The Clock: When the Armory Fires
TI-2026-075W ยท The Armory, Part W Confidence: HIGH โ direct honeypot temporal analysis + multi-source corroboration Classification: TLP:WHITE
A third fingerprint
The series has, so far, read two fingerprints. The HASSH names the weapon โ the tool an attacker carries. The reused SSH key names the hand โ the operator who built the toolkit. Both are properties of the connection itself. This letter is about a third fingerprint that is not in the connection at all, but in when the connection happens: the clock.
The honeypot holds 3,732 temporal_correlation edges โ links between source addresses that fire in the same narrow windows โ and has resolved attacking activity into 57 coordinated campaigns. These are not clustered by tool or by key. They are clustered by time: by the observation that certain addresses light up together, again and again, in the same tight intervals. And that synchronisation is evidence in its own right, because things that act together in time are usually controlled together.
Time, it turns out, is as characteristic as any handshake. When a fleet fires binds it as surely as what it fires โ and, as we will see, the rhythm of an operation can separate a machine from a human hand without any other signal at all.
Timing binds what tool and key cannot
The power of the temporal axis is that it reaches operators the other two signals miss. Consider an operator who is careful: they vary their tooling so no single HASSH unites their fleet, and they rotate their keys so no reused key betrays them. Against tool-clustering and key-clustering, they are invisible โ each of their nodes looks like an unrelated stranger.
But if those nodes still fire together โ if they all wake in the same five-minute window, night after night โ the synchronisation gives them away. Two addresses that share no fingerprint and no key can still be proven coordinated by the simple fact that they act in lockstep, and lockstep does not happen by chance across unrelated actors. The 3,732 temporal-correlation edges are exactly these bindings: coordination visible in time even when it is invisible everywhere else. Add the clock as a third clustering axis alongside the weapon and the hand, and you close a gap the careful operator was relying on โ because they can vary the tool and rotate the key, but if the whole fleet is driven by one schedule, the schedule is the tell.
This is also what separates a campaign from a mere tool cohort. The version fleets (075P) were cohorts โ everyone running the same library, unrelated except by their toolchain. A campaign is tighter: a set of addresses running a tool in a coordinated schedule, launched and paused together. The 57 campaigns are populations with a shared clock, and the clock is what turns a crowd into an operation.
Every fleet keeps its own time
The series has already recorded distinct temporal signatures without stopping to name them โ and collected, they show that the rhythm of a fleet is as diagnostic as its fingerprint.
The residential IoT botnet (The Resident, 075H) fired each node in a single tight burst โ around fifty sessions crammed into five minutes, then gone, the churn of a compromised device waking, hammering, and being handed a new address. The Go swarm (The Compiled Swarm, 075L) logged 780 sessions from one IP in ninety minutes โ the dense, sustained output of a goroutine concurrency engine. The manual PuTTY operator (By Hand, 075M) appeared sparsely, a handful of sessions spread across months โ the patient cadence of a person.
Three fleets, three completely different clocks: the botnet's churn, the swarm's concentration, the human's patience. The pace and shape of activity over time is a signature in itself, and often a defender can classify a source by its rhythm alone, before a single credential or command is seen. Dense, short, machine-paced bursts mean automation. Sparse, long-lived, irregular activity means a hand. The clock classifies before the content arrives.
The rhythm that reveals the human
The most valuable thing the clock does is separate the human from the machine, because automation and people keep fundamentally different time.
A scheduled scanner runs steady-state. A cron job does not sleep; it fires at the same rate at three in the morning as at three in the afternoon, indifferent to the wall clock, because there is no one there to be tired. A human operator does the opposite: they cluster at working hours, because there is someone there, and that someone has a day. Prior temporal analysis โ Waves and Tides (TI-2026-054E) โ found exactly this split: campaign launches recurring at a 19:00 UTC peak while the automation itself ran continuously. The machine ran around the clock; the human pressed the launch button at a consistent, human hour.
