How to Find Files with Status Changes Exactly N Days Ago in Ubuntu (find -ctime)

The Metadata Audit

In Ubuntu Linux, the operating system records a timestamp every time a file’s “status” changes (ctime). Unlike the modification time (mtime), which only updates when the actual contents of the file are edited, the ctime updates whenever the file’s metadata is altered. This includes changing the file’s owner, modifying its read/write permissions, or renaming it. If you suspect an unauthorized user altered the ownership permissions of critical server files exactly two days ago, you cannot rely on a standard content search; you must instruct the Linux search engine to filter files based exclusively on their metadata change history.

Using the find Command with -ctime

The Linux find command utilizes the -ctime flag (change time) to isolate files based on strictly defined 24-hour historical windows.

  1. Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
  2. To scan the /etc/ directory and return files whose permissions or ownership were altered exactly 2 days ago, type the following command exactly:
  3. find /etc/ -type f -ctime 2
  4. Press Enter.

The Precise Window

The integer provided to the -ctime flag does not mean “within the last 2 days.” By omitting the plus or minus modifiers, you are instructing the search engine to look for files whose metadata changed strictly within the 24-hour block that occurred between 48 hours and 72 hours prior to the exact moment you executed the command. This provides incredibly precise, surgical auditing capabilities for system administrators tracking down historical security events.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.