Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1497.002 — User Activity Based Checks
T1497.002

User Activity Based Checks

Stealth
TLP:CLEAR

Description

Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.(Citation: Deloitte Environment Awareness) Adversaries may search for user activity on the host based on variables such as the speed/frequency of mouse movements and clicks (Citation: Sans Virtual Jan 2016) , browser history, cache, bookmarks, or number of files in common directories such as home or the desktop. Other methods may rely on specific user interaction with the system before the malicious code is activated, such as waiting for a document to close before activating a macro (Citation: Unit 42 Sofacy Nov 2018) or waiting for a user to double click on an embedded image to activate.(Citation: FireEye FIN7 April 2017)

MITRE ATT&CK Detection Strategies
1

DET0420 Detect User Activity Based Sandbox Evasion via Input & Artifact Probing
AN1183 Linux

Access to shell history or GUI input state (xdotool, xinput) for presence validation prior to payload execution.

auditd:SYSCALL auditd:SYSCALL
AN1182 Windows

Process execution that probes user activity artifacts (e.g., desktop files, registry history) following recent user login/unlock events.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1184 macOS

API usage or filesystem access revealing user state or browser artifacts (e.g., Safari bookmarks, CGEventState).

macos:unifiedlog macos:unifiedlog

Details

Platforms
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.