Default image of it-sa 365

Timestomping – Manipulation of Timestamps

Timestomping, an anti-forensic technique used to hide malware activities.

Topic

Data security / DLP / Know-how protectionNetwork Security / Patch ManagementSIEM / Threat Analytics / SOC

When & Where

calendar_month

Wed, 10/08/2025, 11:15 - 11:30

location_on

Forum, Booth 9-445

Download session as iCaldownload_for_offline

Details

  • Format:

    Technology lecture

  • Language:

    German

Session description

Malware, ransomware, virus. Every piece of malicious software tries to remain hidden and hides itself until it strikes. The presentation 'Timestomping – Manipulation of Timestamps' deals with a special technique from the field of anti-forensics used to blur traces or manipulate evidence. The time of creation or modification of a file is often crucial for analysis, as it helps determine who, when, and what was manipulated on the system. I explain how timestamps can be forged, the challenges for IT forensics, and what types of timestamps exist in the file system, when they are written or changed, how they can be manipulated, and whether such manipulations can be detected. The g ...

Moderator