Skip to content

Hardware Clock Time

Evidence: Hardware Clock Time
Description: Display the current hardware clock time
Category: System
Platform: esxi
Short Name: hwclk
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

Hardware clock (RTC) maintains system time independently of the operating system. Time accuracy is critical for forensic timeline analysis, log correlation, and detecting time-based anti-forensics techniques like timestomping or clock manipulation to hide malicious activities.

This collector gathers structured data about hardware clock time.

FieldDescriptionExample
AccessTimeAccess Time2023-10-15 14:30:25+03:00
AccessCountAccess Count123
URLURLExample value
BrowserBrowserExample value
TitleTitleExample value
VisitDurationVisit DurationExample value
ReferrerReferrerExample value
TypedCountTyped Count123
IsHiddenIs Hiddentrue
TransitionTypeTransition TypeExample value
VisitIDVisit ID123
TransitionQualifiersTransition QualifiersExample value
UserUserExample value
ProfileProfileExample value
HistoryFilePathHistory File PathExample value

This collector captures the current hardware clock time from the system’s Real-Time Clock (RTC), recording the timestamp at collection to establish a time reference point for the investigation.

Hardware clock comparison with system time reveals time synchronization issues, detects deliberate clock manipulation used to evade detection or hide activity timing, and provides an independent time source for validating event timelines when system time may have been tampered with.