How to Find Files by Metadata Change Time in Ubuntu (find -ctime)

The Metadata Audit

When investigating a security incident or auditing a Linux server, checking when a file’s content was modified (-mtime) is often not enough. A sophisticated attacker might modify a file’s content but artificially spoof the modification timestamp to hide their tracks. However, it is much harder to spoof the “change time” (ctime), which tracks when the file’s metadata (such as its ownership, permissions, or inode information) was altered. If you want to find files where the permissions were recently escalated to root, you must search the metadata timestamp.

Using the find Command with -ctime

The Linux find command utilizes the -ctime flag to search the file system based on when the inode metadata was last altered, calculated in 24-hour blocks.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /etc/ directory and return every file whose permissions or ownership changed within the last 24 hours, type the following command exactly:
  3. sudo find /etc/ -type f -ctime -1
  4. Press Enter and provide your administrator password.

Tracking Permission Changes

Prefixing the command with sudo is mandatory, as normal users cannot read the metadata of secured system files. The minus sign (-1) tells the search engine to look for files whose metadata changed less than one day ago (within the last 24 hours). If you type -ctime +5, it will find files whose metadata changed more than 5 days ago. This is an incredibly powerful forensic tool: if a script quietly runs chmod 777 on a critical configuration file, the content modification time (mtime) will not change, but the ctime will update instantly, allowing this command to catch the security breach.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.