{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/evading-sandbox/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["discovery","stealth","evading-sandbox","powershell","wmi"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries often perform environment reconnaissance during the initial execution phase to determine if the host is a virtual machine or a controlled security analysis environment. By querying Windows Management Instrumentation (WMI) providers via PowerShell, attackers can identify hardware-specific strings, thermal zone sensors, or system characteristics that differ from standard physical endpoints. This capability allows malicious scripts to exit or modify their behavior if virtualization is detected, thereby bypassing automated sandbox analysis and complicating incident response efforts. Defenders should monitor for PowerShell scripts that correlate WMI object access with known virtualization-related class names.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful detection of analysis environments allows malware or malicious scripts to evade automated sandbox analysis, leading to missed infections and prolonged dwell time for attackers within the targeted network. This technique is commonly employed by various threat actors to protect their custom payloads from security research and automated malware analysis platforms.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable PowerShell Script Block Logging (Event ID 4104) across all Windows endpoints to capture the full content of executed scripts.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect suspicious WMI queries associated with virtualization checks.\u003c/li\u003e\n\u003cli\u003eBaseline legitimate administrative scripts that query 'Win32_ComputerSystem' or 'MSAcpi_ThermalZoneTemperature' to minimize false positives.\u003c/li\u003e\n\u003cli\u003eInvestigate any host where unknown scripts are actively searching for VM artifacts, as this indicates a high probability of malicious intent.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T13:37:52Z","date_published":"2026-09-03T13:37:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-powershell-vm-detection/","summary":"Adversaries utilize PowerShell commands to query WMI objects and check for virtualization artifacts to evade sandbox and analysis environments.","title":"PowerShell Virtualization Environment Detection Discovery","url":"https://feed.craftedsignal.io/briefs/2026-09-powershell-vm-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - Evading-Sandbox","version":"https://jsonfeed.org/version/1.1"}