How to Find Files by Inode Number in Ubuntu (find -inum)

The Inode Index

In Ubuntu Linux, the operating system does not actually identify files by their human-readable file names (like document.txt). Instead, the underlying file system assigns every single file a unique, numerical index called an “inode” (Index Node). The inode stores critical metadata: who owns the file, its exact size, and exactly where the data is physically located on the hard drive sector. When a system is compromised, hackers often create files with incredibly strange names (like a file named exactly " - " with spaces) that are impossible to delete using standard commands because the terminal misinterprets the spaces as command flags. To safely target and manipulate these corrupted files, you must bypass the name entirely and search strictly by the underlying inode number.

Using the find Command with -inum

The Linux find command utilizes the highly specialized -inum flag to locate files based exclusively on their numerical index identifier.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. First, you must determine the file’s inode number. Run ls -i in the directory containing the file. The number on the far left of the output is the inode.
  3. Once you have the number (for example, 1234567), type the following command exactly to find the file from the root directory:
  4. sudo find / -inum 1234567
  5. Press Enter and provide your administrator password.

Targeted Deletion

Because the find command locates the file using its raw file system identifier, it completely ignores the corrupted or malicious file name. Once the find command successfully locates the inode, you can append the -delete flag to instantly destroy the file without the Bash shell ever trying to read the dangerous file name: sudo find . -inum 1234567 -delete.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.