Analytics BIOC Informational

VM Detection attempt on Linux

A Process executed a command and/or accessed a file that can be used to detect VM environments.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005) Discovery (TA0007)
ATT&CK techniques: Virtualization/Sandbox Evasion: System Checks (T1497.001)
Attacker's goals:

Avoid malware analysis by identifying execution from within sandboxes and virtual machines.

Investigative actions:

Review the process for additional malicious actions. Check for any additional alerts raised within the same context of the script.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • VM Detection attempt on Linux with further reconnaissance commands Medium (parent: Informational) Adds System Owner/User Discovery (T1033)
  • VM Detection attempt on Linux using an unpopular technique Low (parent: Informational)