본문으로 바로가기

ATT&CK 기법 · Stealth · Discovery

Virtualization/Sandbox Evasion T1497

이 기법을 다룬 REVELARE 한국어 위협 분석 7 · Stealth · Discovery

이 기법을 다룬 분석

MITRE 공식 정의

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payload

플랫폼: Linux, macOS, Windows
Virtualization/Sandbox Evasion (T1497) — ATT&CK 기법 분석 | REVELARE