Anti-Analysis
Checks a sample runs before it commits. Useful offensively, and useful defensively as a fingerprint — the checks themselves are loud.
5 techniques
T1027Windows, Linux, macOS08-04T1497Windows, Linux08-04T1497.001Windows, Linux, macOS09-04T1497.003Windows, Linux08-04T1622Windows08-04
String Encryption
Encrypt string literals at compile time and decrypt them at runtime to remove plaintext IoCs from static analysis.
Sandbox & VM Detection
Fingerprint automated analysis environments and refuse to run inside them.
Hardware Fingerprinting
Hash the machine's hardware identifiers so the implant behaves only on the target and flags sandboxes.
Timing-Based Evasion
Use elapsed-time or CPU-cycle measurements to detect single-stepping, sleep acceleration, and sandboxes.
Anti-Debugging Techniques
Detect or disrupt debuggers to prevent interactive analysis of a running sample.
no techniques match those filters.