How to Find Files Accessed Exactly N Days Ago in Ubuntu

The Access Audit

In Ubuntu Linux, files have multiple timestamps. While the “modification time” tells you when a file was last edited, the “access time” tells you when a file was simply opened and read by a user or an application. This is incredibly useful for security audits. If you suspect an unauthorized user breached your server on a specific date (e.g., exactly three days ago), you can scan the filesystem to see exactly which text files, databases, or logs they opened and read during that 24-hour window, even if they didn’t alter any code.

Using the find Command with -atime

The standard Linux find command utilizes the -atime (Access Time) flag specifically for querying this read-only timestamp.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. Determine the directory you want to audit. For this example, we will check the /home/ directory to see what user files were accessed.
  3. To find all files accessed exactly 3 days ago, type the following command:
  4. sudo find /home/ -type f -atime 3
  5. Press Enter and provide your administrator password.

Time Windows Explained

The -atime flag operates in strict 24-hour blocks. Using 3 means the file was accessed between 72 and 96 hours ago. You can modify this window by using mathematical prefixes:

  • Less Than: -atime -3 will find any file accessed within the last 3 days (0 to 72 hours ago).
  • Greater Than: -atime +3 will find files that have not been accessed in over 3 days (older than 72 hours). This is the perfect command for finding ancient, unused files to safely delete or archive to free up server space.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.