The Read-Only Audit
In Ubuntu Linux, tracking file modifications (when a file was edited) is standard practice. However, tracking file access (when a file was simply opened and read) is a highly specialized forensic technique. If you suspect an unauthorized user has infiltrated your server and is quietly reading your private database configuration files without actually modifying them, checking the “mtime” (modification time) will reveal absolutely nothing. To detect a silent data breach, you must instruct the Linux search engine to filter the file system strictly by the last time a file was opened or read.
Using the find Command with -atime -1
The Linux find command utilizes the -atime (access time) flag combined with a negative integer (-1) to locate files that were opened, read, or executed within the last one day (24 hours).
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To scan a specific secure directory (e.g.,
/var/secure_configs/) and return every file accessed in the last 24 hours, type the following command exactly: sudo find /var/secure_configs/ -type f -atime -1- Press Enter and provide your administrator password.
Detecting Silent Intrusion
Because you are auditing secure files, prefixing the command with sudo is mandatory. The search engine will recursively dig through the specified folder and output the absolute path of every file that was read within the 24-hour window. If you know for a fact that you have not logged into the server or run any backups in the last 24 hours, and this command suddenly returns a list of highly sensitive configuration files, you have instantly detected a silent read-only intrusion, allowing you to lock down the server immediately.