Analytics BIOC
Informational
✕
A user changed the Windows system time
A user changed the Windows system time. This may be indicative of a malicious activity and may affect authentication from the source machine.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: System Time Discovery (T1124)
Attacker's goals:
A malicious insider might change their Windows system time. This action might affect the machine's ability to authenticate to the domain.
Investigative actions:
Check for any other suspicious activity related to the host and the user involved in the alert.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Hour