Times and Time Zones

Timestamps are stored in UTC and displayed in the time zone you choose. Worth setting deliberately before you correlate anything against another system.

Stairwell records time-based fields such as first seen and last seen in UTC. The interface can display them in a different time zone, set per user.

That is the whole mechanism, and it has one consequence worth planning for.

Why it matters when you correlate

Almost every investigation compares a Stairwell timestamp against something else: an EDR alert, a proxy log, a change ticket, a ransom note's own file times. Those systems have their own display settings, and a machine's local clock is a third answer again.

So when you write down "the file arrived at 02:40", write the zone with it. The single most common error in an incident timeline is two timestamps from two tools in two zones, compared as though they were the same, producing a sequence of events that never happened.

This bites hardest in the places where sequence is the finding: Run-to-Ground works within 24 hours either side of arrival, and reading a dwell time from sightings is an exercise in ordering. Both are robust to a consistent offset and neither is robust to an unnoticed one.

Set your display zone deliberately at the start, rather than discovering mid-incident that you have been reading UTC as local for an hour. If your team spans regions, agreeing to read Stairwell in UTC is the simplest convention, because it is what is stored and it needs no conversion.

What should I read next?


Did this page help you?