1200KM / detection
T1070.006 Timestomp — Detection Rules
Detection workspace for T1070.006 Timestomp: 5 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- File Time Attribute Change - Linux · test · medium · {"product":"linux","service":"auditd"}
- Touch Suspicious Service File · test · medium · {"product":"linux","category":"process_creation"}
- File Time Attribute Change · test · medium · {"product":"macos","category":"process_creation"}
- Unauthorized System Time Modification · test · low · {"product":"windows","service":"security","definition":"Requirements: Audit Policy : System > Audit Security State Change, Group Policy : Computer Configuration\\Windows Settings\\Security Settings\\Advanced Audit Policy Configuration\\Audit Policies\\System\\Audit Security State Change"}
- Powershell Timestomp · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
Atlas deterministic concepts
T1070.006 Timestomp
MATCH(file_timestamp_change) AND timestamp_precedes_creation_or_differs_from_known_metadata -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0591 Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering
AN1626 Analytic 1626
Detects attempts to modify file timestamps via API usage (e.g., `SetFileTime`), CLI tools (e.g., `w32tm`, PowerShell), or double-timestomp behavior where $SI and $FN timestamps are mismatched or reverted.
AN1627 Analytic 1627
Detects use of timestamp-altering commands like `touch -a -m -t` or `touch -r`, particularly when executed by unusual users or in suspicious directories.
AN1628 Analytic 1628
Detects timestamp changes using `touch`, `SetFile`, or direct metadata tampering (e.g., xattr manipulation) from Terminal, scripts, or low-level APIs.
AN1629 Analytic 1629
Detects abuse of busybox commands (e.g., `touch`) or log timestamp tampering during backdoor persistence or evasion.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.