Skip to content

v2.8.2 馃帀

Latest

Choose a tag to compare

@NotRequiem NotRequiem released this 14 Sep 05:17
路 46 commits to main since this release

2.8.2 Release

This is mainly a bugfix release.

As VMAware begins operating at massive scale, with over 100,000 devices, detection research has naturally slowed down. Our current priority is improving stability and ensuring detection accuracy across a large and diverse range of systems.

Furthermore, our official TPM research has been improved and, as a simple reminder, you can find it here. While of course local attestation can be bypassed, remote attestation using the same detection ideas cannot.

With TPM-based verification, hypervisor detection is effectively a solved problem in principle. Future VMAware releases will therefore focus on additional firmware-level checks for those environments that do not enforce TPMs, as well as detecting Hyper-V hijacking.

Additions

  • Added official support for new CPU architectures: alpha, arm64ec, hppa, m68k, mips, mipsel, mips64, powerpc, ppc64, sh4, sparc64.

  • Hyper-V integrity verification via TPM.

  • RDPRU interception checks.

  • Exception anomaly detection for interrupt shadows.

  • Exception timing checks to detect nested virtualization.

  • VM::WINE: Improved detections via export detection and MultiDiv quirks.

  • VM::DBVM: Better detections for Dark Byte's VM in Cheat Engine.

  • VM::FIRMWARE:

    • SMI resources firmware check.
    • PRTP and PRTA variable-size relative symmetry check.
    • Constant-agnostic structural _STA check for virtual HPET detection (VEND / PRD threshold).

Improvements

  • Memory safety and general performance of all functions.
  • VM::DMESG and VM::DMIDECODE checks on Linux.
  • GPER firmware check.

Fixes

  • Issues when handling some configuration flags in our public APIs.
  • Every false flag in VM::FIRMWARE.
  • Most VM::TIMER false flags. Additionally, reduced score to 45 and removed CPUID timing checks from running under Hyper-V.
  • Type case for every brand, so that external forks can automate string matching.
  • Caching and scoreboard reset mismatch.
  • Whitelisted some laptop manufacturers and models from several checks, like power and clock checks.
  • Possibility of preprocessor conflicts and debug function call conflicts with external code.
  • VM:.QEMU_USB to return proper VM brand.
  • VM::GAMARUE from not detecting anything.
  • VM::NVRAM from not detecting VMM EFI variables.
  • brand_core_t type to in32_t for all platforms.
  • Any issue when VMAware encountered CPU with 64 cores or more.

Removals

  • Hardening detection API.
  • VM::AUDIO: The absence of waveform audio devices is not a proof of a VM.
  • VM::INVALID brand.
  • VM::CPU_HEURISTIC: RDRAND check, as even if following the Intel SDM/AMD APM to the letter, they still can yield some false flags in very exotic edge-cases.
  • CLI's Vectored Exception Handler to prevent future conflicts with detections.
  • EPT/NPT vmexit timing checks in VM::TIMER: They were not testing true nested vmexit (reflection) latency.

Secondary Changes

  • Added debug workflows for macOS and Linux. Now people can download binaries with all the information reported on Github CI/CD.
  • New string utility struct.
  • Standarized use of brackets in every condition and snake_case across all the library.
  • Replaced mem* functions with their C++ corecrt equivalent.
  • Updated all CPU databases.

Notes

This version still shows as v2.8.1 when the --version argument in the CLI is used.

VirusTotal Results and Executables

https://www.virustotal.com/gui/file/bc5954ecc5c87f0490915a7b7141bbc0ca9a317ccc9c89cf0bdc2f75445987c7?nocache=1

All the binaries were generated in GitHub's CI/CD purely from the source code here.

Contact

For any inquiries, contact us on Discord at shenzken, or email us at vmaware.support@gmail.com.