Powershell Detect Virtualization Environment

 Original Source: [Sigma source]
Title: Powershell Detect Virtualization Environment
Status: test
Description:Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1497.001/T1497.001.md
  -https://techgenix.com/malicious-powershell-scripts-evade-detection/
Author: frack113, Duc.Le-GTSC
Date: 2021-08-03
modified:2022-03-03
Tags:
  • -'attack.discovery'
  • -'attack.stealth'
  • -'attack.t1497.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_action:
    ScriptBlockText|contains:
      -'Get-WmiObject'
      -'gwmi'

  selection_module:
    ScriptBlockText|contains:
      -'MSAcpi_ThermalZoneTemperature'
      -'Win32_ComputerSystem'

  condition:all of selection*
Falsepositives:
  -Unknown
Level: medium