How to Find Files by Specific Date in Ubuntu (find -newermt)

The Temporal Parsing Audit

When investigating a security breach or analyzing a software deployment on an Ubuntu Linux server, searching for files based on generic relative timeframes (e.g., “files modified in the last 24 hours” using -mtime -1) is often too vague. If you know exactly when an attacker penetrated the system (e.g., October 15, 2023), you need the ability to search the filesystem using absolute human-readable dates. The standard find command can handle this, but it requires a specialized flag that allows the engine to parse strict calendar strings and compare them directly against the files’ internal timestamp metadata.

Using the find Command with -newermt

The Linux find command utilizes the -newermt (newer than modification time) flag to perform strict, absolute date-based searches.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To recursively scan the /var/www/ directory for any files that were modified on or after a specific absolute date (e.g., October 15, 2023), type the following command exactly:
  3. sudo find /var/www/ -type f -newermt "2023-10-15"
  4. Press Enter.

Absolute Date Boundaries

The syntax utilizes a strictly formatted date string ("2023-10-15"). The engine internally converts this human-readable calendar date into a raw UNIX epoch timestamp. It then recursively scans the target directory, reading the modification time (mtime) block of every encountered file. If the file’s raw timestamp is mathematically greater than (newer than) the epoch value of the provided date, it is returned as a positive hit. This command is an absolute necessity for security forensic teams attempting to isolate maliciously modified payloads that were dropped on a highly specific calendar day.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.