Time Stomping: Reconstructing Events When File Times Lie
Timestomping changes file timestamps to frustrate timeline analysis. A resilient investigation reconciles file-system metadata with journals, execution artifacts, security telemetry, backups, and remote systems.
This article omits commands and APIs for changing timestamps. Lab guidance uses prepared metadata records.
Many clocks, one incident
NTFS stores several file times, while copying, extraction, installation, sync, and restoration can alter them legitimately. Contradictions are stronger than any isolated value: an apparently old file may have new execution, download, journal, or EDR evidence.
Detection and collection
- Find times outside host, volume, account, or parent-directory lifetimes.
- Compare NTFS attributes with MFT and USN sequence.
- Correlate apparently old files with recent execution and download artifacts.
- Identify timestamp changes after suspicious writes or process creation.
Collect MFT, USN, event and EDR logs, registry, prefetch, Amcache, shortcuts, browser records, file-server data, and backups. Normalize time zones and clock drift. Plaso, Velociraptor, MFTECmd, and Hayabusa support timelines. Test with a synthetic CSV of deliberate contradictions.
ATT&CK and controls
Timestomping maps to T1070.006 and is normally OS functionality, not a CVE. Centralize immutable telemetry, retain endpoint and journal data, synchronize clocks, restrict administrative tooling, and require multi-source timelines in response playbooks.