Join our Newsletter — 33% off our NHI Course

NtSetInformationFile

NtSetInformationFile is a Windows system call used to set file information, including metadata such as timestamps and attributes. Security researchers and attackers can abuse it to modify file times at a low level, which makes the resulting values harder to interpret through standard user-facing tools.

What NtSetInformationFile Changes at the File-System Layer

NtSetInformationFile is a low-level Windows system call for changing file information directly, including metadata such as timestamps and attributes. Because it works below many user-facing abstractions, it can alter what investigators or tools later see without changing file content.

That makes it important to distinguish between the file’s real activity and the metadata record attached to it. The call is part of normal operating-system behavior, but its directness gives both administrators and attackers a precise way to influence file state.

Why Timestamps and Attributes Matter

File metadata is not just administrative decoration. Timestamps, attribute flags, and related information often help analysts reconstruct execution order, user activity, staging, and cleanup. If those fields are changed deliberately, the timeline becomes less trustworthy even when the underlying file still exists.

In practice, this means NT-level metadata changes can interfere with forensic interpretation, tamper-evidence, and routine operations that depend on file age or file state. The underlying content may be unchanged while the evidence trail around it is altered.

How Low-Level Metadata Changes Are Used

Benign software may use this system call for maintenance, synchronization, migration, or archival workflows that need to preserve or adjust file state precisely. But the same capability is also useful when someone wants to mask when a file was created, modified, or staged.

Attackers may abuse that precision to reduce the visibility of suspicious activity, especially when they want file timestamps to look ordinary after dropper execution, tool transfer, or post-compromise cleanup. The abuse is not about breaking the file, it is about shaping the metadata around it.

What Security Teams Should Understand About Visibility

NtSetInformationFile is a reminder that user-facing properties can be imperfect indicators of file history. Security tooling that relies only on explorer views or simple file listings may miss low-level metadata manipulation, so analysts need to correlate file state with event logs, process activity, and other evidence.

It also means defenders should treat suspicious metadata edits as a potential sign of post-exploitation activity or deliberate hiding, not just as a cosmetic change. The value of the call is in its precision, and that same precision is what makes it relevant to investigation.

Risk and Threat Considerations

Low-level file metadata changes can undermine forensic confidence, retention workflows, and any control process that depends on trustworthy timestamps or attributes. When the change is used to conceal activity, the main risk is not the file itself but the distortion of evidence around it.

Failure mechanism: A process with sufficient file access uses the native call to rewrite timestamps or attributes, leaving the file present but altering the metadata that analysts and tools rely on for chronology and attribution.

Impact: Investigators may misread execution order, miss staging or tampering, or understate the age and provenance of a file, which can delay detection and weaken incident reconstruction.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1070.006 — Timestomp Covers file timestamp manipulation to obscure activity and hinder analysis
Recommendation — Correlate timestamp anomalies with host telemetry and hunt for file tampering patterns.
NIST SP 800-53 Rev 5 AU-3 — Content of Audit Records Supports logging enough file activity detail to reconstruct suspicious metadata changes
Recommendation — Record file-change context so altered metadata can be investigated with supporting evidence.
CIS Controls v8 CIS-8 — Audit Log Management Addresses retaining and reviewing logs needed to detect and investigate metadata abuse
Recommendation — Centralize and review file activity logs to spot suspicious low-level metadata modification.

Practitioner Guidance

What to watch for: Treat unexpected timestamp or attribute changes as a signal to correlate file metadata with process creation, image load, and other host telemetry. Metadata that changes without a matching operational reason deserves scrutiny because the low-level path can hide what standard views would otherwise show.

Practitioner takeaway: The important question is not only whether a file exists, but whether its metadata can still be trusted as an evidence source.