Cross-source coverage
T1099 / ATT&CK
Timestomp
ATT&CK has retired this technique. Rules still tag it; the current id is T1070.006 Indicator Removal: Timestomp.
1 rule across 1 source.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may take actions to hide the deployment of new, or modification of existing files to obfuscate their activities. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder. This is done, for example, on files that have been modified or created by the adversary so that they do not appear conspicuous to forensic investigators or file analysis tools. Timestomping may be used along with file name Masquerading to hide malware and tools.
- Tactics
- Stealth
- Platforms
- Linux · Windows · macOS
- Telemetry
- —
socfortress/Wazuh-Rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 2: A process changed a file creation time by · Timestomp (T1099) | Low | Wazuh XML |