The Immediate Aftermath
If you just installed a new software package on your Ubuntu server, or if you suspect a hacker recently breached the system, you need to instantly identify what files were created or modified in the immediate past. Searching by days (using -mtime) is far too broad for an incident response. You need to narrow the search window down to a specific number of minutes to isolate the exact configuration changes or malicious scripts that were deployed moments ago.
Using the find Command with -cmin
The Linux find command utilizes the -cmin (change status minutes) flag to search the file system based on exact minute intervals, rather than 24-hour blocks.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To scan the entire server (
/) and return every file whose metadata was changed within the last 60 minutes, type the following command exactly: sudo find / -type f -cmin -60- Press Enter and provide your administrator password.
Minutes vs. Days
Prefixing the command with sudo is mandatory to scan system directories. The minus sign (-60) is critical: it tells the search engine to look for files changed less than 60 minutes ago. If you omitted the minus sign (60), it would look for files changed exactly 60 minutes ago. You can combine this flag with other filters to create highly specific security audits. For example, typing sudo find /etc/ -type f -cmin -15 will instantly reveal any core network or system configuration files that were silently altered in the last 15 minutes, allowing you to rapidly undo damaging changes.