How to Find Files Accessed Exactly N Days Ago (find -atime)

The Access Audit

In Ubuntu Linux, files track three distinct timestamps: modified, changed, and accessed. When performing an audit to determine if an unauthorized user has been secretly reading (but not modifying) sensitive payroll documents, you cannot use standard modification flags. You must explicitly instruct the search engine to look at the “Access Time” (atime), which updates every single time a file is opened, read, or executed, even if its contents remain perfectly intact.

Using the find Command with -atime

The Linux find command utilizes the -atime flag to search the filesystem based on when a file was last read, measured in 24-hour increments.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the /srv/financials/ directory for any files that were opened and read exactly 3 days ago, type the following command exactly:
  3. sudo find /srv/financials/ -type f -atime 3
  4. Press Enter and provide your administrator password.

Targeted Forensics

The syntax utilizes a strict 24-hour block system. By providing the exact integer 3 without a plus or minus operator, the search engine calculates the time exactly 72 hours ago (3 x 24), and creates a 24-hour window from that point. It will only return files that were opened within that specific historical day. This allows administrators to accurately cross-reference file access times with network login logs, instantly identifying which documents were compromised during a specific unauthorized session.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.