Unauthorized System Time Modification
Detect scenarios where a potentially unauthorized application or user is modifying the system time.
Detection logic
selection
EventID: 4616filter_main_svchost
ProcessName: C:\Windows\System32\svchost.exe
SubjectUserSid: S-1-5-19filter_optional_vmtools
ProcessName:
- C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
- C:\Program Files (x86)\VMware\VMware Tools\vmtoolsd.exe
- C:\Windows\System32\VBoxService.exe
- C:\Windows\System32\oobe\msoobe.exeCondition
selection and not 1 of filter_main_* and not 1 of filter_optional_*Raw YAML
title: Unauthorized System Time Modification
id: faa031b5-21ed-4e02-8881-2591f98d82ed
status: test
description: Detect scenarios where a potentially unauthorized application or user is modifying the system time.
references:
- Private Cuckoo Sandbox (from many years ago, no longer have hash, NDA as well)
- Live environment caused by malware
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4616
author: '@neu5ron'
date: 2019-02-05
modified: 2025-12-03
tags:
- attack.stealth
- attack.t1070.006
logsource:
product: windows
service: security
definition: 'Requirements: Audit Policy : System > Audit Security State Change, Group Policy : Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\System\Audit Security State Change'
detection:
selection:
EventID: 4616
filter_main_svchost:
ProcessName: 'C:\Windows\System32\svchost.exe'
SubjectUserSid: 'S-1-5-19'
filter_optional_vmtools:
ProcessName:
- 'C:\Program Files\VMware\VMware Tools\vmtoolsd.exe'
- 'C:\Program Files (x86)\VMware\VMware Tools\vmtoolsd.exe'
- 'C:\Windows\System32\VBoxService.exe'
- 'C:\Windows\System32\oobe\msoobe.exe'
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- HyperV or other virtualization technologies with binary not listed in filter portion of detection
level: lowFalse positives
- HyperV or other virtualization technologies with binary not listed in filter portion of detection
References
Private Cuckoo Sandbox (from many years ago, no longer have hash, NDA as well)Live environment caused by malware- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4616