How to Find Files Owned by a Specific User But Not a Specific Group in Ubuntu (find -not)

The Security Misconfiguration Audit

In Ubuntu Linux environments running complex multi-tenant applications, it is common for a specific user (like jenkins or www-data) to create files. However, security protocols often mandate that these files immediately inherit a highly restricted group ownership (like deploy_restricted). If a script fails, the user might create files that fall back to their default primary group. To audit this security misconfiguration, you cannot simply search for the user; you must search for the user exclusive of the mandated group. You must find the files that violate the policy.

Using the find Command with -user and -not -group

The Linux find command allows you to chain a positive ownership filter (-user) with a strictly negative group filter (-not -group) to isolate configuration failures.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /opt/app/ directory and return only the files that are owned by the deploy user, but which are absolutely NOT owned by the security_team group, type the following command exactly:
  3. find /opt/app/ -type f -user deploy -not -group security_team
  4. Press Enter.

Strict Logical Negation

The command utilizes the -not operator (which can also be written as ! in some shells) directly before the -group criteria. The engine first locates every file owned by the deploy user. It then evaluates the group ownership of that subset. If the group is security_team, the file is instantly dropped from the results. The final output consists strictly of files owned by deploy that have leaked into another group context. This compound negative syntax is an absolute necessity for security administrators conducting automated compliance sweeps.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.