[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGMzWz4wApbdQ64ZcnzKzKtLKJv-6ZMqZHm31yQ9PjPg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":58,"createdAt":58,"_status":57},1223,"What is the difference between `SetMace` and `FileTimeControl_NTAPI` in terms of modifying file time attributes?","`SetMace` can read all four time attributes (including MFTChangeTime) but cannot modify them on modern Windows (nt6.x+) unless driver signing is bypassed. `FileTimeControl_NTAPI`, which is based on Metasploit's `timestomp` code, can both read and modify all four attributes without needing a driver, but it currently does not support folder operations. For folders, you must use `FileTimeControl_WinAPI` to modify CreateTime, AccessTime, and LastWriteTime. These tools are discussed in detail in the article [Penetration Techniques - Time Attributes of NTFS Files in Windows](\u002Fnews\u002Fpenetration-techniques-time-attributes-of-ntfs-files-in-windows).","\u003Cp>`SetMace` can read all four time attributes (including MFTChangeTime) but cannot modify them on modern Windows (nt6.x+) unless driver signing is bypassed. `FileTimeControl_NTAPI`, which is based on Metasploit&#39;s `timestomp` code, can both read and modify all four attributes without needing a driver, but it currently does not support folder operations. For folders, you must use `FileTimeControl_WinAPI` to modify CreateTime, AccessTime, and LastWriteTime. These tools are discussed in detail in the article [Penetration Techniques - Time Attributes of NTFS Files in Windows](\u002Fnews\u002Fpenetration-techniques-time-attributes-of-ntfs-files-in-windows).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-time-attributes-of-ntfs-files-in-windows\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-difference-between-setmace-and-filetimecontrol_ntapi-in-terms-of-mod-1777479993646","SetMace, FileTimeControl, timestomp, NTAPI, WinAPI, driver signing",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":54,"updatedAt":55,"createdAt":56,"_status":57},294,"Penetration Techniques - Time Attributes of NTFS Files in Windows","penetration-techniques-time-attributes-of-ntfs-files-in-windows","Learn how to modify NTFS file time attributes (CreateTime, AccessTime, LastWriteTime, MFTChangeTime) in Windows for penetration testing and forensic analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, if files need to be deployed on the target system, the time attributes of the parent directory (AccessTime, LastWriteTime, MFTChangeTime) will be altered. If existing files on the target system need to be overwritten, the time attributes of the original files (CreateTime, AccessTime, LastWriteTime, MFTChangeTime) will also be changed.\u003C\u002Fp>\u003Cp>From a penetration perspective, methods to modify file time attributes are needed to eliminate traces.\u003C\u002Fp>\u003Cp>From a forensics perspective, anomalies in file attributes can reveal traces of an attacker's intrusion.\u003C\u002Fp>\u003Cp>This article will introduce methods and details for modifying file attributes, share implementation code, and provide forensic recommendations based on exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Concepts\u003C\u002Fli>\u003Cli>Methods for Reading File Attributes\u003C\u002Fli>\u003Cli>Methods for Modifying File Attributes\u003C\u002Fli>\u003Cli>Code Sharing\u003C\u002Fli>\u003Cli>Exploitation Approaches\u003C\u002Fli>\u003Cli>Forensic Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Time Attributes in the NTFS File System\u003C\u002Fh3>\u003Cp>Include the following four:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime (Modified)\u003C\u002Fli>\u003Cli>MFTChangeTime\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The first three can be obtained via right-click -&gt; Properties, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016704552_0_8ea4b432f1.jpeg\">\u003C\u002Fp>\u003Cp>MFTChangeTime cannot be viewed directly\u003C\u002Fp>\u003Cp>MFTChangeTime records the modification time of the MFT (Master File Table); if file attributes change, MFTChangeTime is updated\u003C\u002Fp>\u003Ch3>2. Methods to Read MFTChangeTime\u003C\u002Fh3>\u003Ch4>(1) Read via NtQueryInformationFile\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Cannot be obtained via WinAPI GetFileTime\u003C\u002Fp>\u003Ch4>(2) Parsing