Analytics BIOC Informational

Security tools detection attempt

A script has executed commands that can be used to detect security tools.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Discovery (TA0007)
ATT&CK techniques: Virtualization/Sandbox Evasion (T1497) Virtualization/Sandbox Evasion: System Checks (T1497.001)
Attacker's goals:

Avoid detection by identifying execution alongside security tools that may alert on a malicious script.

Investigative actions:

Review the script for additional malicious actions. Check for any additional alerts raised within the same context of the script.

Test period:
N/A (single event)
Deduplication:
1 Day