Analytics BIOC Informational

VM Detection attempt

A script has executed commands that can be used to detect VM environments.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Discovery (TA0007)
ATT&CK techniques: Virtualization/Sandbox Evasion: System Checks (T1497.001)
Attacker's goals:

Avoid malware analysis by identifying execution from within sandboxes and virtual machines.

Investigative actions:

Review the script for additional malicious actions. Check for any additional alerts raised within the same context of the script.

Test period:
N/A (single event)
Deduplication:
1 Day