// MITRE ATT&CK
T1124 · System Time Discovery
An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or systemsetup on macOS.(Citation: MSDN System Time)(Citation: Technet Windows Time Service)(Citati...
How to detect & mitigate it
Detecting System Time Discovery starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1033
System Owner/User Discovery T1613
Container and Resource Discovery T1016.001
Internet Connection Discovery T1069
Permission Groups Discovery T1069.003
Cloud Groups T1615
Group Policy Discovery T1652
Device Driver Discovery T1087.002
Domain Account
System Owner/User Discovery T1613
Container and Resource Discovery T1016.001
Internet Connection Discovery T1069
Permission Groups Discovery T1069.003
Cloud Groups T1615
Group Policy Discovery T1652
Device Driver Discovery T1087.002
Domain Account
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.