↑ ↓ select, Enter open, Esc close

Find processes whose executable was deleted

root@server
ls -l /proc/*/exe 2>/dev/null | grep '(deleted)'

Checks the /proc/PID/exe link of every process and shows those whose executable was deleted. Malware likes to start from /tmp and then delete its file to attract less attention. The PID is part of the path, ps -fp PID shows details.

Note: After package updates, old versions of services often keep running and show up here as well. They disappear after the service is restarted.

Also searched as

  • find processes running deleted binary
  • proc exe deleted malware
  • detect fileless malware linux

Related one-liners

All in Security

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.