T1497.001 System Checks
Subtécnica de T1497 Virtualization/Sandbox Evasion
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Powershell Detect Virtualization Environmentmediumtest · windows
- System Information Discovery Using System_Profilermediumtest · macos
- System Information Discovery Via Sysctl - MacOSmediumtest · macos
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.