SysmonObject Access
Event 2: File Create Time Changed
A process changed a file creation time. This event helps track the real creation time of a file. Attackers may change file time attributes to hide their tracks.
Technical Details
Event ID: 2
Sysmon- Object Access
Event Description
A process changed a file creation time. This event helps track the real creation time of a file. Attackers may change file time attributes to hide their tracks.
Key Log Fields
UtcTime- UTC timestamp when file creation time was changedProcessGuid- Process GUID that modified the file timeProcessId- Process IDImage- Process executable pathTargetFilename- Full path of the file whose timestamp was modifiedCreationUtcTime- New creation time set on the filePreviousCreationUtcTime- Original creation time before modification