{"id":"T1547.003","name":"Time Providers","url":"https://attack.mitre.org/techniques/T1547/003","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0122","stix_id":"x-mitre-detection-strategy--9c4b0b07-df7f-4697-8cd1-0b95ff6a6361","name":"Detect Abuse of Windows Time Providers for Persistence","url":"https://attack.mitre.org/detectionstrategies/DET0122","analytics":[{"id":"AN0341","stix_id":"x-mitre-analytic--c223f997-8323-40c2-98c9-38a8a1779db4","name":"Analytic 0341","description":"Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0122#AN0341","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"RegistryPathScope","description":"May need to be tuned to only monitor `W32Time\\TimeProviders` subkey path for performance optimization"},{"field":"UserContext","description":"Should focus on activity from administrative or SYSTEM accounts"},{"field":"TimeWindow","description":"Controls correlation window between registry modification and DLL drop"},{"field":"DllPathEntropyThreshold","description":"Used for anomaly scoring on DLL path patterns (e.g., random names or temp directories)"}],"live":true,"detection_strategies":["DET0122"],"techniques":["T1547.003"]}],"live":true,"version":"1.0","techniques":["T1547.003"]}],"sigma_rules":[{"id":"e88a6ddc-74f7-463b-9b26-f69fc0d2ce85","title":"New TimeProviders Registered With Uncommon DLL Name","author":"frack113","status":"test","level":"high","date":"2022-06-19","modified":"2024-03-26","description":"Detects processes setting a new DLL in DllName in under HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time\\TimeProvider.\nAdversaries may abuse time providers to execute DLLs when the system boots.\nThe Windows Time service (W32Time) enables time synchronization across and within domains.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.003/T1547.003.md"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1547.003"],"path":"rules/windows/registry/registry_set/registry_set_timeproviders_dllname.yml","techniques":["T1547.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}