Unauthorized System Time Modification

 Original Source: [Sigma source]
Title: Unauthorized System Time Modification
Status: test
Description:Detect scenarios where a potentially unauthorized application or user is modifying the system time.
References:
  -Private Cuckoo Sandbox (from many years ago, no longer have hash, NDA as well)
  -Live environment caused by malware
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4616
Author: @neu5ron
Date: 2019-02-05
modified:2025-12-03
Tags:
  • -'attack.stealth'
  • -'attack.t1070.006'
Logsource:
  • product: windows
  • service: security
  • definition: Requirements: Audit Policy : System > Audit Security State Change, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\System\Audit Security State Change
Detection:
  selection:
    EventID: '4616'
  filter_main_svchost:
    ProcessName: 'C:\Windows\System32\svchost.exe'
    SubjectUserSid: 'S-1-5-19'
  filter_optional_vmtools:
    ProcessName:
      -'C:\Program Files\VMware\VMware Tools\vmtoolsd.exe'
      -'C:\Program Files (x86)\VMware\VMware Tools\vmtoolsd.exe'
      -'C:\Windows\System32\VBoxService.exe'
      -'C:\Windows\System32\oobe\msoobe.exe'

  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -HyperV or other virtualization technologies with binary not listed in filter portion of detection
Level: low