The Dotfile Audit
In Ubuntu Linux, any file or directory whose name begins with a period (like .bashrc or .ssh/) is considered a “hidden” file. The operating system actively hides these from standard directory listings (ls without the -a flag) to keep home directories visually clean. However, malware and unauthorized rootkits frequently exploit this mechanic, hiding their payloads in dotfiles to evade casual inspection. When auditing a compromised user directory, you must explicitly instruct the search engine to isolate these hidden structures.
Using the find Command with -name “.*”
The Linux find command utilizes standard wildcard expansion with the -name flag to exclusively search for files that begin with a period.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the
/home/user/directory and return an exact list of every single hidden file and directory, type the following command exactly: find /home/user/ -name ".*"- Press Enter.
Targeted Unmasking
The syntax relies on the string ".*" wrapped in double quotes. The quotes are absolutely critical; they prevent the bash shell from prematurely expanding the asterisk before passing it to the find binary. This command forces the search engine to locate every item where the very first character is a period, followed by any string of characters. This provides system administrators with an instant, isolated manifest of all hidden configurations, SSH keys, and potentially obfuscated malicious scripts residing in a directory.