1200KM / detection
T1497.001 System Checks — Detection Rules
Detection workspace for T1497.001 System Checks: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- System Information Discovery Via Sysctl - MacOS · test · medium · {"product":"macos","category":"process_creation"}
- System Information Discovery Using System_Profiler · test · medium · {"product":"macos","category":"process_creation"}
- Powershell Detect Virtualization Environment · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0168 Virtualization/Sandbox Evasion via System Checks across Windows, Linux, macOS
AN0478 Analytic 0478
Script or binary performs a rapid sequence of system discovery checks (e.g., CPU count, RAM size, registry keys, running processes) indicative of VM detection
AN0479 Analytic 0479
Shell script or binary uses multiple system commands (e.g., dmidecode, lscpu, lspci) in quick succession to detect virtualization environment
AN0480 Analytic 0480
Bash, Swift, or Objective-C programs enumerate system profile, I/O registry, or inspect kernel extensions to identify VM artifacts
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.