Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1124
MITRE ATT&CK Technique

T1124: System Time Discovery

ShareXLinkedInRedditHN

An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or <code>systemsetup</code> on macOS.(Citation: MSDN System Time)(Citation: Technet Windows Time Service)(Citation: systemsetup mac time) These time settings may also be synchronized between systems and services in an enterprise network, typically accomplished with a network time server within a domain.(Citation: Mac Time Sync)(Citation: linux system time) System time information may be gathered in a number of ways, such as with [Net](https://attack.mitre.org/software/S0039) on Windows by performing <code>net time \\hostname</code> to gather the system time on a remote system. The victim's time zone may also be inferred from the current system time or gathered by using <code>w32tm /tz</code>.(Citation: Technet Windows Time Service) In addition, adversaries can discover device uptime through functions such as <code>GetTickCount()</code> to determine how long it has been since the system booted up.(Citation: Virtualization/Sandbox Evasion) On network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show clock detail` can be used to see the current time configuration.(Citation: show_clock_detail_cisco_cmd) On ESXi servers, `esxcli system clock get` can be used for the same purpose. In addition, system calls – such as <code>time()</code> – have been used to collect the current time on Linux devices.(Citation: MAGNET GOBLIN) On macOS systems, adversaries may use commands such as <code>systemsetup -gettimezone</code> or <code>timeIntervalSinceNow</code> to gather current time zone information or current date and time.(Citation: System Information Discovery Technique)(Citation: ESET DazzleSpy Jan 2022) This information could be useful for performing other techniques, such as executing a file with a [Scheduled Task/Job](https://attack.mitre.org/techniques/T1053)(Citation: RSA EU12 They're Inside), or to discover locality information based on time zone to assist in victim targeting (i.e. [System Location Discovery](https://attack.mitre.org/techniques/T1614)). Adversaries may also use knowledge of system time as part of a time bomb, or delaying execution until a specified date/time.(Citation: AnyRun TimeBomb)

Tactics
Discovery
Platforms
ESXi, Linux, macOS, Network Devices, Windows

▪Used by groups (14)

G0010TurlaG0012DarkhotelG0032Lazarus GroupG0046FIN7G0060BRONZE BUTLERG0089The White CompanyG0094KimsukyG0114ChimeraG0121SidewinderG0126HigaisaG0128ZIRCONIUMG1012CURIUMG1017Volt TyphoonG1048UNC3886

▪Software using this technique (83)

S0011TaidoormalwareS0013PlugXmalwareS0017BISCUITmalwareS0039NettoolS0091EpicmalwareS0098T9000malwareS0115CrimsonmalwareS0126ComRATmalwareS0139PowerDukemalwareS0140ShamoonmalwareS0148RTMmalwareS0149MoonWindmalwareS0237GravityRATmalwareS0238ProxysvcmalwareS0251ZebrocymalwareS0260InvisiMolemalwareS0264OopsIEmalwareS0267FELIXROOTmalwareS0268BisonalmalwareS0275UPPERCUTmalwareS0330Zeus PandamalwareS0331Agent TeslamalwareS0335CarbonmalwareS0344AzorultmalwareS0351CannonmalwareS0353NOKKImalwareS0373AstarothmalwareS0376HOPLIGHTmalwareS0380StoneDrillmalwareS0396EvilBunnymalwareS0417GRIFFONmalwareS0439OkrummalwareS0450SHARPSTATSmalwareS0455MetamorfomalwareS0466WindTailmalwareS0467TajMahalmalwareS0471build_downermalwareS0501PipeMonmalwareS0531GrandoreiromalwareS0534BazarmalwareS0554EgregormalwareS0559SUNBURSTmalwareS0574BendyBearmalwareS0586TAINTEDSCRIBEmalwareS0588GoldMaxmalwareS0596ShadowPadmalwareS0603StuxnetmalwareS0608ConfickermalwareS0615SombRATmalwareS0622AppleSeedmalwareS0650QakBotmalwareS0657BLUELIGHTmalwareS0660ClamblingmalwareS0673DarkWatchmanmalwareS0678TorismamalwareS0690Green LambertmalwareS0692SILENTTRINITYtoolS0694DRATzarusmalwareS1033DCSrvmalwareS1034StrifeWatermalwareS1043ccf32malwareS1044FunnyDreammalwareS1051KEYPLUGmalwareS1053AvosLockermalwareS1064SVCReadymalwareS1081BADHATCHmalwareS1087AsyncRATtoolS1111DarkGatemalwareS1134DEADWOODmalwareS1147NightdoormalwareS1148Raccoon StealermalwareS1159DUSTTRAPmalwareS1178ShrinkLockermalwareS1227StarProxymalwareS1228PUBLOADmalwareS1233PAKLOGmalwareS1244Medusa RansomwaremalwareS1246BeaverTailmalwareS9001SystemBCmalwareS9010GlassWormmalwareS9020LODEINFOmalwareS9042CanisterWormmalwareS9043Mini Shai-Huludmalware

▪Reference

T1124on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.