Skip to content

Evasion Detection

Definition

Malware logic that checks whether the execution environment is a real host or an analysis sandbox. Checks may query hardware identifiers, count CPU cores, inspect running processes, or measure elapsed time, and the malware suppresses its payload if it detects an analysis environment.

Domain
Malware analysis
Target
Detecting sandbox or analysis environments
Check types
Hardware IDs, CPU core count, running processes, elapsed time
Effect when triggered
Malware suppresses its payload

Common questions

Why does malware check CPU core count as a sign of a sandbox?+

Many automated analysis sandboxes are provisioned as lightweight virtual machines with fewer CPU cores or minimal resources than a typical real user's machine, so an unusually low core count is a cheap signal the malware can use to infer it is being analysed.

How does timing-based evasion detection work?+

The malware measures elapsed time for certain operations, or inserts a delay and checks whether the environment fast-forwards time, since some sandboxes speed up execution to save analysis time, a discrepancy the malware treats as evidence it is not running on a real host.

How do analysts counter evasion detection when studying a sample?+

They harden the sandbox to mimic a realistic environment more closely, adjusting hardware fingerprints, process lists, and timing behavior, or fall back to manual and static analysis when the sample refuses to execute its payload under automated dynamic analysis.

Related terms

API Hooking
A monitoring technique in which the sandbox intercepts calls the malware makes to operating-system API functions. Each intercepted call is logged with...
Behavioural Analysis
The examination of what a program does at runtime rather than what its code says at rest. Behavioural analysis captures the actual...
MITRE ATT&CK Mapping
The process of classifying observed malware behaviours against the MITRE ATT&CK framework's taxonomy of adversary tactics and techniques. Sandbox platforms increasingly produce...
Network Indicator
A network-based artefact produced by malware at runtime, such as a DNS query, an IP address contacted, an HTTP request path, a...
Sandbox
An isolated execution environment, typically a virtual machine, where a malware sample runs under full instrumentation. The sandbox logs all system calls,...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.