Skip to main content

Breaking Time: Methods, Artifacts, and Forensic Detection of Timestomping on FAT32, Ext3, and Ext4 File Systems

Breaking Time: Methods, Artifacts, and Forensic Detection of Timestomping on FAT32, Ext3, and Ext4 File Systems, published by SANS Institute in October 2025, tests how adversaries manipulate file timestamps on Linux file systems to hide malicious files, and what forensic evidence each method leaves behind. The research built a controlled virtual machine test environment across FAT32, Ext3, and Ext4 file systems to examine four common timestomping techniques: the touch command, the cp --preserve command, the debugfs tool, and system time manipulation ("time travel").

Key findings:

  • The touch command can change a file's access and modified timestamps on any of the three file systems tested, but it cannot change the creation timestamp
  • On Ext3 and Ext4, only the debugfs tool was able to change a file's creation (birth) and change timestamps; touch and cp --preserve could not alter either one
  • FAT32 has no equivalent to debugfs, meaning full timestamp forgery, including the creation date, required combining the time-travel method with file move (mv) and touch operations
  • Using debugfs to timestomp a file does not update the operating system's kernel cache, so the changed timestamps are visible in a raw disk image (via tools like FTK Imager) but not reflected in live commands like ls or stat until the file system is unmounted or the cache is cleared
  • Debugfs unexpectedly failed to update a file's modified timestamp even while successfully changing the other three timestamps, an inconsistency the research flags as a potential detection signal since a modified time preceding a creation time is unusual, but the reverse is not
  • Time-travel timestomping updates the operating system's live view of a file's timestamps immediately, but on Ext3 and Ext4 it made no corresponding changes to the raw disk data itself, a discrepancy the researcher could not fully explain and flags for further study
  • Across all tested timestomping methods, the same four operating system files were consistently modified as indirect artifacts: the wtmp login log, two system journal files, and the random-seed file (the latter excluded as unrelated background noise)
  • Time-travel activity left a distinctive indirect artifact: a new system journal file created and dated to the spoofed past timestamp, plus a recorded event showing the Network Time Protocol (NTP) service being disabled, even though no direct evidence of the time change itself appeared in the journal
  • No system journal entries were found relating to the use of debugfs or umount, meaning these commands can alter file system metadata directly without generating typical operating system-level logging
  • The .bash_history shell history file, often relied on as an investigative artifact, can be bypassed entirely if an SSH session is disconnected before the shell exits normally

The results show a consistent pattern: the simplest LOLBins (touch, cp) can convincingly fake access and modified timestamps but cannot touch creation or change timestamps on Ext3 and Ext4 without specialized tools, and those specialized tools introduce their own detectable inconsistencies between what the raw disk shows and what the live operating system reports. Time-travel is the most complete method for forging all four timestamps at once, but it leaves behind indirect artifacts, such as anomalous journal files and NTP service events, that persist even when the file system itself looks untouched. This means investigators who rely solely on file metadata will miss evidence that a broader, system-level review would catch. The research was conducted using isolated Ubuntu 24.02 virtual machines running VirtualBox, with FAT32, Ext3, and Ext4 file systems created and tested independently for each timestomping method. Direct file system artifacts were analyzed through hex-dump comparison and FTK Imager, while indirect operating system artifacts were identified by hashing and diffing full disk images before and after each timestomping event.

SANS-Breaking-Time-Methods-Artifacts-Forensic-Detection-Timestomping-FAT32-Ext3-Ext4-File-Systems (PDF, 1.59MB)

23 Oct 2025
ByAllan Kroll
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

DeScrypt: A Multi-Tool Framework for Automated Unpacking and Analysis of Malicious Scripts

Research Paper

Scripting languages are increasingly dominant malware vectors that often employ layered obfuscation techniques to slow down manual analysis by reverse engineers and to prevent pattern recognition.

  • 28 Sep 2026
  • Daniel Schalla

The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection

Research Paper

This paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.

  • 11 Aug 2026
  • Garo Sinanian

Reconstructing Deleted File Activity Using FSEvents from macOS

Research Paper

This paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.

  • 30 Jul 2026
  • Josh Clevenger

Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence

Research Paper

Modern Security Operations Centers (SOCs) face a deepening burnout crisis.

  • 20 Jul 2026
  • Jose "Ricky" Banda

Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks

Research Paper

This study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.

  • 22 Jun 2026
  • Eric Fletcher

Capturing the Click: Process-Based Detection of Malicious Link Interactions

Research Paper

This research validates the browser command-line flags used by Chrome, Edge, and Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it.

