{"id":"T1497.003","name":"Time Based Checks","url":"https://attack.mitre.org/techniques/T1497/003","tactics":["stealth","discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0141","stix_id":"x-mitre-detection-strategy--90b6ef43-3f63-47c5-af59-ed4f95cc9c87","name":"Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution","url":"https://attack.mitre.org/detectionstrategies/DET0141","analytics":[{"id":"AN0396","stix_id":"x-mitre-analytic--10c89810-d298-42d6-80dd-1228e737e33f","name":"Analytic 0396","description":"Process creation involving suspicious delays (e.g., Sleep, ping -n loops, WaitForSingleObject), followed by sensitive system access or lateral movement behaviors.","url":"https://attack.mitre.org/detectionstrategies/DET0141#AN0396","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"SleepDurationThreshold","description":"Defines maximum allowable sleep duration in milliseconds before triggering anomaly detection."},{"field":"TimeBetweenExecutionAndNextStage","description":"Temporal window between initial process and next stage (e.g., lateral movement or persistence), used to correlate dormant activity."},{"field":"UserContext","description":"Whether the activity occurs in SYSTEM or user context may affect legitimacy scoring."}],"live":true,"detection_strategies":["DET0141"],"techniques":["T1497.003"]},{"id":"AN0397","stix_id":"x-mitre-analytic--2bbe41df-b8a6-4503-8fb0-028b7387cb1d","name":"Analytic 0397","description":"Script-based execution of sleep loops or time delay commands (e.g., sleep, ping delay, while-loops) followed by file creation or network connections.","url":"https://attack.mitre.org/detectionstrategies/DET0141#AN0397","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve of sleep or ping command within script interpreted by bash/python","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"file write after sleep delay","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"SleepLoopCount","description":"Defines how many loop iterations or sleep cycles are considered anomalous in the monitored environment."},{"field":"ExecutionScriptType","description":"Identifies which scripting interpreter is used (e.g., bash, python, perl) to adjust detection logic."}],"live":true,"detection_strategies":["DET0141"],"techniques":["T1497.003"]},{"id":"AN0398","stix_id":"x-mitre-analytic--fbbe7372-5d33-4181-a68a-e68f5da94df7","name":"Analytic 0398","description":"Use of `usleep`, `nanosleep`, or `NSTimer` calls in executables or binaries with no GUI interaction, especially followed by disk/network activity.","url":"https://attack.mitre.org/detectionstrategies/DET0141#AN0398","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"application logs referencing NSTimer, sleep, or launchd delays","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-unifiedlog"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AppBundleIdentifier","description":"Correlate with known/expected signed apps vs. unsigned binaries to reduce noise."},{"field":"TimeToNextEvent","description":"Minimum time expected between process start and observable I/O for normal apps."}],"live":true,"detection_strategies":["DET0141"],"techniques":["T1497.003"]}],"live":true,"version":"1.0","techniques":["T1497.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}