← ./resources / blog

Time Stomping: Reconstructing Events When File Times Lie

Timestomping changes file timestamps to frustrate timeline analysis. A resilient investigation reconciles file-system metadata with journals, execution artifacts, security telemetry, backups, and remote systems.

Defensive scope

This article omits commands and APIs for changing timestamps. Lab guidance uses prepared metadata records.

Many clocks, one incident

NTFS stores several file times, while copying, extraction, installation, sync, and restoration can alter them legitimately. Contradictions are stronger than any isolated value: an apparently old file may have new execution, download, journal, or EDR evidence.

Build a super-timelineFile timesMFT + USNExecutionEDR + eventsRemote logsNormalize · correlate · explain contradictions
A timestamp is one assertion, not the incident chronology.

Detection and collection

  • Find times outside host, volume, account, or parent-directory lifetimes.
  • Compare NTFS attributes with MFT and USN sequence.
  • Correlate apparently old files with recent execution and download artifacts.
  • Identify timestamp changes after suspicious writes or process creation.

Collect MFT, USN, event and EDR logs, registry, prefetch, Amcache, shortcuts, browser records, file-server data, and backups. Normalize time zones and clock drift. Plaso, Velociraptor, MFTECmd, and Hayabusa support timelines. Test with a synthetic CSV of deliberate contradictions.

ATT&CK and controls

Timestomping maps to T1070.006 and is normally OS functionality, not a CVE. Centralize immutable telemetry, retain endpoint and journal data, synchronize clocks, restrict administrative tooling, and require multi-source timelines in response playbooks.

← Previous: Stack SpoofingNext: Attributes & Locking →