Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1124
MITRE ATT&CK Technique

T1124: System Time Discovery

ShareXLinkedInRedditHN

An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or <code>systemsetup</code> on macOS.(Citation: MSDN System Time)(Citation: Technet Windows Time Service)(Citation: systemsetup mac time) These time settings may also be synchronized between systems and services in an enterprise network, typically accomplished with a network time server within a domain.(Citation: Mac Time Sync)(Citation: linux system time) System time information may be gathered in a number of ways, such as with [Net](https://attack.mitre.org/software/S0039) on Windows by performing <code>net time \\hostname</code> to gather the system time on a remote system. The victim's time zone may also be inferred from the current system time or gathered by using <code>w32tm /tz</code>.(Citation: Technet Windows Time Service) In addition, adversaries can discover device uptime through functions such as <code>GetTickCount()</code> to determine how long it has been since the system booted up.(Citation: Virtualization/Sandbox Evasion) On network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show clock detail` can be used to see the current time configuration.(Citation: show_clock_detail_cisco_cmd) On ESXi servers, `esxcli system clock get` can be used for the same purpose. In addition, system calls – such as <code>time()</code> – have been used to collect the current time on Linux devices.(Citation: MAGNET GOBLIN) On macOS systems, adversaries may use commands such as <code>systemsetup -gettimezone</code> or <code>timeIntervalSinceNow</code> to gather current time zone information or current date and time.(Citation: System Information Discovery Technique)(Citation: ESET DazzleSpy Jan 2022) This information could be useful for performing other techniques, such as executing a file with a [Scheduled Task/Job](https://attack.mitre.org/techniques/T1053)(Citation: RSA EU12 They're Inside), or to discover locality information based on time zone to assist in victim targeting (i.e. [System Location Discovery](https://attack.mitre.org/techniques/T1614)). Adversaries may also use knowledge of system time as part of a time bomb, or delaying execution until a specified date/time.(Citation: AnyRun TimeBomb)

Tactics
Discovery
Platforms
ESXi, Linux, macOS, Network Devices, Windows

▪Used by groups (14)

G0010TurlaG0012DarkhotelG0032Lazarus Group

▪Software using this technique (81)

S0011TaidoormalwareS0013PlugXmalware

▪Reference

T1124on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

G0046FIN7
G0060BRONZE BUTLER
G0089The White Company
G0094Kimsuky
G0114Chimera
G0121Sidewinder
G0126Higaisa
G0128ZIRCONIUM
G1012CURIUM
G1017Volt Typhoon
G1048UNC3886
S0017BISCUITmalware
S0039Nettool
S0091Epicmalware
S0098T9000malware
S0115Crimsonmalware
S0126ComRATmalware
S0139PowerDukemalware
S0140Shamoonmalware
S0148RTMmalware
S0149MoonWindmalware
S0237GravityRATmalware
S0238Proxysvcmalware
S0251Zebrocymalware
S0260InvisiMolemalware
S0264OopsIEmalware
S0267FELIXROOTmalware
S0268Bisonalmalware
S0275UPPERCUTmalware
S0330Zeus Pandamalware
S0331Agent Teslamalware
S0335Carbonmalware
S0344Azorultmalware
S0351Cannonmalware
S0353NOKKImalware
S0373Astarothmalware
S0376HOPLIGHTmalware
S0380StoneDrillmalware
S0396EvilBunnymalware
S0417GRIFFONmalware
S0439Okrummalware
S0450SHARPSTATSmalware
S0455Metamorfomalware
S0466WindTailmalware
S0467TajMahalmalware
S0471build_downermalware
S0501PipeMonmalware
S0531Grandoreiromalware
S0534Bazarmalware
S0554Egregormalware
S0559SUNBURSTmalware
S0574BendyBearmalware
S0586TAINTEDSCRIBEmalware
S0588GoldMaxmalware
S0596ShadowPadmalware
S0603Stuxnetmalware
S0608Confickermalware
S0615SombRATmalware
S0622AppleSeedmalware
S0650QakBotmalware
S0657BLUELIGHTmalware
S0660Clamblingmalware
S0673DarkWatchmanmalware
S0678Torismamalware
S0690Green Lambertmalware
S0692SILENTTRINITYtool
S0694DRATzarusmalware
S1033DCSrvmalware
S1034StrifeWatermalware
S1043ccf32malware
S1044FunnyDreammalware
S1051KEYPLUGmalware
S1053AvosLockermalware
S1064SVCReadymalware
S1081BADHATCHmalware
S1087AsyncRATtool
S1111DarkGatemalware
S1134DEADWOODmalware
S1147Nightdoormalware
S1148Raccoon Stealermalware
S1159DUSTTRAPmalware
S1178ShrinkLockermalware
S1227StarProxymalware
S1228PUBLOADmalware
S1233PAKLOGmalware
S1244Medusa Ransomwaremalware
S1246BeaverTailmalware
S9001SystemBCmalware
S9010GlassWormmalware
S9020LODEINFOmalware