NTFS file format\u003C\u002Fh4>\u003Cp>The $STANDARD_INFORMATION (offset 0x10) and $FILE_NAME (offset 0x30) in the Master File Table contain complete file attributes\u003C\u002Fp>\u003Ch3>3. In Windows 7 system, CreateTime and AccessTime are consistent by default\u003C\u002Fh3>\u003Cp>Under default settings in Windows 7 (and later versions), AccessTime updates are disabled\u003C\u002Fp>\u003Cp>That is, operations that only read files will not change the file attribute AccessTime, and AccessTime remains consistent with CreateTime, which is to reduce hard disk read\u002Fwrite operations\u003C\u002Fp>\u003Cp>Corresponding registry location HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\FileSystem, key value NtfsDisableLastAccessUpdate\u003C\u002Fp>\u003Cp>Value 1 represents disabled, which is the default configuration; value 0 represents enabled. The system must be restarted after modifying the registry for changes to take effect\u003C\u002Fp>\u003Ch3>4. Patterns of file attribute changes\u003C\u002Fh3>\u003Cp>Reading files:\u003C\u002Fp>\u003Cp>Does not change file attributes\u003C\u002Fp>\u003Cp>Overwriting files:\u003C\u002Fp>\u003Cp>Changes all 4 attributes\u003C\u002Fp>\u003Ch3>5. Patterns of folder attribute changes\u003C\u002Fh3>\u003Cp>Create\u002FDelete\u002FRename File:\u003C\u002Fp>\u003Cp>Changes parent folder's AccessTime, LastWriteTime, and MFTChangeTime\u003C\u002Fp>\u003Cp>Read File:\u003C\u002Fp>\u003Cp>Does not change file attributes\u003C\u002Fp>\u003Cp>Overwrite File:\u003C\u002Fp>\u003Cp>Does not change file attributes\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can be tested using SetMace, download at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FSetMace\u003C\u002Fp>\u003Ch2>0x03 Methods for Reading and Modifying File Attributes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using WinAPI GetFileTime and SetFileTime\u003C\u002Fh3>\u003Cp>Can manipulate three file attributes:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime(Modified)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cannot operate on MFTChangeTime\u003C\u002Fp>\u003Ch4>(1) Usage of GetFileTime\u003C\u002Fh4>\u003Cp>Obtain FileTime via GetFileTime()\u003C\u002Fp>\u003Cp>Convert FileTime to SystemTime via FileTimeToSystemTime(), i.e., UTC, same standard\u003C\u002Fp>\u003Cp>Convert SystemTime to LocalTime via SystemTimeToTzSpecificLocalTime(), i.e., UTC plus time zone, considering time zone impact, consistent with current system display time\u003C\u002Fp>\u003Ch4>(2) Usage of SetFileTime\u003C\u002Fh4>\u003Cp>Convert input time data to SystemTime via sscanf()\u003C\u002Fp>\u003Cp>Convert SystemTime to FileTime via SystemTimeToFileTime()\u003C\u002Fp>\u003Cp>Convert FileTime to corresponding UTC FILETIME via LocalFileTimeToFileTime(), i.e., FILETIME plus time zone, considering time zone impact, consistent with current system display time\u003C\u002Fp>\u003Cp>Implementation code is open source, download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>View file\u002Ffolder time (CreateTime, AccessTime, LastWriteTime)\u003C\u002Fli>\u003Cli>Modify file\u002Ffolder time\u003C\u002Fli>\u003Cli>Copy the timestamp from file A to file B\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Using NtQueryInformationFile and NtSetInformationFile\u003C\u002Fh3>\u003Cp>Can manipulate four file attributes:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime (Modified)\u003C\u002Fli>\u003Cli>MFTChangeTime\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In my implementation, I directly referenced the timestomp code from Metasploit, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Frapid7\u002Fmeterpreter\u002Fblob\u002Fmaster\u002Fsource\u002Fextensions\u002Fpriv\u002Fserver\u002Ftimestomp.c\u003C\u002Fp>\u003Cp>Added some features, download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>View file timestamps (CreateTime, AccessTime, LastWriteTime, MFTChangeTime)\u003C\u002Fli>\u003Cli>Modify file timestamps\u003C\u002Fli>\u003Cli>Copy the timestamp from file A to file B\u003C\u002Fli>\u003Cli>Set time to minimum value (1601-01-01 00:00:00)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Folder operations are temporarily not supported\u003C\u002Fp>\u003Ch3>3. Use driver files\u003C\u002Fh3>\u003Ch4>(1) SetMace\u003C\u002Fh4>\u003Cp>Reference