Anti-emulation
ConceptAnti-emulation refers to techniques that detect the presence of a CPU or system emulator, typically to evade dynamic analysis and monitoring frameworks that rely on emulation. It is used both by malware authors (to hide malicious behavior from emulator-based analysis) and, as demonstrated by the Examiner work, by security researchers as a built-in capability of inconsistency-based detection between real devices and emulators.
WIKI
Definition
Anti-emulation is the practice of identifying, fingerprinting, or otherwise discriminating against a software-based CPU or device emulator so that code executing on the emulator behaves differently from code executing on real hardware. It is a detection-avoidance technique most commonly associated with malware analysis resistance, but the term is also used to describe the deliberate (ab)use of hardware/software behavioral gaps to reveal an emulated environment.
Motivations
NEIGHBORHOOD
No graph connections found for this entity yet. It may appear in future ingestion runs.
explore full graph →