How to Find Executable Files in Ubuntu Linux (find -executable)

The Executable Audit

In Ubuntu Linux, a file’s extension (like .sh or .exe) does not dictate whether the operating system is allowed to run it as a program. Instead, Linux relies entirely on a specific permission bit known as the “executable” flag. If you are auditing a directory for security risks—such as a user’s home folder or a public upload directory—you cannot simply search for script extensions. You must instruct the search engine to filter files based entirely on whether the operating system is physically permitted to execute them.

Using the find Command with -executable

The Linux find command utilizes the -executable flag to instantly isolate files that possess the execution permission bit.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the entire /tmp/ directory specifically for files that are allowed to run as programs, type the following command exactly:
  3. sudo find /tmp/ -type f -executable
  4. Press Enter and provide your administrator password.

Identifying Rogue Scripts

The /tmp/ directory is a notorious staging ground for malware because any user can write to it. By running the -executable search against public or temporary directories, you can instantly identify bash scripts, Python payloads, or compiled binaries that an attacker has dropped onto your server and marked as executable. Once identified, you can use the chmod -x command to revoke the permission or delete the files entirely.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.