How to Find Files Modified in the Last 24 Hours in Ubuntu (find -mtime -1)

The Daily Security Audit

In Ubuntu Linux, monitoring the filesystem for recent, unauthorized changes is a core principle of server security. If a vulnerability was exploited overnight, or if a junior developer accidentally deployed code to the wrong directory, you need a way to instantly generate a manifest of every single file that was modified during that specific time window. Searching manually is impossible. You must explicitly instruct the search engine to filter files based on a 24-hour mathematical delta.

Using the find Command with -mtime -1

The Linux find command utilizes the -mtime flag (Modification Time) combined with a negative integer to search for files altered less than a specific number of days ago.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the /var/www/html/ directory for any file that was changed or updated within the last 24 hours, type the following command exactly:
  3. sudo find /var/www/html/ -type f -mtime -1
  4. Press Enter and provide your administrator password.

Time Delta Forensics

The syntax utilizes the -1 operator. The -mtime flag calculates time in 24-hour blocks. By specifying a negative one (-1), you are telling the engine: “Return files where the modification time is mathematically less than one 24-hour block away from the current system clock.” This command allows administrators to instantly isolate the exact files that were altered during an overnight shift or immediately following a suspected server breach, dramatically narrowing the scope of the investigation.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.