download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FSetMace\u003C\u002Fp>\u003Cp>SetMace can normally read file and folder time information (including MFTChangeTime)\u003C\u002Fp>\u003Cp>But cannot modify time information, because since nt6.x, Windows prohibits loading unsigned driver files. If driver protection can be bypassed, time information can be modified\u003C\u002Fp>\u003Ch4>(2) WinHex\u003C\u002Fh4>\u003Cp>Paid version of WinHex supports write operations on hard disk files, which can be used to modify time information\u003C\u002Fp>\u003Ch3>Supplement, file resource cloning\u003C\u002Fh3>\u003Cp>Automate calls to Resource Hacker via PowerShell to clone resource information of executable files (exe, dll, scr, etc.)\u003C\u002Fp>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fthreatexpress\u002Fmetatwin\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This tool does not modify file attributes\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Release files on the target system\u003C\u002Fh3>\u003Cp>Will change the time attributes of the parent directory (AccessTime, LastWriteTime, MFTChangeTime)\u003C\u002Fp>\u003Cp>You can use SetMace to view attribute changes\u003C\u002Fp>\u003Cp>To modify folder time attributes, use FileTimeControl_WinAPI from 0x03, which can modify the following three items:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime (Modified)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To further clear operational traces, use WinHex to modify $STANDARD_INFORMATION (offset 0x10) and $FILE_NAME (offset 0x30) in the Master File Table\u003C\u002Fp>\u003Ch3>2. Overwrite existing files on the target system\u003C\u002Fh3>\u003Cp>Will change the time attributes of the original file (CreateTime, AccessTime, LastWriteTime, MFTChangeTime)\u003C\u002Fp>\u003Cp>You can use FileTimeControl_NTAPI to read and modify time attributes\u003C\u002Fp>\u003Cp>To further eliminate operational traces, it is necessary to use WinHex to modify the $STANDARD_INFORMATION (offset 0x10) and $FILE_NAME (offset 0x30) in the Master File Table.\u003C\u002Fp>\u003Ch2>0x05 Forensic Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Examine the MFTChangeTime attribute of files\u002Ffolders, located in two positions:\u003C\u002Fp>\u003Cul>\u003Cli>$STANDARD_INFORMATION (offset 0x10) in the Master File Table\u003C\u002Fli>\u003Cli>$FILE_NAME (offset 0x30) in the Master File Table\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If the MFTChangeTime is abnormal (later than the other three timestamps), it can generally be considered that the file has been illegally modified.\u003C\u002Fp>\u003Cp>The tool SetMace can be used.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods and details for modifying file attributes, shares two implementation codes (FileTimeControl_WinAPI and FileTimeControl_NTAPI), and provides forensic recommendations based on exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>During penetration testing, if files need to be deployed on the target system, the time attributes of the parent directory (AccessTime, LastWriteTime, MFTChangeTime) will be altered. If existing files on the target system need to be overwritten, the time attributes of the original files (CreateTime, AccessTime, LastWriteTime, MFTChangeTime) will also be changed.\u003C\u002Fp>\u003Cp>From a penetration perspective, methods to modify file time attributes are needed to eliminate traces.\u003C\u002Fp>\u003Cp>From a forensics perspective, anomalies in file attributes can reveal traces of an attacker's intrusion.\u003C\u002Fp>\u003Cp>This article will introduce methods and details for modifying file attributes, share implementation code, and provide forensic recommendations based on exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic Concepts\u003C\u002Fli>\u003Cli>Methods for Reading File Attributes\u003C\u002Fli>\u003Cli>Methods for Modifying File Attributes\u003C\u002Fli>\u003Cli>Code Sharing\u003C\u002Fli>\u003Cli>Exploitation Approaches\u003C\u002Fli>\u003Cli>Forensic Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Time Attributes in the NTFS File System\u003C\u002Fh3>\u003Cp>Include the following four:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime (Modified)\u003C\u002Fli>\u003Cli>MFTChangeTime\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The