How to Find Files Modified in the Last 24 Hours in Ubuntu Linux

The Timeline Audit

In Ubuntu Linux, timestamps are a critical forensic tool. If you discover that a server was hacked early this morning, or if a rogue background script suddenly corrupted your database overnight, you do not want to search through millions of ancient system files. You need to instantly isolate every single file on the hard drive that was altered within the exact timeframe of the incident. To accomplish this, you must instruct the Linux search engine to filter files strictly by their modification date.

Using the find Command with -mtime

The Linux find command utilizes the -mtime (Modification Time) flag to search the filesystem based on 24-hour blocks.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To search the entire /var/www/ directory for any files that were modified within the last 24 hours, type the following command exactly:
  3. sudo find /var/www/ -type f -mtime 0
  4. Press Enter and provide your administrator password.

Understanding the Zero

The 0 is often confusing for beginners, but it is the secret to this command. The -mtime flag counts backward in 24-hour increments. Therefore, a value of 0 means “files modified between right now and exactly 24 hours ago.” If you wanted to find files modified between 24 and 48 hours ago, you would use -mtime 1. If you want to find files modified more than 3 days ago, you add a plus sign: -mtime +3. This allows you to pinpoint exact timestamps during a forensic investigation.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.