The Immediate Aftermath
If you are actively working on an Ubuntu Linux server and suddenly realize a critical configuration file has broken, or if you suspect a script just went rogue and started editing files without your permission, you need to execute an emergency audit of the immediate past. The standard -mtime command is useless here because it measures time in massive 24-hour blocks. When you need surgical precision—such as finding exactly which files were modified while you were away getting a cup of coffee over the last hour—you must switch to a minute-based search parameter.
Using the find Command with -mmin
The Linux find command utilizes the -mmin (Modified Minutes) flag specifically for tracking extremely recent file changes.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- Determine the directory you want to audit. For this emergency example, we will search the entire system (
/). - To find all files modified in the last 60 minutes, type the following command exactly:
sudo find / -type f -mmin -60- Press Enter and provide your administrator password.
Refining the Search Window
The minus sign (-60) is critical. It instructs the terminal to look backward from the current exact second to exactly 60 minutes ago. If you want to expand or contract the search window, simply change the number:
-mmin -15will find files modified in the last 15 minutes.-mmin +120(using a plus sign) will find files modified older than two hours ago, completely ignoring any files changed recently.
This command is the single most effective way to track down a misbehaving script that just ran on a cron schedule.