Linux: Detect touch commands used to alter file timestamps with -t/-a/-c/-m/-r flags
Alerts on touch executions with timestamp options that alter file access and modification times on Linux.
- Product
- linux
- Service
- auditd
- Author
- Igor Fits, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2020-10-15
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Linux processes running touch with timestamp-related parameters that can change file access and/or modification times. Attackers may use timestamp manipulation to hide the creation or modification time of files. The detection relies on auditd EXECVE telemetry capturing the touch command and its specific -t, -acmr, -d, and -r arguments.
Reporting behind it
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Linux: Detect touch commands used to alter file timestamps with -t/-a/-c/-m/-r flags"
id: 7bf04cc5-9676-48c1-92ca-9c6b2b52d7c3
status: test
description: This rule identifies Linux processes running touch with timestamp-related parameters that can change file access and/or modification times. Attackers may use timestamp manipulation to hide the creation or modification time of files. The detection relies on auditd EXECVE telemetry capturing the touch command and its specific -t, -acmr, -d, and -r arguments.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.006/T1070.006.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/execve/lnx_auditd_change_file_time_attr.yml
author: Igor Fits, oscd.community, Huntrule Team
date: 2020-10-15
modified: 2022-11-28
tags:
- attack.stealth
- attack.t1070.006
logsource:
product: linux
service: auditd
detection:
execve:
type: EXECVE
touch:
- touch
selection2:
- -t
- -acmr
- -d
- -r
condition: execve and touch and selection2
falsepositives:
- Unknown
level: medium
simulation:
- type: atomic-red-team
name: Set a file's access timestamp
technique: T1070.006
atomic_guid: 5f9113d5-ed75-47ed-ba23-ea3573d05810
- type: atomic-red-team
name: Set a file's modification timestamp
technique: T1070.006
atomic_guid: 20ef1523-8758-4898-b5a2-d026cc3d2c52
- type: atomic-red-team
name: Modify file timestamps using reference file
technique: T1070.006
atomic_guid: 631ea661-d661-44b0-abdb-7a7f3fc08e50
license: DRL-1.1
related:
- id: b3cec4e7-6901-4b0d-a02d-8ab2d8eb818b
type: derived