How to Find Files Newer Than a Reference File in Ubuntu (find -newer)

The Relative Timestamp Audit

When investigating a security breach or auditing a software deployment on an Ubuntu Linux server, searching for files based on absolute calendar dates (e.g., “files modified on Tuesday”) is often insufficient. If a malicious script was executed or a backup archive was extracted at a highly specific millisecond, you need to identify every single file modified after that exact event. Instead of manually converting calendar times into complex minute-offsets, you can use the event file itself as a temporal anchor, instructing the search engine to find files modified more recently than the anchor file’s timestamp.

Using the find Command with -newer

The Linux find command utilizes the -newer flag to perform a relative chronological comparison against a specified reference file.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. Assume you know a rogue script named payload.sh was executed. To scan the /var/www/html/ directory for any file modified after payload.sh was created or modified, type the following command exactly:
  3. sudo find /var/www/html/ -type f -newer /path/to/payload.sh
  4. Press Enter.

Chronological Indexing

The syntax relies on direct inode metadata extraction. The engine first reads the exact modification timestamp (mtime) of the reference file (payload.sh) down to the millisecond. It then recursively scans the target directory, comparing the mtime of every encountered file against that cached reference value. If a file’s timestamp is mathematically greater (closer to the present moment) than the reference, it is returned as a match. This command is an absolute necessity for forensic system administrators attempting to map the blast radius of a system event by identifying all files altered in its immediate aftermath.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.