How to Find Files Accessed Exactly N Minutes Ago in Ubuntu (find -amin)

The Immediate Security Audit

In Ubuntu Linux, tracking file access times is critical for immediate security auditing. If you suspect an unauthorized user just accessed a highly sensitive configuration file (like /etc/shadow or an SSH key) while you were temporarily logged away from your terminal, you don’t need to know what happened yesterday; you need to know exactly what was read in the last 120 seconds. The Linux search engine features a dedicated, minute-level flag specifically for querying this volatile access data before it gets overwritten by normal system activity.

Using the find Command with -amin

The Linux find command utilizes the -amin flag (accessed minutes) to isolate files based on strictly defined 60-second historical windows regarding their read status.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the entire /etc/ directory and return files that were opened and read exactly 2 minutes ago, type the following command exactly:
  3. find /etc/ -type f -amin 2
  4. Press Enter.

The Precise Window

The integer provided to the -amin flag is highly specific. Because you omitted the plus or minus modifiers, you are instructing the search engine to look for files whose contents were read strictly within the 60-second block that occurred exactly 2 minutes prior to executing the command. If a hacker read the file 1 minute ago or 3 minutes ago, it will not appear in this specific output, allowing you to establish a highly accurate, minute-by-minute timeline of unauthorized access.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.