How to Find Files by Specific Inode Number in Ubuntu (find -inum)

The Corrupt Filename Audit

When managing an Ubuntu Linux server, you will occasionally encounter files with severely corrupted, unprintable, or maliciously crafted filenames (e.g., a file named with raw control characters or spaces that breaks standard rm or mv commands). Because you cannot easily type the filename into a terminal, standard search and manipulation methods fail. To interact with these ghost files, you must bypass the human-readable filename entirely and interact directly with the file’s underlying filesystem identifier: the inode number.

Using the find Command with -inum

The Linux find command utilizes the -inum (inode number) flag to perform a highly specific search targeting a raw filesystem data structure.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. First, use ls -i in the suspected directory to reveal the inode number of the corrupt file (e.g., 1458922).
  3. To execute a targeted search across the current directory and immediately delete the exact file tied to that inode, type the following command exactly:
  4. sudo find . -inum 1458922 -delete
  5. Press Enter.

Raw Metadata Targeting

The syntax utilizes a strict integer value (1458922). The engine completely ignores the textual filename string layer. It recursively scans the specified directory, reading the raw metadata block of every encountered file. If the internal inode reference number matches the specified integer, it is returned as a positive hit. This command is an absolute necessity for system administrators performing forensic cleanup operations, allowing them to precisely target and eradicate maliciously named payloads or corrupted data blocks that standard text-based tools cannot parse.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.