Skip to content
Security

Event ID 4616: System time changed

The system time was changedSecurity event 4616 records a system clock change with old and new time, account and process. Routine time sync is normal; manual jumps skew timelines.
4616
Event ID
4616
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
System
Default logging
Logged by default

What event 4616 means

Event 4616 is written whenever the system time is changed. It records the time before (PreviousTime) and after (NewTime), both in UTC, the account that made the change and — since Windows 7 / Server 2008 R2 — the process that did it (ProcessId, ProcessName).

Most records are the Windows Time service making small corrections: Subject LOCAL SERVICE, process svchost.exe, and a difference of milliseconds to seconds. Those can be ignored. The records that matter are large jumps, changes made by an interactive user, and changes made by unexpected executables.

For a forensic timeline, a clock change is critical context: every timestamp recorded between a jump and its correction is offset by the difference. Kerberos also depends on synchronized clocks, so large changes on domain members can cause authentication failures.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > System > Audit Security State Change (Success). Microsoft documents that 4616 is logged regardless of this subcategory's setting.

ProcessId and ProcessName were added in event version 1 (Windows 7 / Server 2008 R2). Time zone changes do not change the system (UTC) time and are not what this event records.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that changed the time. LOCAL SERVICE is the Windows Time service; a named user points to a manual change.
SubjectUserSidSID of that account.
SubjectLogonIdLogon session of the account; pivot to 4624 to see how it logged on.
PreviousTimeSystem time before the change, in UTC.
NewTimeSystem time after the change, in UTC. Compute the difference with PreviousTime.
ProcessIdHexadecimal PID of the process that changed the time; matches NewProcessId in 4688.
ProcessNameFull path of that process, e.g. C:\Windows\System32\svchost.exe for the time service. Anything else deserves a look.

Common benign sources

  • Windows Time service (LOCAL SERVICE, svchost.exe) correcting drift by small amounts.
  • Virtual machines resyncing their clock after resume from suspend or restore from snapshot.
  • Laptops correcting a large offset at boot after a dead CMOS battery or long power-off.

What attackers do that produces it

  • Moving the clock back or forward to make malicious activity fall outside the investigated window or to confuse timeline analysis.
  • Changing the time to run software or reuse licenses, certificates or tokens past their validity period.

Investigation tips

  • Filter out LOCAL SERVICE changes of a few seconds, then review the rest by size of the jump and by SubjectUserName.
  • When a large jump exists, note both boundaries and adjust the timeline of every artifact written in between.
  • Pivot on ProcessId and SubjectLogonId to 4688 / Sysmon 1 to find the command (date, time, Set-Date, w32tm) and the session that ran it.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4616: system time changes and timestomping

Sources and further reading