{"id":"T1564.006","name":"Run Virtual Instance","url":"https://attack.mitre.org/techniques/T1564/006","tactics":["stealth"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0321","stix_id":"x-mitre-detection-strategy--55321f9d-1646-45b9-b23e-e3c0fe105400","name":"Detection Strategy for Hidden Virtual Instance Execution","url":"https://attack.mitre.org/detectionstrategies/DET0321","analytics":[{"id":"AN0909","stix_id":"x-mitre-analytic--f94e2ae3-7c79-4796-96a1-e462828f9c13","name":"Analytic 0909","description":"Unusual execution of virtualization binaries (VBoxManage.exe, vmware-vmx.exe, vmwp.exe) with headless or suppressed notification arguments. Registry and service modifications linked to virtualization installs. Defender view: anomalies in process creation, service metadata, and registry writes tied to enabling hidden VMs.","url":"https://attack.mitre.org/detectionstrategies/DET0321#AN0909","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:System","channel":"EventCode=7045","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"VirtualizationBinaryWhitelist","description":"Exclude known administrative VM software usage in enterprise environments."},{"field":"TimeWindow","description":"Correlate registry and service modifications with VM process starts within a narrow time frame."}],"live":true,"detection_strategies":["DET0321"],"techniques":["T1564.006"]},{"id":"AN0910","stix_id":"x-mitre-analytic--79ba9430-eeb0-4fce-9757-bb81fc2a43d5","name":"Analytic 0910","description":"Execution of QEMU, KVM, or VirtualBox processes with unusual flags (e.g., '-nographic', '-snapshot'). File creation of VM images in atypical directories. Defender view: monitoring audit logs for process executions and file modifications linked to hidden virtualization.","url":"https://attack.mitre.org/detectionstrategies/DET0321#AN0910","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve calls for qemu-system*, kvm, or VBoxHeadless","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"File creations of *.qcow2, *.vdi, *.vmdk outside standard VM directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ImageDirectoryWhitelist","description":"Legitimate VM image storage paths to reduce false positives."},{"field":"UserContext","description":"Correlate suspicious VM execution with non-admin or service accounts."}],"live":true,"detection_strategies":["DET0321"],"techniques":["T1564.006"]},{"id":"AN0911","stix_id":"x-mitre-analytic--4d76bcf2-0935-4f61-8dd9-57ee3713b840","name":"Analytic 0911","description":"Execution of virtualization binaries (Parallels, VMware Fusion, VirtualBox) with arguments to hide UI. File monitoring for plist modifications indicating hidden virtualization behavior. Defender perspective: tracking process lineage and file modifications in system configs.","url":"https://attack.mitre.org/detectionstrategies/DET0321#AN0911","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Process execution for VBoxHeadless, prl_vm_app, vmware-vmx","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Plist modifications containing virtualization run configurations","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PlistKeyScope","description":"Focus monitoring on UI suppression or VM auto-run keys."}],"live":true,"detection_strategies":["DET0321"],"techniques":["T1564.006"]},{"id":"AN0912","stix_id":"x-mitre-analytic--d677a72d-db0e-4332-a467-95b19836ef16","name":"Analytic 0912","description":"Direct execution of /bin/vmx or presence of rogue .vmx files not registered in vCenter inventory. Defender perspective: anomalous commands in shell history, edits to rc.local.d/local.sh for persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0321#AN0912","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"Execution of '/bin/vmx' or modifications to '/etc/rc.local.d/local.sh'","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"VMX startup messages without associated vCenter inventory records","data_component":"DC0028","data_component_name":"Image Metadata","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"VMInventorySync","description":"Cross-verify running VMs with vCenter inventory for rogue instances."}],"live":true,"detection_strategies":["DET0321"],"techniques":["T1564.006"]}],"live":true,"version":"1.0","techniques":["T1564.006"]}],"sigma_rules":[{"id":"42d36aa1-3240-4db0-8257-e0118dcdd9cd","title":"Suspicious Hyper-V Cmdlets","author":"frack113","status":"test","level":"medium","date":"2022-04-09","modified":null,"description":"Adversaries may carry out malicious operations using a virtual instance to avoid detection","references":["https://learn.microsoft.com/en-us/virtualization/hyper-v-on-windows/quick-start/enable-hyper-v","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1564.006/T1564.006.md#atomic-test-3---create-and-start-hyper-v-virtual-machine"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.stealth","attack.t1564.006"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_hyper_v_condlet.yml","techniques":["T1564.006"],"cves":[]},{"id":"bab049ca-7471-4828-9024-38279a4c04da","title":"Virtualbox Driver Installation or Starting of VMs","author":"Janantha Marasinghe","status":"test","level":"low","date":"2020-09-26","modified":"2025-07-29","description":"Adversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.","references":["https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/","https://threatpost.com/maze-ransomware-ragnar-locker-virtual-machine/159350/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1564.006","attack.t1564"],"path":"rules/windows/process_creation/proc_creation_win_virtualbox_execution.yml","techniques":["T1564.006","T1564"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}