A practical reference for sysadmins using lsof to detect data exfiltration, unauthorized connections, and suspicious file descriptor usage on Linux servers.

What is lsof?

lsof (List Open Files) reports every file descriptor currently open across all processes on a Linux system. In Unix systems, nearly everything is treated as a file — regular files, directories, network sockets, pipes, and device nodes. This makes lsof uniquely powerful for security investigations: it can show you which process is connected to which network endpoint, which process has a deleted file still open (a common malware persistence technique), and which files a specific process or user is actively reading or writing. For incident response, lsof is often more informative than netstat or ss because it directly correlates network connections to the owning process and its full command path. A process holding an open socket to an unfamiliar IP address, combined with its executable path, is often enough to confirm an active data exfiltration or command-and-control channel.

Syntax

lsof
lsof -i
lsof -i :443
lsof -i TCP -s TCP:ESTABLISHED
lsof -u www-data
lsof -p 1234
lsof +D /var/www/html

With no arguments, lsof lists all open files system-wide — output is large. Use -i to filter to network connections only. Append a port with -i :<port> to scope to a specific service. The +D flag recursively lists all open files under a directory, useful for auditing a web root.

Key Options and Flags

Flag / ParameterDescriptionSecurity Note
-iList all network files (sockets) — includes TCP, UDP, listening and establishedFirst flag to use when looking for unauthorized outbound connections
-i TCP -s TCP:ESTABLISHEDShow only established TCP connections, excluding listening socketsFilters out server noise to focus on active outbound connections — key for C2 detection
-i :<port>Filter to connections on a specific port number—
-u <user>Show all files opened by a specific userAudit a compromised service account to see all files and sockets it has open
-p <pid>Show all files opened by a specific process ID—
+D <dir>Recursively list all processes with open files under the specified directoryUse on /var/www or /tmp to find processes actively reading or writing to those paths
-nDo not resolve hostnames — faster output, avoids DNS leaks during investigationAlways use -n during incident response to avoid alerting an attacker via reverse DNS lookups
-PDo not resolve port names — shows raw port numbers instead of service names—

Common Use Cases

Find Which Process Holds an Open Socket to an Unknown IP

When network monitoring detects unexpected outbound traffic, lsof -i TCP -s TCP:ESTABLISHED -n -P maps every active TCP connection to its owning process and full executable path. A connection to an unfamiliar IP from a process in /tmp or with a generic name is a strong indicator of a C2 channel.

lsof -i TCP -s TCP:ESTABLISHED -n -P

Detect Processes Holding Deleted Files Open

Malware commonly deletes its executable from disk after launching to hinder forensic recovery, but the process continues to run and the file descriptor remains open. lsof will show these as entries with (deleted) in the NAME column. The file contents can be recovered from /proc/<PID>/fd/<FD> while the process is still running.

lsof | grep deleted

Audit All Network Activity of a Specific Service Account

Service accounts should have predictable, limited network activity. Querying lsof by user shows every socket open under that account — revealing any unexpected outbound connections that might indicate a compromised service making data exfiltration calls.

lsof -u www-data -i -n -P

Security Relevance: Mapping Open File Descriptors to Detect Data Exfiltration

Data exfiltration and command-and-control channels both require an active network connection. lsof is the most direct tool for mapping those connections to the exact process responsible, including its full executable path and owning user. This is faster and more precise than correlating PID information from netstat or ss separately. The deleted file pattern is particularly important: sophisticated malware routinely deletes its binary from disk immediately after execution, leaving only the running process and an open file descriptor. Standard file-based scanners will not find the binary. lsof exposes it by showing the open descriptor with a (deleted) marker, and the file contents remain recoverable from the /proc filesystem as long as the process is alive. Run lsof as part of any incident triage alongside ps aux and netstat to build a complete picture of process, file, and network activity.

  • A process with an ESTABLISHED connection to a non-standard port and an executable path under /tmp is a high-confidence C2 indicator
  • Entries marked (deleted) in lsof output may be malware that erased its binary — recover via /proc/<PID>/fd/<FD> before killing the process
  • lsof without -n performs DNS lookups for each connection — this can alert an attacker monitoring their DNS logs during an investigation
  • Running lsof system-wide on a busy server produces thousands of lines — always filter with -i, -u, or -p to scope the output

Practical Examples

List all established TCP connections with process details

lsof -i TCP -s TCP:ESTABLISHED -n -P

Shows every active outbound and inbound TCP connection, the PID, the process name, the user, and the full remote address and port. Use this as the first network triage command during an incident.

Find and recover a deleted malware binary still running in memory

# Find the deleted file and its FD
lsof | grep deleted

# Recover the binary via /proc (replace PID and FD)
cp /proc/<PID>/fd/<FD> /tmp/recovered_binary

If lsof shows a process with a (deleted) executable, the binary contents are still accessible through the process’s /proc file descriptor entry. Copy it for forensic analysis before terminating the process.

Find all processes with open files in the web root

lsof +D /var/www/html

Lists every process with an open file descriptor pointing to anywhere under the web root. During a web compromise investigation, this shows which processes are actively reading or writing web application files.

Troubleshooting Common Issues

Problem: lsof output is extremely large and hard to navigate

Solution: Always filter with specific flags: -i for network only, -u <user> for a specific account, -p <pid> for a single process, or +D <dir> for a directory. Running bare lsof system-wide is rarely useful without a filter.

Problem: lsof shows no output for a process you know is running

Solution: Run lsof as root. Non-root users can only see file descriptors for processes they own. Many interesting security findings (malware running as root or other system users) are invisible without root access.

Problem: lsof is very slow on a system with many processes

Solution: Add -n -P to skip hostname and port name resolution. DNS lookups are the primary cause of lsof slowness. These flags make output faster and also avoid unintended network queries during a sensitive investigation.

Summary

lsof is the definitive tool for correlating network connections, open files, and file descriptors with the processes that own them. Its ability to expose deleted-but-running executables and map active sockets to exact process paths makes it indispensable for both data exfiltration detection and post-compromise forensics. Use it alongside ps aux and netstat as a core part of every incident triage workflow.

  • Use lsof -i TCP -s TCP:ESTABLISHED -n -P as the first network triage command — it maps every active connection to its owning process
  • Run lsof | grep deleted to find malware that erased its binary but is still running in memory
  • Always add -n -P to lsof commands during investigations to prevent DNS lookups that could alert an attacker

Is Your Linux Server Monitored 24/7?

INTRAM provides managed Linux hosting with continuous process and performance monitoring. We detect anomalies before they become incidents — so your team can focus on building, not firefighting.

Explore Managed Hosting

Let’s assess what your business actually needs.

We will use these details only to understand your request and reply appropriately.