Hide Navigation Hide TOC Suspicious Hyper-V Cmdlets (42d36aa1-3240-4db0-8257-e0118dcdd9cd) Adversaries may carry out malicious operations using a virtual instance to avoid detection Cluster A Galaxy A Cluster B Galaxy B Level Suspicious Hyper-V Cmdlets (42d36aa1-3240-4db0-8257-e0118dcdd9cd) Sigma-Rules Run Virtual Instance - T1564.006 (b5327dd1-6bf9-4785-a199-25bcbd1f4a9d) Attack Pattern 1 Hide Artifacts - T1564 (22905430-4901-4c2a-84f6-98243cb173f8) Attack Pattern Run Virtual Instance - T1564.006 (b5327dd1-6bf9-4785-a199-25bcbd1f4a9d) Attack Pattern 2