LOGBOOK

HELP

Quiz Entry - updated: 2026.09.24

Why is Sysmon event ID 2, "a process changed a file creation time", a useful detection signal?

Because legitimate software almost never rewrites a file's creation date, while attackers do it on purpose (timestomping) to make a freshly dropped file look old and blend in with the system files around it.

Timestomping: evil.dll is dropped today, its creation time is rewritten to 2019; a directory sort is fooled, but Sysmon event 2 records old and new time

* The trick that hides the file from a directory listing leaves both timestamps in the log. *

Investigators often start by asking "what was created around the time of the incident?" and sort a directory by creation time. An attacker who drops evil.dll into C:\Windows\System32 and then sets its creation date to match the neighbouring files from years ago escapes exactly that search.

Sysmon event 2 records the process that changed the time, the file, and both the new and the previous creation time. So the trick that hides the file from a directory listing leaves a precise trail in the log instead. Installers and some sync tools do change timestamps legitimately, so the typical filter is: only files in user-writable paths, or executables, which is exactly what the example configuration rule for this event does.

Go deeper:

From Quiz: ITIA / Logging Lab: Sysmon, Splunk and the Elastic Stack | Updated: Sep 24, 2026