DFIR Tech Blog – an AI playground

Deutsch English
Foto von Thomas Bormans auf Unsplash.com

Weaponized Timestamps: Anti-Forensics in 2026 Ransomware

09.08.2026 anti-forensicsransomwaretimestompingntfs-forensics

When Ransomware Writes Its Own Timeline

In 2026, ransomware operators are investing as much effort in sabotaging forensic reconstruction as in encryption itself. The latest Picus Blue Report examines the ten least-prevented ransomware families and reveals just how systematically anti-forensic tradecraft has become standard practice. Ten ransomware families with the lowest 2026 prevention scores share evasion tradecraft built to stay hidden, with Play recording the lowest prevention score at 13%, followed by BlackByte at 25%.

BlackByte 2.0’s playbook is particularly instructive. The ransomware uses the well-known ping-delay-then-delete trick so both its collector and its encryptor remove themselves after finishing, with the ping providing a short delay so the file handle is released first. That alone would already complicate an investigation, but the group goes further: it also timestomps the encrypted files and the ransom note, backdating them to 2000-01-01 to frustrate timeline forensics.

Other families rely on complementary techniques. Black Kingdom deletes the PowerShell PSReadLine history file before encrypting so responders cannot replay the operator’s commands. Play, meanwhile, favors disguise over deletion: it stages its tooling and the ransom note in a legitimate-looking path and ships a service binary named to mimic the genuine Sysinternals PsExec service, so it blends in with expected admin tooling.

The NTFS Arms Race: $SI, $FN, and the Limits of Timestomp Detection

Timestomping (MITRE ATT&CK T1070.006) is nothing new to forensic examiners, but detection methodology is racing to keep pace with evasion. The textbook check compares two distinct attribute sets inside the Master File Table: there are two attribute types in the MFT recording timestamps — $STANDARD_INFORMATION works at user-level space using API calls, while $FILE_NAME works at the kernel level and can only be modified by the kernel. A discrepancy between $SI and $FN creation times has long been treated as a strong red flag.

But that shortcut has limits. As practitioners caution: the two most commonly taught detection methods — comparing $SI and $FN timestamps, and looking for nanosecond patterns like “0000000” that suggest automated tools such as Metasploit — rest on two fallacies, since neither $FILE_NAME immutability nor nanosecond precision is truly beyond an attacker’s reach. Sophisticated operators now timestomp both attribute sets, nanosecond precision included.

More resilient evidence sits deeper in the file system. For deleted or renamed artifacts, the USN Journal frequently provides the decisive lead: the USN Journal gives investigators the original file name and keeps records of changes to the file, like when the file is renamed. The $LogFile sequence number offers a further layer of corroboration, as a recent forensic write-up demonstrated: the $LogFile Sequence Number was the smoking gun that revealed the timestomped file. Practitioners at Kroll confirm this pattern from real-world engagements: a common anti-forensic technique Kroll has observed during incident response engagements is timestomping — the alteration of timestamps of a file on an NTFS file system, commonly utilized by threat actors to hide their tools on the victim’s file system.

What This Means for DFIR Teams

Tools like Eric Zimmerman’s MFTECmd or istat make it straightforward to extract $SI/$FN discrepancies from a disk image at scale, but they don’t substitute for a critical understanding of that method’s blind spots. Analysts who rely solely on MFT timestamp comparisons risk building a timeline on ground attackers can deliberately shift beneath them. The practical takeaway: USN Journal entries, $LogFile records, and Prefetch/Amcache correlation need to function as redundant, mutually validating evidence sources — precisely because ransomware crews are now professionalizing their anti-forensic capabilities with the same rigor they once reserved for encryption routines.

← Back to overview