Skip to content

Hide Navigation Hide TOC

Powershell Detect Virtualization Environment (d93129cd-1ee0-479f-bc03-ca6f129882e3)

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox

Cluster A Galaxy A Cluster B Galaxy B Level
System Checks - T1497.001 (29be378d-262d-4e99-b00d-852d573628e6) Attack Pattern Powershell Detect Virtualization Environment (d93129cd-1ee0-479f-bc03-ca6f129882e3) Sigma-Rules 1
System Checks - T1497.001 (29be378d-262d-4e99-b00d-852d573628e6) Attack Pattern Virtualization/Sandbox Evasion - T1497 (82caa33e-d11a-433a-94ea-9b5a5fbef81d) Attack Pattern 2