How to Find Files by Minutes Modified in Ubuntu (find -mmin)

The Micro-Forensic Modification Audit

While the standard -mtime flag allows system administrators to search for files based on the number of days since they were last modified (written to), this metric is useless for rapid incident response. If you suspect an attacker has just edited a PHP configuration file on your Ubuntu server, or if you need to find log files that were updated during a crash that occurred five minutes ago, you need extreme precision. You must instruct the search engine to evaluate the modification timestamp at the minute level.

Using the find Command with -mmin

The Linux find command utilizes the -mmin flag (Modification Minute) to explicitly search for files based on the exact number of minutes that have elapsed since their data blocks were last altered.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /etc/ directory for any configuration files that have been modified in the last 10 minutes, type the following command exactly:
  3. find /etc/ -type f -mmin -10
  4. Press Enter.

Minute-Level Precision

The syntax utilizes a numeric integer representing minutes, prefaced by a mathematical operator. Using -10 means “less than 10 minutes ago” (highly useful for real-time security auditing). Conversely, using +120 would return files that have not been modified in over two hours. If you omit the plus or minus sign (e.g., -mmin 5), the command will mathematically restrict the search to files modified exactly 5 minutes ago. This flag is an absolute necessity for system administrators attempting to isolate exactly which files were altered during a highly specific timeframe.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.