How to Find Files by Specific User ID in Ubuntu (find -uid)

The Numeric Ownership Audit

When auditing file permissions on an Ubuntu Linux server, searching for files owned by a specific username (e.g., using -user root) is standard practice. However, if an account was recently deleted from the system, its text-based username no longer exists in the /etc/passwd file, but the orphaned files remain on the disk, tagged with the account’s raw numeric User ID (UID). If a malicious actor compromised an account (e.g., UID 1005), created a payload, and then you deleted the account, you must search the filesystem using that raw numeric identifier to locate the orphaned malware. You must instruct the search engine to bypass the username resolution layer and query the inode table directly.

Using the find Command with -uid

The Linux find command utilizes the -uid flag to perform a strict numerical ownership search.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To recursively scan the entire filesystem (starting at the root /) for any file owned by the exact numeric User ID 1005, type the following command exactly:
  3. sudo find / -type f -uid 1005
  4. Press Enter.

Raw Inode Filtering

The syntax utilizes a strict integer value (1005). The engine bypasses the system’s user resolution daemon entirely. It recursively scans every directory, reading the raw metadata block of every encountered file. If the 32-bit integer representing the owner exactly matches 1005, it is returned as a positive hit, completely regardless of whether that UID currently maps to a valid username. This command is an absolute necessity for system administrators performing forensic cleanup operations after purging compromised user accounts from the operating system.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.