1200KM / simulation
T1497.001 System Checks — Attack Simulation
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before…
Technique description
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Check if System Integrity Protection is enabled
Procedure 2b73cd9b-b2fb-4357-b9d7-c73c41d9e945; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Detect Virtualization Environment via WMI Manufacturer/Model Listing (Windows)
Procedure 4a41089a-48e0-47aa-82cb-5b81a463bc78; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Detect Virtualization Environment (Windows)
Procedure 502a7dc4-9d6f-4d28-abf2-f0e84692562d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Detect Virtualization Environment using sysctl (hw.model)
Procedure 6beae646-eb4c-4730-95be-691a4094408c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Detect Virtualization Environment via ioreg
Procedure a960185f-aef6-4547-8350-d1ce16680d09; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Detect Virtualization Environment (Linux)
Procedure dfbd1a21-540d-4574-9731-e852bd6fe840; elevation required; cleanup not declared. Not executed or individually validated.
- Detect Virtualization Environment using system_profiler
Procedure e04d2e89-de15-4d90-92f9-a335c7337f0f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Detect Virtualization Environment (FreeBSD)
Procedure e129d73b-3e03-4ae9-bf1e-67fc8921e0fd; elevation required; cleanup not declared. Not executed or individually validated.
- Turla Mosquito Sandbox Evasion via SetupDiGetClassDevs Check
Procedure eed8b13f-ad93-4b1e-8fa8-57cd400a0399; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.