Repository navigation
2.8.2 Release
This is mainly a bugfix release.
As VMAware begins operating at massive scale, with over 100,000 devices, detection research has naturally slowed down. Our current priority is improving stability and ensuring detection accuracy across a large and diverse range of systems.
Furthermore, our official TPM research has been improved and, as a simple reminder, you can find it here. While of course local attestation can be bypassed, remote attestation using the same detection ideas cannot.
With TPM-based verification, hypervisor detection is effectively a solved problem in principle. Future VMAware releases will therefore focus on additional firmware-level checks for those environments that do not enforce TPMs, as well as detecting Hyper-V hijacking.
Additions
-
Added official support for new CPU architectures:
alpha,arm64ec,hppa,m68k,mips,mipsel,mips64,powerpc,ppc64,sh4,sparc64. -
Hyper-V integrity verification via TPM.
-
RDPRU interception checks.
-
Exception anomaly detection for interrupt shadows.
-
Exception timing checks to detect nested virtualization.
-
VM::WINE: Improved detections via export detection andMultiDivquirks. -
VM::DBVM: Better detections for Dark Byte's VM in Cheat Engine. -
VM::FIRMWARE:- SMI resources firmware check.
- PRTP and PRTA variable-size relative symmetry check.
- Constant-agnostic structural _STA check for virtual HPET detection (VEND / PRD threshold).
Improvements
- Memory safety and general performance of all functions.
VM::DMESGandVM::DMIDECODEchecks on Linux.- GPER firmware check.
Fixes
- Issues when handling some configuration flags in our public APIs.
- Every false flag in
VM::FIRMWARE. - Most
VM::TIMERfalse flags. Additionally, reduced score to 45 and removed CPUID timing checks from running under Hyper-V. - Type case for every brand, so that external forks can automate string matching.
- Caching and scoreboard reset mismatch.
- Whitelisted some laptop manufacturers and models from several checks, like power and clock checks.
- Possibility of preprocessor conflicts and debug function call conflicts with external code.
VM:.QEMU_USBto return proper VM brand.VM::GAMARUEfrom not detecting anything.VM::NVRAMfrom not detecting VMM EFI variables.brand_core_ttype to in32_t for all platforms.- Any issue when VMAware encountered CPU with 64 cores or more.
Removals
- Hardening detection API.
VM::AUDIO: The absence of waveform audio devices is not a proof of a VM.VM::INVALIDbrand.VM::CPU_HEURISTIC: RDRAND check, as even if following the Intel SDM/AMD APM to the letter, they still can yield some false flags in very exotic edge-cases.- CLI's Vectored Exception Handler to prevent future conflicts with detections.
- EPT/NPT vmexit timing checks in
VM::TIMER: They were not testing true nested vmexit (reflection) latency.
Secondary Changes
- Added debug workflows for macOS and Linux. Now people can download binaries with all the information reported on Github CI/CD.
- New string utility struct.
- Standarized use of brackets in every condition and snake_case across all the library.
- Replaced mem* functions with their C++ corecrt equivalent.
- Updated all CPU databases.
Notes
This version still shows as v2.8.1 when the --version argument in the CLI is used.
VirusTotal Results and Executables
All the binaries were generated in GitHub's CI/CD purely from the source code here.
Contact
For any inquiries, contact us on Discord at shenzken, or email us at vmaware.support@gmail.com.