Command library / stat
stat
Show a file's metadata and timestamps
Prints everything the filesystem knows about a file except its contents: size, owner, permissions, inode, and three timestamps. Modify is when the content last changed; Change is when the metadata last changed (permissions, owner, links); Access is when it was last read. In an investigation they help build the timeline: a Change time newer than Modify usually means the permissions or ownership were altered after the content was written.
Practice statUsage
Options and flags
filethe file(s) to describe
-c, --formatFORMATprint only the fields you ask for, e.g. %y (last modification) or %U (owner)
-L, --dereferencefollow a symbolic link and describe the file it points to
-t, --terseall fields on one line, for scripts
Examples
stat /etc/passwdOwner, permissions, size and all three timestamps.
stat -c %y /var/log/auth.logOnly the time the content was last modified.
stat -L /usr/bin/python3Describe the real file behind a symbolic link.
Common mistakes
-c takes a format first; here it swallows the path as the format and has no file left to describe.