T1497 Virtualization/Sandbox Evasion
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Powershell Detect Virtualization Environmentmediumtest · windows
- System Information Discovery Using System_Profilermediumtest · macos
- System Information Discovery Via Sysctl - MacOSmediumtest · macos
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.