Analytics BIOC Informational

A user changed the Windows system time

A user changed the Windows system time. This may be indicative of a malicious activity and may affect authentication from the source machine.

Module:
Identity Threat Detection (ITDR)
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: System Time Discovery (T1124)
Attacker's goals:

A malicious insider might change their Windows system time. This action might affect the machine's ability to authenticate to the domain.

Investigative actions:

Check for any other suspicious activity related to the host and the user involved in the alert.

Test period:
N/A (single event)
Deduplication:
1 Hour