1200KM / simulation
T1070.006 Timestomp — Attack Simulation
Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files. In Windows systems, both the `$STANDARD_INFORMATION` (`$SI`) and `$FILE_NAME` (`$FN`) attributes record times in a Master File Table (MFT) file.…
Technique description
Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files. In Windows systems, both the `$STANDARD_INFORMATION` (`$SI`) and `$FILE_NAME` (`$FN`) attributes record times in a Master File Table (MFT) file.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Set a file's modification timestamp
Procedure 20ef1523-8758-4898-b5a2-d026cc3d2c52; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Set a file's access timestamp
Procedure 5f9113d5-ed75-47ed-ba23-ea3573d05810; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Modify file timestamps using reference file
Procedure 631ea661-d661-44b0-abdb-7a7f3fc08e50; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Event Log Manipulations- Time slipping via Powershell
Procedure 7bcf83bf-f5ef-425c-9d9a-71618ad9ed12; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Set a file's creation timestamp
Procedure 8164a4a6-f99c-4661-ac4f-80f5e4e78d2b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- MacOS - Timestomp Date Modified
Procedure 87fffff4-d371-4057-a539-e3b24c37e564; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Windows - Modify file creation timestamp with PowerShell
Procedure b3b2c408-2ff0-4a33-b89b-1cb46a9e6a9c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Windows - Timestomp a File
Procedure d7512c33-3a75-4806-9893-69abc3ccdd43; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Windows - Modify file last access timestamp with PowerShell
Procedure da627f63-b9bd-4431-b6f8-c5b44d061a62; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Windows - Modify file last modified timestamp with PowerShell
Procedure f8f6634d-93e1-4238-8510-f8a90a20dcf2; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.