{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/timestomping/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["defense-evasion","timestomping","linux","macos"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eTimestomping is an anti-forensics technique employed by adversaries to manipulate file access, modification, and change timestamps. By modifying these metadata attributes, attackers can make malicious files appear as though they were created at the same time as legitimate system files, effectively blending in with their surroundings to evade automated detection and human analysis. On Linux and macOS systems, the 'touch' command is commonly leveraged for this purpose due to its inherent ability to alter timestamp attributes through various command-line arguments.\u003c/p\u003e\n\u003cp\u003eThis activity is particularly concerning for defenders because it complicates timeline analysis during incident response. Defenders must identify anomalous usage of 'touch' by non-root users and distinguish it from legitimate administrative tasks. The threat is platform-agnostic across Unix-like systems and requires granular process monitoring to detect deviations from established baselines in environment-specific workflows.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established on a Linux or macOS endpoint via exploitation or credential compromise.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies a target malicious file or directory intended to be hidden or disguised.\u003c/li\u003e\n\u003cli\u003eThe attacker assesses the timestamps of surrounding legitimate system files to determine the target timeframe.\u003c/li\u003e\n\u003cli\u003eThe attacker executes the 'touch' utility with specific flags, such as -r (reference) or -t (timestamp), to apply the chosen metadata to the malicious file.\u003c/li\u003e\n\u003cli\u003eThe file's timestamp is updated, effectively masking its true creation or modification time in the filesystem.\u003c/li\u003e\n\u003cli\u003eThe attacker may move the file to a system directory to further blend in with existing binaries.\u003c/li\u003e\n\u003cli\u003eThe attacker proceeds with additional malicious activities, such as lateral movement or data exfiltration, while the forensic trail remains obscured.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful timestomping undermines the integrity of forensic investigations by invalidating file-based temporal evidence. This allows attackers to maintain persistence longer and evade detection by security teams relying on file-creation alerts. It is frequently observed in post-compromise stages across a wide variety of sectors, as it allows attackers to bypass baseline monitoring that looks for recently created or modified files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should monitor process execution logs for anomalous 'touch' activity.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable process-creation logging (e.g., via Auditd or Elastic Defend) to monitor the execution of '/bin/touch'.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to flag instances where 'touch' is executed with flags like -t, -d, -a, -m, or -r.\u003c/li\u003e\n\u003cli\u003eBaseline the environment to identify legitimate administrative or build-related usage of the 'touch' command and add these paths to the detection filter list.\u003c/li\u003e\n\u003cli\u003eReview and tighten file system permissions to ensure only authorized users or service accounts can modify metadata for critical system files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:13:14Z","date_published":"2026-09-18T19:13:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-timestomping-touch/","summary":"Adversaries perform timestomping on Linux and macOS systems using the touch command to modify file timestamps and evade forensic detection.","title":"Timestomping via Touch Utility","url":"https://feed.craftedsignal.io/briefs/2026-09-timestomping-touch/"}],"language":"en","title":"CraftedSignal Threat Feed - Timestomping","version":"https://jsonfeed.org/version/1.1"}