How to Find Files by Minutes Accessed in Ubuntu (find -amin)

The Micro-Forensic Audit

While the standard -atime flag allows system administrators to search for files based on the number of days since they were last accessed, this metric is far too broad for active incident response. If you suspect a malicious script executed on your Ubuntu server within the last hour, or if you are debugging a rapid-fire cron job that is touching configuration files every few minutes, you need micro-forensic precision. You must instruct the search engine to evaluate the access timestamp at the minute level.

Using the find Command with -amin

The Linux find command utilizes the -amin flag (Access Minute) to explicitly search for files based on the exact number of minutes that have elapsed since they were last opened or read.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /var/www/ directory for any files that have been accessed in the last 15 minutes, type the following command exactly:
  3. find /var/www/ -type f -amin -15
  4. Press Enter.

Minute-Level Precision

The syntax utilizes a numeric integer representing minutes, prefaced by a mathematical operator. Using -15 means “less than 15 minutes ago” (highly useful for real-time debugging). Conversely, using +60 would return files that have not been accessed in over an hour. If you omit the plus or minus sign (e.g., -amin 30), the command will mathematically restrict the search to files accessed exactly 30 minutes ago. This flag is an absolute necessity for developers tracking down high-speed read operations in rapidly changing file systems.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.