Windows System Time Discovery via net.exe or w32tm.exe

Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-24
Updated
2026-07-30

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions of Windows time-related utilities by matching net.exe/net1.exe commands containing the string "time" or w32tm.exe commands containing "tz". Attackers can use these queries to determine the target system’s time zone and support subsequent actions such as scheduling or timing-dependent operations. Telemetry relies on process creation events with command line and executable path information.

Related detections3 linkedT1124 — drag to rearrange
System Time Lookup
Windows: w32tm.exe Timer/Delay Usage via stripchart Parameters
Cisco AAA discovery via show/dir commands
Windows System Time Discovery via net.exe or w32tm.exe
Pivot detection · T1124 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.