That gives a defender two things at once. First, a way to tell automated activity from human-driven activity: steady-state is a machine, working-hours clustering is a hand. Second, and more valuable, a way to find the exact moments a human intervened. In an otherwise steady automated fleet, the deviations from steady-state โ the sudden burst, the new campaign launch, the behaviour change, all landing at a consistent human hour โ mark the points where a person made a decision. Those transition points are the most investigation-worthy events in the whole timeline, because they are where the automation stopped and the operator started, where choices were made rather than schedules executed.
The one clock the operator forgets to hide
There is a final gift in the timing, and it is the temporal twin of the reused key. An operator controls their IPs' geolocation โ they rent addresses wherever they like, and the flag on an address tells you where they shopped, not where they are (075G). But they do not, usually, control the hour they choose to work.
When campaign launches recur at a consistent wall-clock time, that time leaks the operator's timezone and working pattern. The machine runs on UTC, but the person who starts it runs on their own local clock, and over many launches that local clock narrows the operator's likely region of activity โ without any need to trust an IP's geolocation, which they obfuscate, because they do not think to obfuscate the hour. It is the same shape of failure as the reused key: a free tell, available for nothing, that the operator gives away because it never occurs to them that anyone is correlating it. They spend enormous effort hiding where their addresses are and forget entirely to hide when their hands are on the keyboard.
This is coarse intelligence โ a region and a working pattern, not a name โ and it must be stated with appropriate uncertainty. But it is genuine, and it is durable, because it rides on the one thing the operator cannot easily fake without changing their own life: the time of day they choose to work.
Reading the clock โ for defenders
- Add temporal coordination as a third clustering axis. Alongside HASSH (weapon) and reused key (hand), cluster on synchronized timing. Addresses that repeatedly fire in the same tight window are one operation regardless of how diverse their tools and keys are.
- Classify on rhythm. Burst density and cadence classify a source before its content is seen: tight machine-paced bursts imply automation, sparse long-lived activity implies a human. It is a free early classifier.
- Hunt the human-intervention points. Deviations from steady-state at consistent human hours mark where an operator made a decision in an automated fleet โ the most investigation-worthy moments in the timeline.
- Estimate timezone from launch times. Consistent wall-clock launch/burst times leak the operator's working pattern and region. Unlike IP geolocation, it is not attacker-controlled โ track it across many events.
The whole series has read the connection: what tool made it, whose key rode inside it. This letter reads the space between connections โ the schedule, the burst, the hour โ and finds that it, too, is a fingerprint. The weapon says what; the key says who; the clock says when, and in the when is hidden both the coordination that binds a fleet and the human rhythm the automation was supposed to conceal. The operator watched the address and forgot the hour. The honeypot watched the hour.
Indicators (TLP:WHITE)
| Indicator | Type | Meaning |
|---|---|---|
| Addresses firing in the same narrow window repeatedly | Attribution signal | Temporal coordination โ one operation despite tool/key diversity (3,732 edges) |
| Coordinated launch-and-pause schedule | Campaign signal | A campaign, not a mere tool cohort (57 detected) |
| Tight machine-paced bursts vs sparse long-lived activity | Classifier | Automation vs human operator โ free, pre-content |
| Steady-state broken by activity at a consistent human hour | Detection priority | Human-intervention point โ an operator decision |
| Recurring wall-clock launch time (e.g. ~19:00 UTC) | Attribution | Leaks operator timezone/working pattern โ not attacker-controlled |
Cross-references
- TI-2026-054E โ Waves and Tides โ the 19:00 UTC human-operator launch peak.
- TI-2026-075U โ The Key Ring โ the clock is the third attribution axis after weapon and hand.
- TI-2026-075M โ By Hand โ the human's sparse cadence vs the machine's steady state.
- TI-2026-075L / 075H โ The Compiled Swarm / The Resident โ the burst signatures of automated fleets.
- TI-2026-075I โ The Weapon Is Never the Point โ the synthesis: what, who, and now when.
This dossier documents observed adversary temporal patterns for defensive purposes. Timezone inference from launch timing is coarse and probabilistic; it is offered as a bounded intelligence signal, not an identification. TLP:WHITE.