Insider Threat Matrix™Insider Threat Matrix™
  • ID: PV043
  • Created: 07th April 2025
  • Updated: 07th April 2025
  • Platform: Windows
  • Contributor: The ITM Team

Restrict Windows System Time Modification

Using Group Policy on Windows it is possible to block the ability for users to modify the system date/time.

 

In the Group Policy Editor, navigate to:
Computer Configuration -> Windows Settings -> Security Settings → Local Policies → User Rights Assignment → Change the system time

 

Remove any users or groups that do not need this permission.

Sections

ID Name Description
AF032System Time Modification

A subject modifies the system date, time, time zone, hardware clock, or time synchronization configuration of a device to obscure the chronology of activity relevant to an insider threat investigation. This behavior may affect timestamps associated with file creation, file modification, authentication events, process execution, log generation, scheduled activity, or other forensic artifacts used to reconstruct subject activity.

 

System time modification may be performed before, during, or after an infringement to create ambiguity in the investigative timeline, frustrate correlation between endpoint, identity, network, and application telemetry, or cause investigators to misinterpret the sequence of events. The behavior should be assessed in context with administrative privilege use, time synchronization changes, endpoint telemetry gaps, and inconsistencies between local artifacts and centralized logging sources.

AF032.001Windows System Time Modification

A subject modifies the Windows system time, time zone, or time synchronization behavior to obscure timestamps associated with local artifacts, event logs, file activity, process execution, or other evidence relevant to an insider threat investigation.

 

On Windows systems, this behavior may involve manual date and time changes, abuse of the “Change the system time” user right, modification of Windows Time service behavior, or use of administrative tooling to alter clock settings.