$ ls -l /proc/$PID/exe
# 或
$ file /proc/$PID/exe
$ netstat -antlp | grep ESTABLISHED
$ netstat -antlp | grep LISTEN
$ ps aux | grep $PID | grep -v grep
$ ps -ef | awk '{print}' | sort -n | uniq >1
$ ls /proc | sort -n |uniq >2
$ diff 1 2
$ lsof -p [PID]
$ pwdx [PID]