The Folder Audit
When investigating a security incident or tracking down a rogue application on an Ubuntu Linux server, searching for recently modified files can sometimes be overwhelming, returning thousands of log files and cache entries. If you are specifically trying to locate which major system folders or project directories have had their internal structures altered recently (such as a new folder being created or deleted inside them), you must instruct the Linux search engine to exclusively filter for directories based on their modification timestamp.
Using the find Command with -type d and -mtime
The Linux find command utilizes the -type d (directory) flag combined with the -mtime (modification time) flag to isolate recently altered folders.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire
/var/directory for exclusively folders that have had their contents modified within the last 24 hours, type the following command exactly: sudo find /var/ -type d -mtime -1- Press Enter and provide your administrator password.
Refining the Search
Because the -mtime flag counts in 24-hour blocks, it can sometimes be too broad. If you know a suspicious application was installed exactly three hours ago, you can swap the flag to -mmin (modification minutes). For example, running sudo find /etc/ -type d -mmin -180 will instantly output a list of system configuration directories that have been altered within the last 180 minutes, providing a highly precise timeline of recent structural changes on your server.