Event ID 4616: System time changed
- Event ID
- 4616
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- System
- Default logging
- Logged by default
What event 4616 means
Event 4616 is written whenever the system time is changed. It records the time before (PreviousTime) and after (NewTime), both in UTC, the account that made the change and — since Windows 7 / Server 2008 R2 — the process that did it (ProcessId, ProcessName).
Most records are the Windows Time service making small corrections: Subject LOCAL SERVICE, process svchost.exe, and a difference of milliseconds to seconds. Those can be ignored. The records that matter are large jumps, changes made by an interactive user, and changes made by unexpected executables.
For a forensic timeline, a clock change is critical context: every timestamp recorded between a jump and its correction is offset by the difference. Kerberos also depends on synchronized clocks, so large changes on domain members can cause authentication failures.
When it is logged
Advanced Audit Policy Configuration > System > Audit Security State Change (Success). Microsoft documents that 4616 is logged regardless of this subcategory's setting.
ProcessId and ProcessName were added in event version 1 (Windows 7 / Server 2008 R2). Time zone changes do not change the system (UTC) time and are not what this event records.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that changed the time. LOCAL SERVICE is the Windows Time service; a named user points to a manual change. |
| SubjectUserSid | SID of that account. |
| SubjectLogonId | Logon session of the account; pivot to 4624 to see how it logged on. |
| PreviousTime | System time before the change, in UTC. |
| NewTime | System time after the change, in UTC. Compute the difference with PreviousTime. |
| ProcessId | Hexadecimal PID of the process that changed the time; matches NewProcessId in 4688. |
| ProcessName | Full path of that process, e.g. C:\Windows\System32\svchost.exe for the time service. Anything else deserves a look. |
Common benign sources
- Windows Time service (
LOCAL SERVICE,svchost.exe) correcting drift by small amounts. - Virtual machines resyncing their clock after resume from suspend or restore from snapshot.
- Laptops correcting a large offset at boot after a dead CMOS battery or long power-off.
What attackers do that produces it
- Moving the clock back or forward to make malicious activity fall outside the investigated window or to confuse timeline analysis.
- Changing the time to run software or reuse licenses, certificates or tokens past their validity period.
Investigation tips
- Filter out
LOCAL SERVICEchanges of a few seconds, then review the rest by size of the jump and by SubjectUserName. - When a large jump exists, note both boundaries and adjust the timeline of every artifact written in between.
- Pivot on ProcessId and SubjectLogonId to 4688 / Sysmon 1 to find the command (
date,time,Set-Date,w32tm) and the session that ran it.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowUnauthorized System Time ModificationRule by @neu5ron, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.