The Access Audit
In Ubuntu Linux, files have multiple timestamps. While the “modification time” tells you when a file was last edited, the “access time” tells you when a file was simply opened and read by a user or an application. This is incredibly useful for security audits. If you suspect an unauthorized user breached your server on a specific date (e.g., exactly three days ago), you can scan the filesystem to see exactly which text files, databases, or logs they opened and read during that 24-hour window, even if they didn’t alter any code.
Using the find Command with -atime
The standard Linux find command utilizes the -atime (Access Time) flag specifically for querying this read-only timestamp.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- Determine the directory you want to audit. For this example, we will check the
/home/directory to see what user files were accessed. - To find all files accessed exactly 3 days ago, type the following command:
sudo find /home/ -type f -atime 3- Press Enter and provide your administrator password.
Time Windows Explained
The -atime flag operates in strict 24-hour blocks. Using 3 means the file was accessed between 72 and 96 hours ago. You can modify this window by using mathematical prefixes:
- Less Than:
-atime -3will find any file accessed within the last 3 days (0 to 72 hours ago). - Greater Than:
-atime +3will find files that have not been accessed in over 3 days (older than 72 hours). This is the perfect command for finding ancient, unused files to safely delete or archive to free up server space.