The Numeric Ownership Audit
When auditing file permissions on an Ubuntu Linux server, searching for files owned by a specific username (e.g., using -user root) is standard practice. However, if an account was recently deleted from the system, its text-based username no longer exists in the /etc/passwd file, but the orphaned files remain on the disk, tagged with the account’s raw numeric User ID (UID). If a malicious actor compromised an account (e.g., UID 1005), created a payload, and then you deleted the account, you must search the filesystem using that raw numeric identifier to locate the orphaned malware. You must instruct the search engine to bypass the username resolution layer and query the inode table directly.
Using the find Command with -uid
The Linux find command utilizes the -uid flag to perform a strict numerical ownership search.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To recursively scan the entire filesystem (starting at the root
/) for any file owned by the exact numeric User ID1005, type the following command exactly: sudo find / -type f -uid 1005- Press Enter.
Raw Inode Filtering
The syntax utilizes a strict integer value (1005). The engine bypasses the system’s user resolution daemon entirely. It recursively scans every directory, reading the raw metadata block of every encountered file. If the 32-bit integer representing the owner exactly matches 1005, it is returned as a positive hit, completely regardless of whether that UID currently maps to a valid username. This command is an absolute necessity for system administrators performing forensic cleanup operations after purging compromised user accounts from the operating system.