{"id":"T1497","name":"Virtualization/Sandbox Evasion","url":"https://attack.mitre.org/techniques/T1497","tactics":["stealth","discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0046","stix_id":"x-mitre-detection-strategy--7f5dde79-7872-48dd-8718-cd2e10d7cbfc","name":"Detection Strategy for T1497 Virtualization/Sandbox Evasion","url":"https://attack.mitre.org/detectionstrategies/DET0046","analytics":[{"id":"AN0127","stix_id":"x-mitre-analytic--55808d73-7aa9-4f2c-8122-8e60bf14f4c6","name":"Analytic 0127","description":"Execution of discovery commands or API calls for virtualization artifacts (e.g., registry keys, device drivers, services), sleep/skipped execution behavior, or sandbox evasion DLLs before payload deployment.","url":"https://attack.mitre.org/detectionstrategies/DET0046#AN0127","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Time range in which multiple discovery processes or sleep/delay operations are executed to avoid sandbox detonation."},{"field":"KnownVMArtifactList","description":"Registry paths, DLLs, services or device names indicative of sandbox/VM environments."}],"live":true,"detection_strategies":["DET0046"],"techniques":["T1497"]},{"id":"AN0128","stix_id":"x-mitre-analytic--412b76ec-d44e-4064-9dc1-32cf793f0176","name":"Analytic 0128","description":"Execution of commands to enumerate virtualization-related files or processes (e.g., '/sys/class/dmi/id/product_name', dmesg, lscpu, lspci), or querying hypervisor interfaces prior to malware execution.","url":"https://attack.mitre.org/detectionstrategies/DET0046#AN0128","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve or syscall invoking vm artifact check commands (e.g., dmidecode, lspci, dmesg)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"sleep function usage or loops (nanosleep, usleep) in scripts","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TimeWindow","description":"Duration between VM discovery commands and payload execution"},{"field":"CommandArtifactMatchList","description":"Command-line regex patterns indicative of sandbox evasion (e.g., grep QEMU, strings vmware)"}],"live":true,"detection_strategies":["DET0046"],"techniques":["T1497"]},{"id":"AN0129","stix_id":"x-mitre-analytic--b12639b9-5daa-46aa-a21f-521f6962f042","name":"Analytic 0129","description":"Execution of scripts or binaries that check for virtualization indicators (e.g., system_profiler, ioreg -l, kextstat), combined with delay functions or anomalous launchd activity.","url":"https://attack.mitre.org/detectionstrategies/DET0046#AN0129","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"execution of system_profiler, ioreg, kextstat with argument patterns related to VM/sandbox checks","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"dynamic loading of sleep-related functions or sandbox detection libraries","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ProcessCommandPattern","description":"Detection regex or substring matching sandbox-related checks"},{"field":"SleepThreshold","description":"Maximum duration of sleep execution before alert (e.g., > 5 minutes)"}],"live":true,"detection_strategies":["DET0046"],"techniques":["T1497"]}],"live":true,"version":"1.0","techniques":["T1497"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2025-6558","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-2783","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2014-0546","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2015-3113","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}