Loading interactive filters…
1200KM / detection
T1547.003 Time Providers — Detection Rules
Detection workspace for T1547.003 Time Providers: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- New TimeProviders Registered With Uncommon DLL Name · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0122 Detect Abuse of Windows Time Providers for Persistence
AN0341 Analytic 0341
Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1547.003 simulation workspace
- File Creation · DC0039
- Module Load · DC0016
- Process Creation · DC0032
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.