Skip to content

Hide Navigation Hide TOC

Unauthorized System Time Modification (faa031b5-21ed-4e02-8881-2591f98d82ed)

Detect scenarios where a potentially unauthorized application or user is modifying the system time.

Cluster A Galaxy A Cluster B Galaxy B Level
Unauthorized System Time Modification (faa031b5-21ed-4e02-8881-2591f98d82ed) Sigma-Rules Timestomp - T1070.006 (47f2d673-ca62-47e9-929b-1b0be9657611) Attack Pattern 1
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern Timestomp - T1070.006 (47f2d673-ca62-47e9-929b-1b0be9657611) Attack Pattern 2