title: 'File Time Attribute Change' id: b3cec4e7-6901-4b0d-a02d-8ab2d8eb818b status: experimental description: 'Detect file time attribute change to hide new or changes to existing files.' # For this rule to work you must enable audit of process execution in OpenBSM, see # https://osquery.readthedocs.io/en/stable/deployment/process-auditing/#macos-process-socket-auditing author: 'Igor Fits, Mikhail Larin, oscd.community' date: 2020/10/19 references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.006/T1070.006.md logsource: product: macos category: process_creation detection: selection1: ProcessName|endswith: '/touch' selection2: CommandLine|contains: - '-t' - '-acmr' - '-d' - '-r' condition: selection1 and selection2 falsepositives: - 'Unknown' level: medium tags: - attack.defense_evasion - attack.t1070.006