Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0151 — Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery
DET0151

Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN0430 Analytic 0430
Windows

Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \\host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values).

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=11 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 etw:Microsoft-Windows-Kernel-Process High-frequency or suspicious sequence of QueryPerformanceCounter/GetTickCount API calls from a non-standard process lineage WinEventLog:TaskScheduler EventCode=106 WinEventLog:TaskScheduler Task registration/execution shortly after a time discovery event EDR:Telemetry Process lineage and API usage enrichment (GetSystemTime, GetTimeZoneInformation, NtQuerySystemTime)
[TimeWindow] Correlation window (e.g., 5–15 minutes) between time discovery and follow-on scheduling/conditional actions.
[AllowedParents] Legitimate parent processes (e.g., corporate scripts, management agents) that frequently call time APIs.
[CommandlineKeywordList] Extend/restrict keyword list for time queries (e.g., custom PS functions, .NET calls).
[UserContextScope] Restrict to non-service, non-administrative, or newly created/rare users.
[ProcessPrevalenceThreshold] Frequency threshold to exclude common estate-wide benign usage.
AN0431 Analytic 0431
Linux

A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic.

auditd:SYSCALL type=EXECVE or SYSCALL for /bin/date, /usr/bin/timedatectl, /sbin/hwclock, /bin/cat /etc/timezone, /bin/cat /proc/uptime auditd:SYSCALL Rules capturing clock_gettime, time, gettimeofday syscalls when enabled linux:syslog sudo/date/timedatectl execution by non-standard users linux:cron cron activity
[AuditRulesSyscalls] Scope of syscalls (time, clock_gettime, gettimeofday) monitored; may be performance-sensitive.
[AllowedBinaries] List of legitimate automation/orchestration tools frequently querying time.
[TimeWindow] Correlation window (e.g., 5–20 minutes) to link time discovery to follow-on cron/at changes.
[UserContextScope] Ignore root-owned maintenance agents if desired; focus on interactive or newly created users.
AN0432 Analytic 0432
macOS

Process/script execution of systemsetup -gettimezone, date, ioreg, or API usage (timeIntervalSinceNow, gettimeofday) followed by time-based scheduling (launchd plist modification) or sleep-based execution.

macos:unifiedlog process exec events of systemsetup, date, ioreg with command_line parameters indicating time discovery macos:unifiedlog New/modified launchd plist (persistence/scheduling) within TimeWindow after time query
[LaunchdPaths] Organization-specific list of allowed launchd write locations to filter benign agents.
[TimeWindow] Correlation window to link time discovery to launchd persistence/scheduling.
[AllowedCallers] Known management agents (e.g., JAMF) that legitimately call systemsetup/date.
AN0433 Analytic 0433
ESXi

Interactive or remote shell/API invocation of esxcli system clock get or querying time parameters via hostd/vpxa shortly followed by time/ntp configuration checks or scheduled task creation, executed by non-standard accounts or outside maintenance windows.

esxi:shell /var/log/shell.log entries containing "esxcli system clock get" esxi:hostd /var/log/hostd.log API calls reading/altering time/ntp settings esxi:syslog /var/log/vpxa.log task invocations tied to time configuration
[MaintenanceWindow] Only alert if outside approved ops windows.
[PrivilegedAccountsAllowList] Suppress alerts for known service accounts.
[RemoteIPAllowList] Whitelist management station IPs.
[TimeWindow] Correlation between esxcli time query and subsequent hostd/vpxa config calls.
AN0434 Analytic 0434
Network Devices

Non-standard or rare users/locations issue CLI commands like "show clock detail" or "show timezone"; optionally followed by configuration of time/timezone or NTP sources. AAA/TACACS+ accounting and syslog correlate execution to identity, source IP, and privilege level.

networkdevice:syslog command-exec: CLI commands containing "show clock", "show clock detail", "show timezone" executed by suspicious user/source networkdevice:config config-change: timezone or ntp server configuration change after a time query command
[AllowedAdminSubnets] Only alert on access from outside the NOC/management subnets.
[KnownMaintenanceUsers] Whitelist known automation/orchestration accounts.
[TimeWindow] Correlation window between time query and config change.

Detected Techniques

1

Details

MITRE ID
DET0151
STIX ID
x-mitre-detection-strategy--98ae5e06-7ea5-49b9-b793-7f97b1d306b2
Analytics
5
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.