For the complete documentation index, see llms.txt. This page is also available as Markdown.

VM Detection attempt on Linux

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Stealth (TA0005), Discovery (TA0007)

ATT&CK Technique

Virtualization/Sandbox Evasion: System Checks (T1497.001)

Severity

Informational

Description

A Process executed a command and/or accessed a file that can be used to detect VM environments.

Attacker's Goals

Avoid malware analysis by identifying execution from within sandboxes and virtual machines.

Investigative actions

  • Review the process for additional malicious actions.

  • Check for any additional alerts raised within the same context of the script.

Variations

VM Detection attempt on Linux with further reconnaissance commands

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005), Discovery (TA0007), Discovery (TA0007)

ATT&CK Technique

Virtualization/Sandbox Evasion: System Checks (T1497.001), System Owner/User Discovery (T1033)

Severity

Medium

Description

A Process executed a command and/or accessed a file that can be used to detect VM environments.

Attacker's Goals

Avoid malware analysis by identifying execution from within sandboxes and virtual machines.

Investigative actions

  • Review the process for additional malicious actions.

  • Check for any additional alerts raised within the same context of the script.

VM Detection attempt on Linux using an unpopular technique

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005), Discovery (TA0007)

ATT&CK Technique

Virtualization/Sandbox Evasion: System Checks (T1497.001)

Severity

Low

Description

A Process executed a command and/or accessed a file that can be used to detect VM environments.

Attacker's Goals

Avoid malware analysis by identifying execution from within sandboxes and virtual machines.

Investigative actions

  • Review the process for additional malicious actions.

  • Check for any additional alerts raised within the same context of the script.

Was this helpful?