Linux lsblk Command Cheat Sheet: Identify Disks, USB Drives and Encrypted Volumes Like a SOC Analyst
A junior analyst on a night shift gets a ticket: a contractor plugged an unknown USB drive into a Linux jump host. Another responder, in a hurry, runs a disk operation against /dev/sdb, assuming it is the USB stick. It is actually a secondary data volume. Nobody lost data to an attacker that night. A wrong device name did the damage.
Mistakes like this are why lsblk is one of the first commands I run in Linux incident response and digital forensics work. It is read-only and fast, and it shows how storage is laid out right now. This guide covers the commands you will actually use, what each column means, and how to apply them to endpoint security and USB triage.
Table of Contents
- What lsblk Does and Why Defenders Care
- Core lsblk Commands
- Useful Columns for Investigations
- Real-World Scenario: USB Triage on a Linux Host
- Verifying Targets Before Forensic Imaging
- Spotting Encrypted and LVM Volumes
- JSON Output and Automation
- Filtering Output the Right Way
- Common Misconceptions
- Detection and Prevention Tips
- Expert Tips
- FAQ
What lsblk Does and Why Defenders Care
According to the util-linux documentation, lsblk lists information about block devices. It reads from the sysfs filesystem and the udev database, which means it does not need root privileges for most output. It shows disks, partitions, loop devices, LVM logical volumes, and encrypted mappings in a tree.
For SOC teams this matters for three reasons:
- Safety: you can confirm exactly which device you are about to touch.
- Visibility: removable media, unexpected disks, and encrypted containers show up quickly.
- Low footprint: a read-only command is a sensible first step on a system you are investigating.
Core lsblk Commands
Start with the default view. It shows name, major:minor numbers, removable flag, size, read-only flag, type, and mount point.
lsblk
Expected output: a tree such as sda with children sda1 and sda2, plus any loop devices.
| Command | What it does | When to use it |
lsblk -f | Shows filesystem type, label, UUID, and mount points | Identifying a USB drive or checking a disk before any destructive work |
lsblk -p | Prints full device paths such as /dev/sda1 | Copying exact paths into notes or scripts |
lsblk -pf | Full paths plus filesystem details | A good default for evidence notes |
lsblk -d | Top-level disks only, no partitions | Quick hardware inventory |
lsblk -a | Includes empty and otherwise hidden devices | Seeing devices the default view omits |
lsblk -r | Raw output, no tree formatting | Piping to grep, awk, or other tools |
lsblk -m | Shows owner, group, and permission mode of device nodes | Checking who can access a device |
lsblk /dev/sdb | Shows one device and its children | Focusing on a single suspect drive |
Useful Columns for Investigations
The -o option lets you pick exactly which columns to show. This is where lsblk becomes an investigation tool.
lsblk -o NAME,MAJ:MIN,SIZE,FSTYPE,LABEL,UUID,MOUNTPOINTS
This gives a complete storage overview. Note that the MOUNTPOINTS column (plural) appears in newer util-linux releases. On older systems, use MOUNTPOINT instead.
| Command | Why it helps |
lsblk -o NAME,SIZE,TYPE | Separates disks, partitions, loops, and LVM volumes |
lsblk -o NAME,RM,SIZE,TYPE,MOUNTPOINTS | The RM column flags removable devices |
lsblk -o NAME,TRAN,SIZE,FSTYPE,MOUNTPOINTS | TRAN shows the transport: usb, sata, nvme, and so on, when available |
lsblk -o NAME,VENDOR,MODEL,SIZE | Identifies the hardware by vendor and model |
lsblk -o NAME,SERIAL,SIZE | Records serial numbers for chain-of-custody notes, where available |
lsblk -o NAME,WWN,SIZE | Shows World Wide Name identifiers when the device reports them |
lsblk -o NAME,PARTUUID,UUID,FSTYPE | Distinguishes partition UUIDs from filesystem UUIDs |
lsblk -d -o NAME,SIZE,MODEL,SERIAL | One line per physical disk with identifying details |
Some fields come back empty. Virtual machines, USB bridges, and certain controllers do not report serial or vendor data, so a blank value is not proof of anything suspicious.
