How to Find Files with Status Changes Exactly N Minutes Ago in Ubuntu (find -cmin)

The Immediate Privilege Audit

In Ubuntu Linux, tracking metadata changes (ctime) is just as important as tracking content changes. If a malicious script or an unauthorized user suddenly grants root-level execution privileges to a seemingly harmless text file, the file’s contents won’t change, but its “status” timestamp will update instantly. If you suspect a privilege escalation attack occurred just moments ago, waiting to search by “days” is entirely useless. You must instruct the Linux search engine to filter files based on metadata changes that happened within a strict, minute-by-minute window.

Using the find Command with -cmin

The Linux find command utilizes the -cmin flag (change minutes) to isolate files based on 60-second historical blocks regarding their metadata status.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /usr/bin/ directory and return files whose permissions or ownership were altered exactly 5 minutes ago, type the following command exactly:
  3. find /usr/bin/ -type f -cmin 5
  4. Press Enter.

The Precise Window

The integer provided to the -cmin flag is highly specific. Because you omitted the mathematical modifiers (like + or -), the search engine will exclusively hunt for files whose metadata changed strictly within the 60-second block that occurred exactly 5 minutes prior to executing the command. If a file’s permissions were altered 4 minutes ago or 6 minutes ago, it will be completely ignored, allowing you to build an incredibly precise timeline of a security breach.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.