MITRE ATT&CK technique
T1099
Timestomp
Adversaries may take actions to hide the deployment of new, or modification of existing files to obfuscate their activities. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder. This is done, for example, on files that have been modified or created by the adversary so that they do not appear conspicuous to forensic investigators or file analysis tools. Timestomping may be used along with file name [Masquerading](https://attack.mitre.org/techniques/T1036) to hide malware and tools. (Citation: WindowsIR Anti-Forensic Techniques)
TA0005
Linked Daily items
0 hits
No Daily items mapped yet.
Linked Incidents
0 hits
No incidents mapped yet.
Predicted CVE associations
0 items
No mappings yet for this technique.
These relationships come from the current triage artifact and are not official MITRE mappings.