Releases: NotRequiem/VMAware
Release list
2.1.0 🎉
- added new function
VM::detected_enums() - added new brands:
- Intel TDX
- LKVM
- AMD SEV
- AMD SEV-ES
- AMD SEV-SNP
- Neko Project II
- NoirVisor
- Qihoo 360 Sandbox
- nsjail
- added new techniques:
- VM::TIMER
- VM::GPU
- VM::VM_DEVICES
- VM::ACPI_TEMPERATURE
- VM::VIRTUAL_PROCESSORS
- VM::HYPERV_QUERY
- VM::BAD_POOLS
- VM::AMD_SEV
- VM::AMD_THREAD_MISMATCH
- VM::NATIVE_VHD
- VM::VIRTUAL_REGISTRY
- VM::FIRMWARE
- VM::FILE_ACCESS_HISTORY
- VM::AUDIO
- VM::UNKNOWN_MANUFACTURER
- VM::OSXSAVE
- VM::NSJAIL_PID
- VM::PCI_VM
- added new features to the CLI:
- added brand descriptions
- added --mit and --enums oprions
- renamed --no-color option with --no-ansi
- fixed MacOS techniques
- fixed Hyper-X mechanism
- fixed C++ standards compatibility issues
- fixed argument handler issues
- improved cpu module
- improved Windows stuff
- various fixes, improvements, and optimisations to many techniques
- merged tons of techniques into one
- modified the scores for many techniques
- removed WMI module with a more efficient replacement
- removed brands:
- Micorosft x86-to-ARM
- Apple Rosetta 2
- removed techniques:
- VM::RDTSC
- VM::VMWARE_REG
- VM::VBOX_REG
- VM::USER
- VM::VBOX_WINDOW_CLASS
- VM::LOADED_DLLS
- VM::KVM_REG
- VM::KVM_DRIVERS
- VM::AUDIO
- VM::VMID_0X4
- VM::PARALLELS_VM
- VM::QEMU_BRAND
- VM::VPC_BOARD
- VM::HYPERV_WMI
- VM::HYPERV_REG
- VM::BIOS_SERIAL
- VM::VALID_MSR
- VM::QEMU_PROC
- VM::VPC_PROC
- VM::HYPERV_BOARD
- VM::VM_FILES_EXTRA
- VM::UPTIME
- VM::HYPERV_BITMASK
- VM::VMWARE_DMI
- VM::HYPERV_EVENT_LOGS
- VM::VMWARE_EVENT_LOGS
- VM::GPU_CHIPTYPE
- VM::VM_HDD
- VM::ACPI_DETECT
- VM::GPU_NAME
- VM::VMWARE_DEVICES
- VM::VMWARE_MEMORY
- VM::WMI_MODEL
- VM::WMI_MANUFACTURER
- VM::WMI_TEMPERATURE
- VM::CPU_FANS
- VM::VMWARE_HARDENER
- VM::WMI_QUERIES
VirusTotal (3/73, as of 21 March 2025)
The windows binaries were generated here purely from the source code.
Credits
@NotRequiem, this release wouldn't had been possible without him
@Scrut1ny, for useful feedback
2.0.0 🎉
- added optional
VM::vmawarestructure - added new functions:
VM::type()VM::conclusion()VM::detected_count()
- added improvements to Hyper-X (version 5)

- added argument support of
VM::NO_MEMOtoVM::check() - added 24 new techniques:
VM::GPU_CHIPTYPEby @koughingVM::DRIVER_NAMESVM::VBOX_IDTVM::HDD_SERIALVM::PORT_CONNECTORSVM::VM_HDDVM::ACPI_HYPERVVM::GPU_NAMEVM::VMWARE_DEVICESVM::VMWARE_MEMORYVM::IDT_GDT_MISMATCHVM::PROCESSOR_NUMBERVM::NUMBER_OF_CORESVM::WMI_MODELVM::WMI_MANUFACTURERVM::WMI_TEMPERATUREVM::PROCESSOR_IDVM::CPU_FANSVM::POWER_CAPABILITIESVM::SETUPAPI_DISKVM::VMWARE_HARDENERVM::WMI_QUERIESVM::SYS_QEMUVM::LSHW_QEMU
- added 5 option flags to the CLI:
--no-color--high-threshold--dynamic--verbose--compact
- added improvements and fixes to
VM::add_custom() - added 3 new brands:
- Barevisor
- HyperPlatform
- Minivisor
note: all of these brands were made by @tandasat
- added new WMI structure module and overall WMI improvements
- updated the scores of most techniques (see the scoring system)
- updated:
VM::HKLM_REGISTRIESVM::DRIVER_NAMESVM::REGISTRY
- optimized
VM::INTEL_THREAD_MISMATCH - fixed MacOS bugs [link]
- disabled
VM::VMWARE_DMESGby default - removed
VM::SPOOFABLEand--spoofable - removed:
VM::MOUSE_DEVICEVM::VBOX_FOLDERSVM::CURSORVM::HYPERV_WMIVM::HYPERV_REGVM::ANYRUN_DRIVER(still present in the CLI)VM::ANYRUN_DIRECTORY(same)VM::CWSANDBOX_VMVM::MEMORY
(these were removed either due to unreliability, unpredictability, overall low quality, ethical reasons, or a combination of them)
Credits to
- @NotRequiem
- @koughing
- MeGaMax
VirusTotal results (17/72)
I'm fully aware this looks really suspicious, but the binaries were generated through the CI/CD here purely from the source code. The score might fluctuate as it did previously, so if it doesn't match, please notify me with an issue.
