Cross-source coverage

T1099 / ATT&CK

Timestomp

ATT&CK has retired this technique. Rules still tag it; the current id is T1070.006 Indicator Removal: Timestomp.

1 rule across 1 source.

1 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may take actions to hide the deployment of new, or modification of existing files to obfuscate their activities. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder. This is done, for example, on files that have been modified or created by the adversary so that they do not appear conspicuous to forensic investigators or file analysis tools. Timestomping may be used along with file name Masquerading to hide malware and tools.

Tactics
Stealth
Platforms
Linux · Windows · macOS
Telemetry

socfortress/Wazuh-Rules

1 rule
Detection Severity Format
Sysmon - Event 2: A process changed a file creation time by · Timestomp (T1099) Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.