Sysmon Event ID 2: File creation time changed
- Event ID
- 2
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Files
- Default logging
- Needs configuration
What event 2 means
Sysmon event 2 records a process setting the creation time of a file explicitly. It gives the new value (CreationUtcTime) and the old one (PreviousCreationUtcTime), plus the process that did it.
Attackers backdate dropped files to make them blend in with operating-system files, which defeats naive timeline analysis based on $STANDARD_INFORMATION timestamps. Seeing the change as it happens, with the responsible process, is often the fastest way to catch it.
The event is noisy on its own: browsers, installers, archive tools and cloud-sync clients routinely set creation times. Most configurations limit it to executables, scripts and sensitive folders, or exclude well-known updaters.
When it is logged
Sysmon installed with a configuration containing a <FileCreateTime> rule (include rules for the paths or extensions you care about).
Key fields
| Field | What it tells you |
|---|---|
| UtcTime | When Sysmon saw the change. |
| ProcessGuid | Process that changed the timestamp; pivot to its event 1. |
| ProcessId | PID of that process. |
| Image | Executable that changed the timestamp. |
| TargetFilename | File whose creation time was changed. |
| CreationUtcTime | The new creation time set by the process. |
| PreviousCreationUtcTime | The creation time before the change. A new value that is years older than the previous one on a freshly written executable is the classic timestomping pattern. |
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Browsers and download managers setting timestamps on downloaded files.
- Installers, archive extractors and file-copy tools preserving original timestamps.
- Cloud-sync clients such as OneDrive restoring file metadata.
What attackers do that produces it
- Malware or an operator backdating a dropped DLL or EXE in
C:\Windows\System32orProgramDatato match neighboring system files. - Timestomping tools or PowerShell (
(Get-Item x).CreationTime = ...) run right after a payload drop.
Investigation tips
- Compare CreationUtcTime with PreviousCreationUtcTime; large backwards jumps on new executables stand out.
- Pivot on ProcessGuid to event 1 to see who ran the process and to event 11 for the original file creation.
- Verify with the NTFS
$FILE_NAMEtimestamps in the MFT, which timestomping tools usually do not change.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1070.006 Indicator Removal: Timestomp | Stealth |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighUnusual File Modification by dns.exeRule by Tim Rauch (Nextron Systems), Elastic (idea), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.