Virtualization for Defense Evasion: Hiding Tracks
ID: 35337965-f8ca-5b3f-9288-6264c52b9ea9
STIX ID: report--35337965-f8ca-5b3f-9288-6264c52b9ea9
Feed Name: ReliaQuest Blog
This report explains how threat actors use host-hosted virtualization (particularly Type 2 hypervisors) to evade detection by creating and operating guest virtual machines on compromised endpoints. It covers the attack chain—image download/ingress, hypervisor installation, VM configuration and control, and VM-originated C2—provides observable indicators (e.g., unusual image downloads, hypervisor installer artifacts, process attribution of network traffic), and recommends hunting, baselining virtualization usage, and blocking unauthorized hypervisors as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
