ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: AF021
  • Created: 07th April 2025
  • Updated: 07th April 2025
  • Platform: Windows
  • Contributor: David Larsen

Windows System Time Modification

The subject modifies the Windows system time in an attempt to obscure the timestamps of any system artifacts that may provide value to investigators.

Prevention

ID Name Description
PV043Restrict Windows System Time Modification

Using Group Policy on Windows it is possible to block the ability for users to modify the system date/time.

 

In the Group Policy Editor, navigate to:
Computer Configuration -> Windows Settings -> Security Settings → Local Policies → User Rights Assignment → Change the system time

 

Remove any users or groups that do not need this permission.

PV044Windows Time Service Synchronization

The Windows Time service (W32Time) synchronizes the date and time for all computers managed by Active Directory Domain Services (AD DS). While this does not prevent local system tampering, it ensures that any changes are temporary and will only last until the next synchronization.

 

Alternatively, hosts can be configured to use an internal or external Network Time Protocol (NTP) server, that can synchronize the system time.

Detection

ID Name Description
DT109Windows Event Log, System Time Modification

Windows Event ID 4616 within the Security log is generated when the system time is modified. This log contains key information for investigators:

  • The original system time
  • The modified system time
  • The username of the account responsible for the change