How to Find Files with Changed Metadata Exactly N Minutes Ago (find -cmin)

The Metadata Audit

In Ubuntu Linux, tracking file modifications is critical, but the standard -mmin flag only looks at changes to the actual contents of a file. However, if a malicious user alters a file’s ownership, changes its read/write permissions, or moves it to a new location without actually editing the data inside, the modification timestamp remains completely unchanged. To detect these covert administrative alterations, you must search based on the Change Time (ctime), which tracks modifications exclusively to the file’s inode metadata.

Using the find Command with -cmin

The Linux find command utilizes the -cmin (changed minutes) flag to search the filesystem based on exact, minute-by-minute metadata alterations.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the /etc/ directory for any files whose permissions or ownership were altered less than 10 minutes ago, type the following command exactly:
  3. sudo find /etc/ -type f -cmin -10
  4. Press Enter and provide your administrator password.

Granular Security Tracking

The syntax utilizes mathematical operators for absolute precision. Using a minus sign (-10) finds files whose metadata changed less than 10 minutes ago. Using a plus sign (+10) finds files whose metadata changed more than 10 minutes ago. If you omit the operator and simply type -cmin 10, the engine will exclusively return files whose permissions were altered exactly 10 minutes ago (a strict 60-second window). This surgical precision allows administrators to instantly detect unauthorized chmod or chown commands immediately after they are executed.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.