{"id":"T1497.001","name":"System Checks","url":"https://attack.mitre.org/techniques/T1497/001","tactics":["stealth","discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0168","stix_id":"x-mitre-detection-strategy--5b998fb4-fb3f-4207-ae00-cdf0e1a22b76","name":"Virtualization/Sandbox Evasion via System Checks across Windows, Linux, macOS","url":"https://attack.mitre.org/detectionstrategies/DET0168","analytics":[{"id":"AN0478","stix_id":"x-mitre-analytic--04bcbbb7-bfa9-41a5-9fb8-72a6df9ad50b","name":"Analytic 0478","description":"Script or binary performs a rapid sequence of system discovery checks (e.g., CPU count, RAM size, registry keys, running processes) indicative of VM detection","url":"https://attack.mitre.org/detectionstrategies/DET0168#AN0478","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Sequence of system enumeration events within X seconds"},{"field":"ProcessAncestry","description":"Parent-child lineage to identify potentially suspicious launch sources (e.g., Office, browser, WMI, PowerShell)"},{"field":"UserContext","description":"Limit to non-admin or interactive sessions if desired"}],"live":true,"detection_strategies":["DET0168"],"techniques":["T1497.001"]},{"id":"AN0479","stix_id":"x-mitre-analytic--7b4b3b54-d992-4f03-922a-6eec96c9342e","name":"Analytic 0479","description":"Shell script or binary uses multiple system commands (e.g., dmidecode, lscpu, lspci) in quick succession to detect virtualization environment","url":"https://attack.mitre.org/detectionstrategies/DET0168#AN0479","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve of system tools like dmidecode, lspci, lscpu, dmesg, systemd-detect-virt","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TimeWindow","description":"Burst of system info commands within X seconds"},{"field":"CommandPattern","description":"Regex or substring matching virtualization artifact checks"}],"live":true,"detection_strategies":["DET0168"],"techniques":["T1497.001"]},{"id":"AN0480","stix_id":"x-mitre-analytic--5a92bf3c-1832-453b-8ac9-24f8688d6faf","name":"Analytic 0480","description":"Bash, Swift, or Objective-C programs enumerate system profile, I/O registry, or inspect kernel extensions to identify VM artifacts","url":"https://attack.mitre.org/detectionstrategies/DET0168#AN0480","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"exec or spawn of 'system_profiler', 'ioreg', 'kextstat', 'sysctl', or calls to sysctl API","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ExecutionBurst","description":"Threshold of sequential system checks or tools used in a short time"},{"field":"ToolName","description":"Specific tools used for querying device and system metadata"}],"live":true,"detection_strategies":["DET0168"],"techniques":["T1497.001"]}],"live":true,"version":"1.0","techniques":["T1497.001"]}],"sigma_rules":[{"id":"4809c683-059b-4935-879d-36835986f8cf","title":"System Information Discovery Using System_Profiler","author":"Stephen Lincoln `@slincoln_aiq` (AttackIQ)","status":"test","level":"medium","date":"2024-01-02","modified":null,"description":"Detects the execution of \"system_profiler\" with specific \"Data Types\" that have been seen being used by threat actors and malware. It provides system hardware and software configuration information.\nThis process is primarily used for system information discovery. However, \"system_profiler\" can also be used to determine if virtualization software is being run for defense evasion purposes.\n","references":["https://www.trendmicro.com/en_za/research/20/k/new-macos-backdoor-connected-to-oceanlotus-surfaces.html","https://www.sentinelone.com/wp-content/uploads/pdf-gen/1630910064/20-common-tools-techniques-used-by-macos-threat-actors-malware.pdf","https://ss64.com/mac/system_profiler.html","https://objective-see.org/blog/blog_0x62.html","https://www.welivesecurity.com/2019/04/09/oceanlotus-macos-malware-update/","https://gist.github.com/nasbench/9a1ba4bc7094ea1b47bc42bf172961af"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.discovery","attack.stealth","attack.t1082","attack.t1497.001"],"path":"rules/macos/process_creation/proc_creation_macos_system_profiler_discovery.yml","techniques":["T1082","T1497.001"],"cves":[]},{"id":"6ff08e55-ea53-4f27-94a1-eff92e6d9d5c","title":"System Information Discovery Via Sysctl - MacOS","author":"Pratinav Chandra","status":"test","level":"medium","date":"2024-05-27","modified":null,"description":"Detects the execution of \"sysctl\" with specific arguments that have been used by threat actors and malware. It provides system hardware information.\nThis process is primarily used to detect and avoid virtualization and analysis environments.\n","references":["https://www.loobins.io/binaries/sysctl/#","https://evasions.checkpoint.com/techniques/macos.html","https://www.welivesecurity.com/2019/04/09/oceanlotus-macos-malware-update/","https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/","https://objective-see.org/blog/blog_0x1E.html","https://www.virustotal.com/gui/file/1c547a064494a35d6b5e6b459de183ab2720a22725e082bed6f6629211f7abc1/behavior","https://www.virustotal.com/gui/file/b4b1fc65f87b3dcfa35e2dbe8e0a34ad9d8a400bec332025c0a2e200671038aa/behavior"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.stealth","attack.t1497.001","attack.discovery","attack.t1082"],"path":"rules/macos/process_creation/proc_creation_macos_sysctl_discovery.yml","techniques":["T1497.001","T1082"],"cves":[]},{"id":"d93129cd-1ee0-479f-bc03-ca6f129882e3","title":"Powershell Detect Virtualization Environment","author":"frack113, Duc.Le-GTSC","status":"test","level":"medium","date":"2021-08-03","modified":"2022-03-03","description":"Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.\nThis may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1497.001/T1497.001.md","https://techgenix.com/malicious-powershell-scripts-evade-detection/"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.discovery","attack.stealth","attack.t1497.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_detect_vm_env.yml","techniques":["T1497.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}