Linux auditd: File timestamp manipulation via touch -t/-a/-c/-m/-r options

Alerts on touch executions with timestamp options that alter file access and modification times on Linux.

FreeUnreviewedSigmamediumv1
title: "Linux auditd: File timestamp manipulation via touch -t/-a/-c/-m/-r options"
id: 7bf04cc5-9676-48c1-92ca-9c6b2b52d7c3
status: test
description: This rule flags Linux processes running touch that include timestamp-modifying options (-t, and/or -a, -c, -m, -r) based on EXECVE events. Attackers can use file time changes to reduce the chance that newly created or modified files stand out during investigation. It relies on auditd telemetry capturing the executed command line arguments for touch.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.006/T1070.006.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/execve/lnx_auditd_change_file_time_attr.yml
author: Igor Fits, oscd.community, Huntrule Team
date: 2020-10-15
modified: 2022-11-28
tags:
  - attack.stealth
  - attack.t1070.006
logsource:
  product: linux
  service: auditd
detection:
  execve:
    type: EXECVE
  touch:
    - touch
  selection2:
    - -t
    - -acmr
    - -d
    - -r
  condition: execve and touch and selection2
falsepositives:
  - Unknown
level: medium
simulation:
  - type: atomic-red-team
    name: Set a file's access timestamp
    technique: T1070.006
    atomic_guid: 5f9113d5-ed75-47ed-ba23-ea3573d05810
  - type: atomic-red-team
    name: Set a file's modification timestamp
    technique: T1070.006
    atomic_guid: 20ef1523-8758-4898-b5a2-d026cc3d2c52
  - type: atomic-red-team
    name: Modify file timestamps using reference file
    technique: T1070.006
    atomic_guid: 631ea661-d661-44b0-abdb-7a7f3fc08e50
license: DRL-1.1
related:
  - id: b3cec4e7-6901-4b0d-a02d-8ab2d8eb818b
    type: derived

What it detects

This rule flags Linux processes running touch that include timestamp-modifying options (-t, and/or -a, -c, -m, -r) based on EXECVE events. Attackers can use file time changes to reduce the chance that newly created or modified files stand out during investigation. It relies on auditd telemetry capturing the executed command line arguments for touch.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.