Suspicious Timestomping of PHP Webshell in Ivanti CSA Webroot via touch (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-08-29
Updated
2026-08-29

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects use of touch with an explicit date argument to backdate a PHP file inside the Ivanti Cloud Service Appliance LANDesk broker webroot, the timestomping behavior used by the Houken intrusion set to blend planted webshells with legitimate appliance files. Adversaries leverage timestamp manipulation to frustrate forensic triage, making this a strong signal of an attacker actively concealing webshell drops on the appliance.

Related detections8 linkedT1070.006 — drag to rearrange
Suspicious File Timestamp Manipulation via PowerShell (via process_creation)
Suspicious System Time Changed (via security)
Linux Service File Touch with Timestamp Argument
Windows File Creation Time Altered to a Previous Year
PowerShell timestomping via file timestamp property and setter usage (Windows)
macOS process using touch to modify file timestamps and hide file changes
Linux: Detect touch commands used to alter file timestamps with -t/-a/-c/-m/-r flags
Windows Security Event 4616 for System Time Changes by Non-Service Accounts
Suspicious Timestomping of PHP Webshell in Ivanti CSA Webroot via touch (via process_creation)
Pivot detection · T1070.006 · 8 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.