Real-World Scenario: USB Triage on a Linux Host
Say a monitoring alert reports a new USB mass-storage device on a Linux workstation. Before anyone mounts it, take a snapshot of what the system sees:
lsblk -p -o NAME,TRAN,RM,SIZE,VENDOR,MODEL,SERIAL,FSTYPE,LABEL,UUID,MOUNTPOINTS
Here is how I read the result:
- TRAN = usb and RM = 1: consistent with removable USB storage.
- MOUNTPOINTS empty: the device is attached but not mounted. This is good, because nothing has been auto-opened.
- MOUNTPOINTS populated: a desktop auto-mount may already have happened, so note the path.
- FSTYPE: vfat, exfat, ntfs, ext4, or crypto_LUKS tells you what you are dealing with.
Save the output as a record of what the device looked like on arrival:
lsblk -pf > block-devices.txt
This writes to a file in the current directory. Use a location that is not on the evidence device, and do not overwrite an existing file you need.
If a udev event is still being processed and the layout looks incomplete, wait for it to finish and check again:
sudo udevadm settle; lsblk
Verifying Targets Before Forensic Imaging
In forensic work, the most costly error is acquiring from, or writing to, the wrong device. Two habits help:
- Run
lsblk -pfbefore you start and again right before the operation. - Match size, model, and serial against your case notes, not just the device name.
Warning: device names like /dev/sda and /dev/sdb are assigned at detect time and can change after a reboot or when devices are attached in a different order. Never rely on a name remembered from earlier. For anything destructive, such as partitioning or formatting, verify the target immediately before running the command. Use a hardware write blocker for evidence media wherever your procedures call for one.
To inspect a single device or partition:
lsblk /dev/sdb
lsblk -f /dev/sdb1
Recent util-linux versions also show filesystem usage columns with -f. If yours does not, df -h reports usage for mounted filesystems.
Spotting Encrypted and LVM Volumes
When you review endpoint security posture on Linux servers, you want to know whether data at rest is encrypted. lsblk -f helps here.
lsblk -f
- A partition with FSTYPE
crypto_LUKSis a LUKS-encrypted container. - An unlocked container appears as a child device of type
crypt, usually with its own filesystem and mount point. - FSTYPE
LVM2_membermarks a physical volume, with logical volumes shown beneath it.
For a clearer hierarchy, use:
lsblk -o NAME,TYPE,SIZE,FSTYPE,MOUNTPOINTS
This tells you at a glance whether the root filesystem sits on LVM, on LUKS, or directly on a partition. An unencrypted data volume on a laptop or removable drive is the kind of gap auditors and cyber insurance questionnaires tend to ask about.
JSON Output and Automation
For scripts and SOC automation, lsblk can emit JSON:
lsblk -J -o NAME,SIZE,TYPE,FSTYPE,MOUNTPOINTS
lsblk -J -f
You can feed this into jq or a log pipeline. For example, a scheduled job can record the storage layout of a server and flag a new disk or removable device when the snapshot changes. Treat this as one signal among many, since legitimate maintenance also changes storage.
Filtering Output the Right Way
Exclude loop devices, which are common on systems with snap packages. Major number 7 is the loop driver:
lsblk -e 7
Show only devices with a given major number. Major 8 is typically SCSI/SATA/USB disks (sd*):
lsblk -I 8
Physical disks only, filtered for NVMe:
lsblk -d -o NAME,SIZE,MODEL | grep nvme
List partitions by filtering on type:
lsblk -o NAME,SIZE,TYPE | grep part
Tree characters can interfere with text filtering, so add -r for raw output when parsing. A quick way to show only entries that have a mount point:
lsblk -r -o NAME,SIZE,FSTYPE,MOUNTPOINTS | awk 'NF>=4'
Note that filtering with grep -v '^$' only removes blank lines. It does not limit the list to mounted devices. If a partition has no filesystem, fields shift, so check the results rather than trusting them blindly.
