Skip to content
Sysmon

Sysmon Event ID 2: File creation time changed

A process changed a file creation timeSysmon event 2 fires when a process explicitly changes a file's creation timestamp — the classic trace of timestomping, but also common in installers.
2
Event ID
2
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Files
Default logging
Needs configuration

What event 2 means

Sysmon event 2 records a process setting the creation time of a file explicitly. It gives the new value (CreationUtcTime) and the old one (PreviousCreationUtcTime), plus the process that did it.

Attackers backdate dropped files to make them blend in with operating-system files, which defeats naive timeline analysis based on $STANDARD_INFORMATION timestamps. Seeing the change as it happens, with the responsible process, is often the fastest way to catch it.

The event is noisy on its own: browsers, installers, archive tools and cloud-sync clients routinely set creation times. Most configurations limit it to executables, scripts and sensitive folders, or exclude well-known updaters.

When it is logged

Audit policy / configuration

Sysmon installed with a configuration containing a <FileCreateTime> rule (include rules for the paths or extensions you care about).

Key fields

FieldWhat it tells you
UtcTimeWhen Sysmon saw the change.
ProcessGuidProcess that changed the timestamp; pivot to its event 1.
ProcessIdPID of that process.
ImageExecutable that changed the timestamp.
TargetFilenameFile whose creation time was changed.
CreationUtcTimeThe new creation time set by the process.
PreviousCreationUtcTimeThe creation time before the change. A new value that is years older than the previous one on a freshly written executable is the classic timestomping pattern.
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Browsers and download managers setting timestamps on downloaded files.
  • Installers, archive extractors and file-copy tools preserving original timestamps.
  • Cloud-sync clients such as OneDrive restoring file metadata.

What attackers do that produces it

  • Malware or an operator backdating a dropped DLL or EXE in C:\Windows\System32 or ProgramData to match neighboring system files.
  • Timestomping tools or PowerShell ((Get-Item x).CreationTime = ...) run right after a payload drop.

Investigation tips

  • Compare CreationUtcTime with PreviousCreationUtcTime; large backwards jumps on new executables stand out.
  • Pivot on ProcessGuid to event 1 to see who ran the process and to event 11 for the original file creation.
  • Verify with the NTFS $FILE_NAME timestamps in the MFT, which timestomping tools usually do not change.

MITRE ATT&CK techniques

TechniqueTactics
T1070.006 Indicator Removal: TimestompStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading