Python can be used to modify timestamps or timestomp files:
import os
import time
new_time = 1672531200 # UNIX timestamp (Jan 1, 2023)
os.utime("/path/to/file", (new_time, new_time))
timestomping using Python
0001-01-01
Python can be used to modify timestamps or timestomp files:
import os
import time
new_time = 1672531200 # UNIX timestamp (Jan 1, 2023)
os.utime("/path/to/file", (new_time, new_time))
Linux Persistence: Modular Software
2025-04-17 DFIR CTF persistence linux persistence apache asterisk
Linux Persistence: Web Shells
2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP
Linux Persistence: Rootkits
2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking
Defanging Linux LKM Rootkits With cleanup_module()
2025-04-05 Linux LKM rootkits EDR hooks incident response Linux LKM rootkit