The Timeline Audit
In Ubuntu Linux, timestamps are a critical forensic tool. If you discover that a server was hacked early this morning, or if a rogue background script suddenly corrupted your database overnight, you do not want to search through millions of ancient system files. You need to instantly isolate every single file on the hard drive that was altered within the exact timeframe of the incident. To accomplish this, you must instruct the Linux search engine to filter files strictly by their modification date.
Using the find Command with -mtime
The Linux find command utilizes the -mtime (Modification Time) flag to search the filesystem based on 24-hour blocks.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire
/var/www/directory for any files that were modified within the last 24 hours, type the following command exactly: sudo find /var/www/ -type f -mtime 0- Press Enter and provide your administrator password.
Understanding the Zero
The 0 is often confusing for beginners, but it is the secret to this command. The -mtime flag counts backward in 24-hour increments. Therefore, a value of 0 means “files modified between right now and exactly 24 hours ago.” If you wanted to find files modified between 24 and 48 hours ago, you would use -mtime 1. If you want to find files modified more than 3 days ago, you add a plus sign: -mtime +3. This allows you to pinpoint exact timestamps during a forensic investigation.