1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1070.006 Timestomp — Detection Rules

Detection workspace for T1070.006 Timestomp: 5 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

  • File Time Attribute Change - Linux · test · medium · {"product":"linux","service":"auditd"}
  • Touch Suspicious Service File · test · medium · {"product":"linux","category":"process_creation"}
  • File Time Attribute Change · test · medium · {"product":"macos","category":"process_creation"}
  • Unauthorized System Time Modification · test · low · {"product":"windows","service":"security","definition":"Requirements: Audit Policy : System > Audit Security State Change, Group Policy : Computer Configuration\\Windows Settings\\Security Settings\\Advanced Audit Policy Configuration\\Audit Policies\\System\\Audit Security State Change"}
  • Powershell Timestomp · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}

Atlas deterministic concepts

T1070.006 Timestomp

MATCH(file_timestamp_change) AND timestamp_precedes_creation_or_differs_from_known_metadata -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0591 Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering

AN1626 Analytic 1626

Detects attempts to modify file timestamps via API usage (e.g., `SetFileTime`), CLI tools (e.g., `w32tm`, PowerShell), or double-timestomp behavior where $SI and $FN timestamps are mismatched or reverted.

AN1627 Analytic 1627

Detects use of timestamp-altering commands like `touch -a -m -t` or `touch -r`, particularly when executed by unusual users or in suspicious directories.

AN1628 Analytic 1628

Detects timestamp changes using `touch`, `SetFile`, or direct metadata tampering (e.g., xattr manipulation) from Terminal, scripts, or low-level APIs.

AN1629 Analytic 1629

Detects abuse of busybox commands (e.g., `touch`) or log timestamp tampering during backdoor persistence or evasion.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1070.006 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.