first three can be obtained via right-click -&gt; Properties, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016704552_0_8ea4b432f1-1.jpeg\">\u003C\u002Fp>\u003Cp>MFTChangeTime cannot be viewed directly\u003C\u002Fp>\u003Cp>MFTChangeTime records the modification time of the MFT (Master File Table); if file attributes change, MFTChangeTime is updated\u003C\u002Fp>\u003Ch3>2. Methods to Read MFTChangeTime\u003C\u002Fh3>\u003Ch4>(1) Read via NtQueryInformationFile\u003C\u002Fh4>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Cannot be obtained via WinAPI GetFileTime\u003C\u002Fp>\u003Ch4>(2) Parsing NTFS file format\u003C\u002Fh4>\u003Cp>The $STANDARD_INFORMATION (offset 0x10) and $FILE_NAME (offset 0x30) in the Master File Table contain complete file attributes\u003C\u002Fp>\u003Ch3>3. In Windows 7 system, CreateTime and AccessTime are consistent by default\u003C\u002Fh3>\u003Cp>Under default settings in Windows 7 (and later versions), AccessTime updates are disabled\u003C\u002Fp>\u003Cp>That is, operations that only read files will not change the file attribute AccessTime, and AccessTime remains consistent with CreateTime, which is to reduce hard disk read\u002Fwrite operations\u003C\u002Fp>\u003Cp>Corresponding registry location HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\FileSystem, key value NtfsDisableLastAccessUpdate\u003C\u002Fp>\u003Cp>Value 1 represents disabled, which is the default configuration; value 0 represents enabled. The system must be restarted after modifying the registry for changes to take effect\u003C\u002Fp>\u003Ch3>4. Patterns of file attribute changes\u003C\u002Fh3>\u003Cp>Reading files:\u003C\u002Fp>\u003Cp>Does not change file attributes\u003C\u002Fp>\u003Cp>Overwriting files:\u003C\u002Fp>\u003Cp>Changes all 4 attributes\u003C\u002Fp>\u003Ch3>5. Patterns of folder attribute changes\u003C\u002Fh3>\u003Cp>Create\u002FDelete\u002FRename File:\u003C\u002Fp>\u003Cp>Changes parent folder's AccessTime, LastWriteTime, and MFTChangeTime\u003C\u002Fp>\u003Cp>Read File:\u003C\u002Fp>\u003Cp>Does not change file attributes\u003C\u002Fp>\u003Cp>Overwrite File:\u003C\u002Fp>\u003Cp>Does not change file attributes\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can be tested using SetMace, download at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FSetMace\u003C\u002Fp>\u003Ch2>0x03 Methods for Reading and Modifying File Attributes\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Using WinAPI GetFileTime and SetFileTime\u003C\u002Fh3>\u003Cp>Can manipulate three file attributes:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime(Modified)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Cannot operate on MFTChangeTime\u003C\u002Fp>\u003Ch4>(1) Usage of GetFileTime\u003C\u002Fh4>\u003Cp>Obtain FileTime via GetFileTime()\u003C\u002Fp>\u003Cp>Convert FileTime to SystemTime via FileTimeToSystemTime(), i.e., UTC, same standard\u003C\u002Fp>\u003Cp>Convert SystemTime to LocalTime via SystemTimeToTzSpecificLocalTime(), i.e., UTC plus time zone, considering time zone impact, consistent with current system display time\u003C\u002Fp>\u003Ch4>(2) Usage of SetFileTime\u003C\u002Fh4>\u003Cp>Convert input time data to SystemTime via sscanf()\u003C\u002Fp>\u003Cp>Convert SystemTime to FileTime via SystemTimeToFileTime()\u003C\u002Fp>\u003Cp>Convert FileTime to corresponding UTC FILETIME via LocalFileTimeToFileTime(), i.e., FILETIME plus time zone, considering time zone impact, consistent with current system display time\u003C\u002Fp>\u003Cp>Implementation code is open source, download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>View file\u002Ffolder time (CreateTime, AccessTime, LastWriteTime)\u003C\u002Fli>\u003Cli>Modify file\u002Ffolder time\u003C\u002Fli>\u003Cli>Copy the timestamp from file A to file B\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Using NtQueryInformationFile and NtSetInformationFile\u003C\u002Fh3>\u003Cp>Can manipulate four file attributes:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime (Modified)\u003C\u002Fli>\u003Cli>MFTChangeTime\u003C\u002Fli>\u003C\u002Ful>\u003Cp>In my implementation, I directly referenced the timestomp code from Metasploit, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Frapid7\u002Fmeterpreter\u002Fblob\u002Fmaster\u002Fsource\u002Fextensions\u002Fpriv\u002Fserver\u002Ftimestomp.c\u003C\u002Fp>\u003Cp>Added