System time changes are logged by the security event 4616. Legit system time changes will have:
- svchost.exe as process name
- NT AUTHORITY\LOCAL SERVICE as account name
References:
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4616
No comments:
Post a Comment