PowerShell Timestomping via File Attribute Modification - T1070.006
Detects the use of PowerShell commands that modify file system metadata (e.g., CreationTime, LastWriteTime, LastAccessTime). This technique, often referred to as 'timestomping', is used by adversaries to manipulate file timestamps to evade detection or hide activity.
Microsoft Sentinel (KQL)

