How to Find Files Modified in the Last 15 Minutes in Ubuntu (find -mmin)

The Immediate Threat Audit

When responding to an active security incident on an Ubuntu Linux server, such as a malicious script that just executed or an unexpected application crash that occurred moments ago, you do not have time to parse through gigabytes of historical log data. You need to instantly identify every single file on the filesystem that was altered within the immediate temporal vicinity of the event. To achieve this, you must instruct the search engine to filter files based on a strict minute-by-minute countdown from the present moment.

Using the find Command with -mmin

The Linux find command utilizes the -mmin (modification minutes) flag to perform a highly granular, minute-based temporal filter.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /var/ directory (the standard location for system logs and application data) for any file modified strictly within the last 15 minutes, type the following command exactly:
  3. sudo find /var/ -type f -mmin -15
  4. Press Enter.

Minute-Level Temporal Targeting

The syntax utilizes a negative integer (-15). The engine first checks the current system clock down to the millisecond. It then recursively scans the target directory, extracting the exact modification timestamp (mtime) from the inode table of every encountered file. If the file’s mtime falls within the strict 15-minute window preceding the current system time, it is returned as a match. (Conversely, using +15 would find files older than 15 minutes). This command is an absolute necessity for incident responders attempting to rapidly isolate modified payloads or trace the exact files a rogue process touched just before it crashed.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.