Common Misconceptions
-tis not "tree view." Tree output is the default. Per the man page,-t(--topology) shows topology columns such as alignment, I/O sizes, and scheduler. Use it for performance troubleshooting, not layout.-his help. It does not make sizes human-readable. Sizes are already shown in human-readable form by default, and-bprints bytes.lsblk -fdoes not prove a device is safe. It only describes what is visible. Contents still need to be examined in a controlled way.lsblkalone does not show hidden data or tampering. It reports the block layer, not file contents.
Detection and Prevention Tips
- Control USB use: apply USB device control policies (for example, udev rules or endpoint tooling) so unknown removable storage is blocked or logged.
- Disable auto-mount on servers: a plugged-in device should never mount itself on a production host.
- Log device events: review kernel and udev logs, and your EDR or SIEM, for new storage attach events. On systemd systems,
journalctl -kshows kernel messages about attached devices. - Encrypt portable data: LUKS on laptops and removable media reduces exposure if a device is lost.
- Baseline storage layouts: keep a known-good
lsblk -Jsnapshot per server class and compare during audits. - Follow your data-handling policy: frameworks like NIST guidance on media protection are a useful reference, but check them against your own compliance requirements.
None of these measures guarantees protection on its own. They work best layered.
Expert Tips
- Use
-pin anything you paste into a ticket, so no one has to guess the path. - Use
-owith a fixed column list in scripts. Default columns can differ between distributions and versions. - Add
-nto drop the header line when parsing output. - Check
lsblk --helporman lsblkon the exact system you are on. Available columns vary with the util-linux version. - Run
lsblktwice, before and after attaching a device, and compare. It is the simplest way to be sure which device is new.
Related Cybersecurity Topics You Should Explore
- Linux umount Command Cheat Sheet: Safe Unmount Without Data Loss
- Linux Mount Commands Cheat Sheet: Secure Mounts (2026)
- Linux du Command Cheat Sheet: Find Disk Space Hogs Fast
- Linux df Command Cheat Sheet: Fix Full Disk & Missing Logs
- Linux Disk Commands Cheat Sheet: df, du, mount, fsck (2026)
- Linux umask Cheat Sheet: 022 vs 027 vs 077 Explained
- Linux chgrp Cheat Sheet (2026): Commands, Examples & Audit Tips
- Linux chown Command Cheat Sheet: 40+ Examples (2026)
- Linux chmod Cheat Sheet: Stop Using 777 (Safer Fixes)
- OnePlus 15 Root Exploit: Zero-Permission Apps Can Take Full Control
- One Misconfigured chmod Command Gave Attackers Root Access
FAQ
What does lsblk stand for?
"List block devices." It shows disks, partitions, loop devices, and logical volumes.
Do I need sudo to run lsblk?
Usually not. It reads sysfs and the udev database. Some details, such as certain filesystem fields, may be limited for unprivileged users depending on your system.
How do I find out which device is my USB drive?
Run lsblk -o NAME,TRAN,RM,SIZE,MODEL,MOUNTPOINTS before and after plugging it in. The new entry with TRAN of usb is your drive.
How can I tell if a partition is encrypted?
Run lsblk -f and look for FSTYPE crypto_LUKS. An unlocked volume appears below it as a device of type crypt.
What is the difference between lsblk and fdisk -l?
lsblk gives a readable tree with mount and filesystem context. fdisk -l focuses on partition tables and typically needs root.
How do I get lsblk output for a script?
Use lsblk -J for JSON or lsblk -r for raw text, and choose your columns with -o.
Why are there so many loop devices?
Loop devices back things like snap packages and mounted image files. Hide them with lsblk -e 7.
Does lsblk modify anything?
No. It only reads information, which makes it a safe first command on a system under investigation.
Conclusion
lsblk is a small command with outsized value for anyone doing Linux incident response or day-to-day system administration. It answers the questions that matter before you act: what is attached, how it is laid out, what filesystem it holds, whether it is encrypted, and where it is mounted. In the opening story, one extra look at the output would have prevented the mistake.
Make lsblk -pf a reflex before you mount, image, or format anything, and save the output into your case notes.
Analysis based on SOC monitoring experience and review of public util-linux documentation.
