kevmap

TechniquesT1497 › AN0127

AN0127 Analytic 0127

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Execution of discovery commands or API calls for virtualization artifacts (e.g., registry keys, device drivers, services), sleep/skipped execution behavior, or sandbox evasion DLLs before payload deployment.</p>
Detects
T1497 Virtualization/Sandbox Evasion
Part of
DET0046 Detection Strategy for T1497 Virtualization/Sandbox Evasion

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SysmonEventCode=7DC0016 Module Load

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowTime range in which multiple discovery processes or sleep/delay operations are executed to avoid sandbox detonation.
KnownVMArtifactListRegistry paths, DLLs, services or device names indicative of sandbox/VM environments.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2014-0546Adobe Reader and AcrobatMapped
CVE-2015-3113Adobe Flash PlayerMapped
CVE-2025-2783Google Chromium MojoMapped
CVE-2025-6558Google ChromiumMapped