Analytics BIOC
Medium
✕
Suspicious time provider registered
The endpoint time provider has been tampered, this change may be used to gain persistence on the host by loading libraries into the time management service.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Time Providers (T1547.003)
Attacker's goals:
Gain persistence using the legitimate Windows time provider mechanism, which loads libraries into Windows services.
Investigative actions:
Verify if the registered library is malicious. Check if the software performing the installation is a malicious binary. Check for any network activity from a "svchost.exe -k LocalService" process that seems suspicious.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Suspicious time provider registered manually by reg.exe High (parent: Medium)
- Suspicious time provider registered using an uncommon provider name High (parent: Medium)