VM Detection attempt on Linux
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Stealth (TA0005), Discovery (TA0007)
ATT&CK Technique
Virtualization/Sandbox Evasion: System Checks (T1497.001)
Severity
Informational
Description
A Process executed a command and/or accessed a file that can be used to detect VM environments.
Attacker's Goals
Avoid malware analysis by identifying execution from within sandboxes and virtual machines.
Investigative actions
Review the process for additional malicious actions.
Check for any additional alerts raised within the same context of the script.
Variations
PreviousUser signed in to an application via Power Automate for the first time
NextVM Detection attempt
Was this helpful?
