Time Providers

T1547.003

Sub-technique of T1547 Boot or Logon Autostart Execution.View on attack.mitre.org

About this technique

Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time synchronization across and within domains. W32Time time providers are responsible for retrieving time stamps from hardware/network resources and outputting these values to other network clients.

Time providers are implemented as dynamic-link libraries (DLLs) that are registered in the subkeys of `HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\W32Time\TimeProviders\`. The time provider manager, directed by the service control manager, loads and starts time providers listed and enabled under this key at system startup and/or whenever parameters are changed.

Adversaries may abuse this architecture to establish persistence, specifically by creating a new arbitrarily named subkey pointing to a malicious DLL in the `DllName` value. Administrator privileges are required for time provider registration, though execution will run in context of the Local Service account.

Detection rules2

Rules on DetectionCode tagged with T1547.003.

Sigma1

RuleLevelLog source
New TimeProviders Registered With Uncommon DLL Namehighwindows / registry_set

Splunk1

RuleTypeRiskData source
Time Provider Persistence RegistryTTPNULLSysmon EventID 13

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References3

  1. Github W32Time Oct 2017 Open source
    Lundgren, S. (2017, October 28). w32time. Retrieved March 26, 2018.
  2. Microsoft TimeProvider Open source
    Microsoft. (n.d.). Time Provider. Retrieved March 26, 2018.
  3. Microsoft W32Time Feb 2018 Open source
    Microsoft. (2018, February 1). Windows Time Service (W32Time). Retrieved March 26, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.