T1678 Delay Execution
Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms to obscure malicious activity, blend in with benign activity, and avoid scrutiny. Adversaries can perform this behavior within virtualization/sandbox environments or natively on host systems. Adversaries may utilize programmatic `sleep`…
Who uses it · with stories on Jábega
Sigma rules to hunt it
SigmaHQ has no rules for this technique.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.