How to Find Files by Hard Link Count in Ubuntu (find -links)

The Hard Link Audit

In Ubuntu Linux, a “hard link” is a direct pointer to the physical inode (the actual data blocks) on the hard drive. Unlike a symbolic link (which is just a shortcut pointing to a file name), a hard link is indistinguishable from the original file. A file is only truly deleted from the disk when its hard link count reaches zero. If a malicious actor creates a hidden hard link to a massive database file, deleting the original database file will not actually free up any disk space. System administrators must routinely audit the filesystem to locate files with an abnormally high number of hard links.

Using the find Command with -links

The Linux find command utilizes the -links flag to explicitly search for files that possess a specific mathematical count of hard links.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /var/www/ directory and locate any file that possesses exactly two hard links, type the following command exactly:
  3. find /var/www/ -links 2
  4. Press Enter.

Link Count Forensics

The syntax requires an integer representing the exact number of links. You can also use comparative operators. For example, typing -links +2 will instruct the search algorithm to only return files that have strictly more than two hard links pointing to their inode. (Note: Directories in Linux inherently have a link count of at least two, plus one for every subdirectory they contain. Therefore, this command is almost always paired with -type f to restrict the search exclusively to regular files, ignoring directory structures entirely).

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.