Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

fsnoop

A tool to monitor file operations on GNU/Linux systems by using the Inotify mechanism. Its primary purpose is to help de

scannerRed Team
Official docs ↗

Platforms: Linux · Last verified September 6, 2026

A tool to monitor file operations on GNU/Linux systems by using the Inotify mechanism. Its primary purpose is to help detecting file race condition vulnerabilities and since version 3, to exploit them with loadable DSO modules (also called “payload modules” or “paymods”).

Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.

Getting started

Install on BlackArch with `pacman -S fsnoop` (or add the BlackArch repository to an existing Arch Linux install). See the official BlackArch tool listing linked above for details.

Commonly preinstalled on

BlackArch

Arch Linux-based distribution with one of the largest pentest tool repositories