How to Find Files Modified in the Last 24 Hours in Ubuntu (find -mtime -1)

The Immediate Security Audit

In Ubuntu Linux, responding to a security incident or debugging a broken deployment requires rapidly identifying exactly what changed in the immediate past. If a website suddenly stops working or a database crashes, finding out which configuration files or log files were altered within the last 24 hours is the fastest way to pinpoint the problem. Instead of manually checking timestamps on hundreds of folders using ls -l, you must instruct the Linux search engine to filter the entire file system strictly by modification date.

Using the find Command with -mtime -1

The Linux find command utilizes the -mtime (modification time) flag combined with a negative integer (-1) to search for files that were modified less than one day (24 hours) ago.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /etc/ directory and return every file modified in the last 24 hours, type the following command exactly:
  3. sudo find /etc/ -type f -mtime -1
  4. Press Enter and provide your administrator password.

Rapid Troubleshooting

Because you are searching the system configuration folder (/etc/), prefixing the command with sudo is recommended. The search engine will recursively dig through all subdirectories and output the absolute path of every file that was edited or created within the 24-hour window. The minus sign (-) is critical; typing -mtime 1 (without the minus) searches for files modified exactly 24 to 48 hours ago. By using -1, you instantly generate a comprehensive audit trail of every immediate change, allowing you to rapidly undo a broken configuration edit or spot a newly dropped malicious script.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.