For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security tools detection attempt

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Stealth (TA0005), Discovery (TA0007)

ATT&CK Technique

Virtualization/Sandbox Evasion (T1497), Virtualization/Sandbox Evasion: System Checks (T1497.001)

Severity

Informational

Description

A script has executed commands that can be used to detect security tools.

Attacker's Goals

Avoid detection by identifying execution alongside security tools that may alert on a malicious script.

Investigative actions

  • Review the script for additional malicious actions.

  • Check for any additional alerts raised within the same context of the script.

Was this helpful?