some features, download address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements the following functions:\u003C\u002Fp>\u003Cul>\u003Cli>View file timestamps (CreateTime, AccessTime, LastWriteTime, MFTChangeTime)\u003C\u002Fli>\u003Cli>Modify file timestamps\u003C\u002Fli>\u003Cli>Copy the timestamp from file A to file B\u003C\u002Fli>\u003Cli>Set time to minimum value (1601-01-01 00:00:00)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Folder operations are temporarily not supported\u003C\u002Fp>\u003Ch3>3. Use driver files\u003C\u002Fh3>\u003Ch4>(1) SetMace\u003C\u002Fh4>\u003Cp>Reference download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjschicht\u002FSetMace\u003C\u002Fp>\u003Cp>SetMace can normally read file and folder time information (including MFTChangeTime)\u003C\u002Fp>\u003Cp>But cannot modify time information, because since nt6.x, Windows prohibits loading unsigned driver files. If driver protection can be bypassed, time information can be modified\u003C\u002Fp>\u003Ch4>(2) WinHex\u003C\u002Fh4>\u003Cp>Paid version of WinHex supports write operations on hard disk files, which can be used to modify time information\u003C\u002Fp>\u003Ch3>Supplement, file resource cloning\u003C\u002Fh3>\u003Cp>Automate calls to Resource Hacker via PowerShell to clone resource information of executable files (exe, dll, scr, etc.)\u003C\u002Fp>\u003Cp>Download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fthreatexpress\u002Fmetatwin\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This tool does not modify file attributes\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Release files on the target system\u003C\u002Fh3>\u003Cp>Will change the time attributes of the parent directory (AccessTime, LastWriteTime, MFTChangeTime)\u003C\u002Fp>\u003Cp>You can use SetMace to view attribute changes\u003C\u002Fp>\u003Cp>To modify folder time attributes, use FileTimeControl_WinAPI from 0x03, which can modify the following three items:\u003C\u002Fp>\u003Cul>\u003Cli>CreateTime (Created)\u003C\u002Fli>\u003Cli>AccessTime (Accessed)\u003C\u002Fli>\u003Cli>LastWriteTime (Modified)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>To further clear operational traces, use WinHex to modify $STANDARD_INFORMATION (offset 0x10) and $FILE_NAME (offset 0x30) in the Master File Table\u003C\u002Fp>\u003Ch3>2. Overwrite existing files on the target system\u003C\u002Fh3>\u003Cp>Will change the time attributes of the original file (CreateTime, AccessTime, LastWriteTime, MFTChangeTime)\u003C\u002Fp>\u003Cp>You can use FileTimeControl_NTAPI to read and modify time attributes\u003C\u002Fp>\u003Cp>To further eliminate operational traces, it is necessary to use WinHex to modify the $STANDARD_INFORMATION (offset 0x10) and $FILE_NAME (offset 0x30) in the Master File Table.\u003C\u002Fp>\u003Ch2>0x05 Forensic Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Examine the MFTChangeTime attribute of files\u002Ffolders, located in two positions:\u003C\u002Fp>\u003Cul>\u003Cli>$STANDARD_INFORMATION (offset 0x10) in the Master File Table\u003C\u002Fli>\u003Cli>$FILE_NAME (offset 0x30) in the Master File Table\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If the MFTChangeTime is abnormal (later than the other three timestamps), it can generally be considered that the file has been illegally modified.\u003C\u002Fp>\u003Cp>The tool SetMace can be used.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods and details for modifying file attributes, shares two implementation codes (FileTimeControl_WinAPI and FileTimeControl_NTAPI), and provides forensic recommendations based on exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",6,"Onedaysec",4,"published","2026-02-02T07:25:19.683Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Modify NTFS File Time Attributes in Windows for Penetration Testing","NTFS file attributes, penetration testing, Windows forensics, file time modification, MFTChangeTime, SetFileTime, NtQueryInformationFile",null,false,[],{"docs":43,"hasNextPage":53},[44,4,45,46,47,48,49,50,51,52],1224,1222,1221,1220,1219,1218,1217,1216,1215,true,{"title":39,"description":39,"image":39},"2026-07-24T15:37:08.814Z","2026-07-23T16:02:41.630Z","draft","2026-07-23T16:17:30.154Z"]