How to Find Files Changed Exactly N Days Ago in Ubuntu (find -ctime)

The Metadata Modification Audit

When auditing an Ubuntu Linux server after a suspected security breach, simply checking when a file’s content was last modified (using -mtime) is insufficient. An attacker might change a file’s permissions (making a script executable) or alter its ownership (assigning it to root) without actually altering the text inside the file itself. To track these structural security changes, you must audit the file’s Change Time (ctime), which records exactly when the file’s metadata or inode information was altered.

Using the find Command with -ctime

The Linux find command utilizes the -ctime flag to explicitly isolate files based on the exact number of days that have elapsed since their metadata was last modified.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /bin/ directory for system binaries whose permissions or ownership were changed exactly 3 days ago, type the following command exactly:
  3. sudo find /bin/ -type f -ctime 3
  4. Press Enter.

Absolute Temporal Precision

Unlike -mtime (content) or -atime (access), -ctime cannot be easily spoofed by the touch command without root-level system clock manipulation. By omitting the + or - operators (e.g., just using 3), the command engine mathematically restricts the search to files whose metadata changed exactly between 72 and 96 hours ago. This command is an absolute necessity for security analysts attempting to build a precise timeline of an attacker’s privilege escalation activities across the filesystem.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.