ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: DT109
  • Created: 07th April 2025
  • Updated: 07th April 2025
  • Platform: Windows
  • Contributor: The ITM Team

Windows Event Log, System Time Modification

Windows Event ID 4616 within the Security log is generated when the system time is modified. This log contains key information for investigators:

  • The original system time
  • The modified system time
  • The username of the account responsible for the change

Sections

ID Name Description
AF021Windows System Time Modification

The subject modifies the Windows system time in an attempt to obscure the timestamps of any system artifacts that may provide value to investigators.