  • 22 Jun 2026
  • Daniel Gott

Know Your Blind Spots: Better Visibility Through EDR Policy Hardening

Research Paper

Endpoint Detection and Response (EDR) tools identify, detect, and respond to anomalous behavior.

  • 9 Jun 2026
  • Joshuah Williams

Applying CIS Controls to AI Workflows

Research Paper

This research provides guidance on using the CIS Controls in conjunction with AI-specific frameworks to build a robust information security program.

  • 12 May 2026
  • Brian Ventura

A Forensic Study of Artifact Persistence in Containerd-Based Kubernetes Workloads

Research Paper

A container is a standard unit of software that packages code, including its dependencies, so the application runs quickly and reliably across computing environments.

  • 12 May 2026
  • Ahmed Alharbi

Implementing Micro-Segmentation in a Legacy Enterprise Lab Network: A Zero Trust Approach to Reducing Lateral Movement, Improving Containment, and Controlling Operational Overhead

Research Paper

This study evaluates micro-segmentation as a practical Zero Trust control in a Windows Active Directory lab that models common legacy dependencies (directory services, file services, a web tier, and a database tier).

  • 24 Mar 2026
  • Dennis Ankrah

Assessing the Impact of Memory Acquisition on Key Windows Artifacts

Research Paper

This research evaluates the impact of memory capture tools on data at rest, aiming to understand the degree of change that occurs to artifacts, measure differences based on tool selection, and inform best practices for live responders.

  • 20 Mar 2026
  • Russell Devine

From Ambiguity to Action: A Forensic Framework for Differentiating ClickFix Payloads

Research Paper

The "ClickFix" social engineering technique, which leverages fake CAPTCHA or browser update lures to trick users into executing a malicious PowerShell script, presents a critical challenge for incident responders.

  • 24 Feb 2026
  • James Chisolm-Williams

Measuring Malware Obfuscation: Evaluating CNN- Based Detection for Real-World Resilience

Research Paper

This study examined how layered obfuscation affects image-based convolutional neural network (CNN) detectors and introduces a novel, reproducible framework for measuring obfuscation itself.

  • 19 Nov 2025
  • Michael Reglein

Scrutinizing A Web-Based LLM in Private Browsing Mode: An Analysis of Memory Artifacts and Privacy Implications

Research Paper

Using web-based LLMs such as ChatGPT has changed the web browsing landscape to become part of the typical everyday experience.

  • 7 Nov 2025
  • Chris Kosmas

Adversary-Aware IOC Retention: Analyzing Time-to-Live Patterns by Threat Actor Attribution

Research Paper

After analyzing hundreds of IOCs across three unique Advanced Persistent Threats (APTs) from disparate regions, it can be confirmed that not only do threat actors cycle their IOCs at different rates, but those rates can be tracked. This paper introduces an enhanced decay model incorporating a threat actor variable that accounts for these differences in sophistication and hygiene.

  • 23 Oct 2025
  • Nathaniel Jakusz

Breaking Through Deception: Addressing Barriers in the Adoption of Cyber Deception Technologies

Research Paper

Despite the increasing sophistication of cyber threats and the need for organizations to employ innovative defense strategies, cyber deception technologies, tools designed to mislead attackers and gain a defensive advantage, remain significantly underutilized across organizational cybersecurity programs.

  • 23 Oct 2025
  • Dakota Campbell

Forensic Investigation of Bluetooth-Based Credit Card Skimmers

Research Paper

Hidden Bluetooth Low Energy (BLE) credit skimmers are a growing threat to credit card fraud. Criminals can set up practical and inexpensive systems built on top of modules, such as the HM-19, to collect and transmit stolen data covertly across wireless channels.

  • 3 Sep 2025
  • John Passaro

Beneath the Mask: Can Contribution Data Unveil Malicious Personas in Open-Source Projects?

Research Paper

In February 2024, after building trust over two years with project maintainers by making a significant volume of legitimate contributions, GitHub user "JiaT75" self-merged a version of the XZ Utils project containing a highly sophisticated well-disguised backdoor targeting sshd processes running on systems with the backdoored package installed.

  • 13 May 2025
  • SANS Institute

Catching the Hand in the Cookie Jar: Canary Session Cookies

Research Paper

This project demonstrates how even applications secured with MFA are still vulnerable to hijacked session cookies. Given the persistent threats posed to organizations by stolen authentication cookies, this research proposes implementing Canary session cookies to detect the theft and malicious use of credentials.

  • 17 Apr 2025
  • Caleb Patten

A Pebble In the Ocean: Maximizing Log Fidelity In Container Environments

Research Paper

Log fidelity is crucial for Incident Response Teams to investigate and contain cyber incidents but can be difficult to optimize in containerized environments.

  • 17 Apr 2025
  • Zach Salva