Detections
- Home
- - Detections
- -DT109
- ID: DT109
- Created: 07th April 2025
- Updated: 07th April 2025
- Platform: Windows
- Contributor: The ITM Team
Windows Event Log, System Time Modification
Windows Event ID 4616 within the Security log is generated when the system time is modified. This log contains key information for investigators:
- The original system time
- The modified system time
- The username of the account responsible for the change
Sections
ID | Name | Description |
---|---|---|
AF021 | Windows System Time Modification | The subject modifies the Windows system time in an attempt to obscure the timestamps of any system artifacts that may provide value to investigators. |