This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Unauthorized System Time Modification
Original Source:
[Sigma source]
Title:
Unauthorized System Time Modification
Status:
test
Description:
Detect scenarios where a potentially unauthorized application or user is modifying the system time.
References:
-Private Cuckoo Sandbox (from many years ago, no longer have hash, NDA as well)
-Live environment caused by malware
-https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4616
Author:
@neu5ron
Date:
2019-02-05
modified:
2025-12-03
Tags:
-'attack.stealth'
-'attack.t1070.006'
Logsource:
product: windows
service: security
definition: Requirements: Audit Policy : System > Audit Security State Change, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\System\Audit Security State Change
Detection:
selection:
EventID
:
'4616'
filter_main_svchost:
ProcessName
:
'C:\Windows\System32\svchost.exe'
SubjectUserSid
:
'S-1-5-19'
filter_optional_vmtools:
ProcessName
:
-'C:\Program Files\VMware\VMware Tools\vmtoolsd.exe'
-'C:\Program Files (x86)\VMware\VMware Tools\vmtoolsd.exe'
-'C:\Windows\System32\VBoxService.exe'
-'C:\Windows\System32\oobe\msoobe.exe'
condition
:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-HyperV or other virtualization technologies with binary not listed in filter portion of detection
Level:
low