Linux auditd: File timestamp manipulation via touch -t/-a/-c/-m/-r options
Alerts on touch executions with timestamp options that alter file access and modification times on Linux.
FreeUnreviewedSigmamediumv1
linux-auditd-file-timestamp-manipulation-via-touch-t-a-c-m-r-options-b3cec4e7
title: "Linux auditd: File timestamp manipulation via touch -t/-a/-c/-m/-r options"
id: 7bf04cc5-9676-48c1-92ca-9c6b2b52d7c3
status: test
description: This rule flags Linux processes running touch that include timestamp-modifying options (-t, and/or -a, -c, -m, -r) based on EXECVE events. Attackers can use file time changes to reduce the chance that newly created or modified files stand out during investigation. It relies on auditd telemetry capturing the executed command line arguments for touch.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.006/T1070.006.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/execve/lnx_auditd_change_file_time_attr.yml
author: Igor Fits, oscd.community, Huntrule Team
date: 2020-10-15
modified: 2022-11-28
tags:
- attack.stealth
- attack.t1070.006
logsource:
product: linux
service: auditd
detection:
execve:
type: EXECVE
touch:
- touch
selection2:
- -t
- -acmr
- -d
- -r
condition: execve and touch and selection2
falsepositives:
- Unknown
level: medium
simulation:
- type: atomic-red-team
name: Set a file's access timestamp
technique: T1070.006
atomic_guid: 5f9113d5-ed75-47ed-ba23-ea3573d05810
- type: atomic-red-team
name: Set a file's modification timestamp
technique: T1070.006
atomic_guid: 20ef1523-8758-4898-b5a2-d026cc3d2c52
- type: atomic-red-team
name: Modify file timestamps using reference file
technique: T1070.006
atomic_guid: 631ea661-d661-44b0-abdb-7a7f3fc08e50
license: DRL-1.1
related:
- id: b3cec4e7-6901-4b0d-a02d-8ab2d8eb818b
type: derived
What it detects
This rule flags Linux processes running touch that include timestamp-modifying options (-t, and/or -a, -c, -m, -r) based on EXECVE events. Attackers can use file time changes to reduce the chance that newly created or modified files stand out during investigation. It relies on auditd telemetry capturing the executed command line arguments for touch.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.