Analytics BIOC
Informational
✕
VM Detection attempt
A script has executed commands that can be used to detect VM environments.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Discovery (TA0007)
ATT&CK techniques: Virtualization/Sandbox Evasion: System Checks (T1497.001)
Attacker's goals:
Avoid malware analysis by identifying execution from within sandboxes and virtual machines.
Investigative actions:
Review the script for additional malicious actions. Check for any additional alerts raised within the same context of the script.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day