file descriptor. Standard file-based scanners will not find the binary. lsof exposes it by showing the open descriptor with a (deleted) marker, and the file contents remain recoverable from the /proc filesystem as long as the process is alive. Run lsof as part of any incident triage alongside ps aux and netstat to build a complete picture of process, file, and network activity.
- A process with an ESTABLISHED connection to a non-standard port and an executable path under /tmp is a high-confidence C2 indicator
- Entries marked (deleted) in lsof output may be malware that erased its binary — recover via /proc/<PID>/fd/<FD> before killing the process
- lsof without -n performs DNS lookups for each connection — this can alert an attacker monitoring their DNS logs during an investigation
- Running lsof system-wide on a busy server produces thousands of lines — always filter with -i, -u, or -p to scope the output
Practical Examples
List all established TCP connections with process details
lsof -i TCP -s TCP:ESTABLISHED -n -PShows every active outbound and inbound TCP connection, the PID, the process name, the user, and the full remote address and port. Use this as the first network triage command during an incident.
Find and recover a deleted malware binary still running in memory
# Find the deleted file and its FD
lsof | grep deleted
# Recover the binary via /proc (replace PID and FD)
cp /proc/<PID>/fd/<FD> /tmp/recovered_binaryIf lsof shows a process with a (deleted) executable, the binary contents are still accessible through the process’s /proc file descriptor entry. Copy it for forensic analysis before terminating the process.
Find all processes with open files in the web root
lsof +D /var/www/htmlLists every process with an open file descriptor pointing to anywhere under the web root. During a web compromise investigation, this shows which processes are actively reading or writing web application files.
Troubleshooting Common Issues
Problem: lsof output is extremely large and hard to navigate
Solution: Always filter with specific flags: -i for network only, -u <user> for a specific account, -p <pid> for a single process, or +D <dir> for a directory. Running bare lsof system-wide is rarely useful without a filter.
Problem: lsof shows no output for a process you know is running
Solution: Run lsof as root. Non-root users can only see file descriptors for processes they own. Many interesting security findings (malware running as root or other system users) are invisible without root access.
Problem: lsof is very slow on a system with many processes
Solution: Add -n -P to skip hostname and port name resolution. DNS lookups are the primary cause of lsof slowness. These flags make output faster and also avoid unintended network queries during a sensitive investigation.
Summary
lsof is the definitive tool for correlating network connections, open files, and file descriptors with the processes that own them. Its ability to expose deleted-but-running executables and map active sockets to exact process paths makes it indispensable for both data exfiltration detection and post-compromise forensics. Use it alongside ps aux and netstat as a core part of every incident triage workflow.
- Use
lsof -i TCP -s TCP:ESTABLISHED -n -Pas the first network triage command — it maps every active connection to its owning process - Run
lsof | grep deletedto find malware that erased its binary but is still running in memory - Always add
-n -Pto lsof commands during investigations to prevent DNS lookups that could alert an attacker
Related Commands
netstat for network socket auditing • ss for fast open port enumeration • htop for interactive process tree inspection
Is Your Linux Server Monitored 24/7?
INTRAM provides managed Linux hosting with continuous process and performance monitoring. We detect anomalies before they become incidents — so your team can focus on building, not firefighting.
Explore Managed Hosting