Extra
For any inquiries, contact me on discord at kr.nl or email me at jeanruyv@gmail.com
1.9.0 🎉
- renamed Virtual Apple to Apple Rosetta 2
- fixed oversight for AMD CPU detection
- fixed bug for
VM::BOCHS_CPU - fixed
VM::ALLthanks to @D00Movenok - fixed MSVC compiler warnings thanks to @NotRequiem
- disabled
VM::CURSOR,VM::RDTSC, andVM::RDTSC_EXITby default - added
--allto the CLI, which will enable all techniques including the above ones - added
ANY.RUNVM brand - added
VM::ANYRUN_DRIVERandVM::ANYRUN_DIRECTORYtechniques
NOTE: It's been exactly a year since I've started and continuously maintained this project since September 2023, and I'm taking a break for a while. Not sure when the next release will be, but I'll try to come back to this project after I've recharged my energy while I'm focusing on some side projects I've been working on occasionally :)
For any inquiries, contact me on discord at kr.nl or email me at jeanruyv@gmail.com
1.8.0 🎉
- Fixed false positives due to Hyper-V artifacts with new "Hyper-X" mechanism designed by @NotRequiem
-
added 10 new VM brands:
Hyper-V artifact (not an actual VM)User-mode LinuxIBM PowerVMGoogle Compute Engine (KVM)OpenStack (KVM)KubeVirt (KVM)AWS Nitro System EC2 (KVM-based)PodmanWSLOpenVZ
-
added 14 new techniques:
VM::EVENT_LOGSVM::QEMU_VIRTUAL_DMIVM::QEMU_USBVM::HYPERVISOR_DIRVM::UML_CPUVM::KMSGVM::VM_PROCSVM::VBOX_MODULEVM::SYSINFO_PROCVM::DEVICE_TREEVM::DMI_SCANVM::SMBIOS_VM_BITVM::PODMAN_FILEVM::WSL_PROC
1.7.1 🎉
- added
VM::SPOOFABLEflag to enable easily spoofable techniques - added VM types as summary output
- added CLI options for VM type details (
-tor--type) - added
QEMU+KVM Hyper-V EnlightenmentVM brand - added better CLI indications such as techniques that require permissions
- changed so that spoofable techniques are no longer run by default, unless
VM::SPOOFABLEis inputted.
1.7.0 🎉
-
added better heuristic checks for Hyper-V host virtualisation
-
added argument handler improvements to the CLI
-
added VM type information to the CLI
-
added 4 new techniques:
VM::CPUID_SIGNATUREVM::HYPERV_BITMASKVM::KVM_BITMASKVM::KGT_SIGNATURE
-
added 7 new VM brands:
JailhouseApple VZIntel KGT (Trusty)VMware FusionMicrosoft Azure Hyper-VXbox NanoVisor (Hyper-V)SimpleVisor
-
renamed VM brand "Thread Expert" to "ThreatExpert" (i fucked up)
-
renamed
VM::HYPERV_CPUIDtechnique toVM::CPUID_BITSET -
removed
VM::EXTREMEsettings flag -
removed 2 techniques (both due to potential false positives):
VM::CPUID_SPACINGVM::CPUID_0X4
1.6.1 🎉
- added 2 new variables:
VM::technique_countVM::technique_vectorvariables
- added 9 new techniques:
VM::NETTITUDE_VM_REGIONSVM::HYPERV_CPUIDVM::CUCKOO_DIRVM::CUCKOO_PIPEVM::USB_DRIVEVM::HYPERV_HOSTNAMEVM::GENERAL_HOSTNAMEVM::SCREEN_RESOLUTIONVM::DEVICE_STRING
- added
VM::HIGH_THRESHOLDnon-technique flag to set a higher threshold score - added optimisations to
VM::detect()andVM::percentage() - added Cuckoo and BlueStacks VM brands
- added heuristic checks for Hyper-V host virtualisation (thanks to @NotRequiem for the suggestion)
- improved memoization system
- renamed
VM::BRANDtechnique toVM::CPU_BRANDto avoid confusion withVM::brand() - fixed wcstomb() deprecation warning
1.5.0 🎉
- added 6 different brands:
KVM Hyper-V EnlightenmentNVMMOpenBSD VMMIntel HAXMUnisys s-ParLockheed Martin LMHS
- added better checks for flag handling
- added C++23 support
- added
VM::DISABLE()function for manually disabling flags - major CLI changes
- added
--brand-listoption which outputs the list of possible VM brands - added
--disable-hyperv-hostoptions which will disregard the possibility of Hyper-V default virtualisation - added number of techniques and number of detected techniques as output
- added
- improved and renewed flag system
- improved discarding mechanism if Hyper-V is detected in case of default virtualisation
- removed
VM::WMICtechnique - deprecated
VM::WIN_HYPERV_DEFAULT, useVM::ENABLE_HYPERV_HOSTinstead
Full Changelog: https://github.com/kernelwernel/VMAware/compare/v1.4...v1.5
1.4.0 🎉
- Added 3 new techniques:
VM::ODD_CPU_THREADS
VM::INTEL_THREAD_MISMATCH
VM::XEON_THREAD_MISMATCH - Added better x86 compatibility for description table techniques (idt)
- Added better caching that's much more efficient now
- Fixed warnings, thanks Requiem :)
- Removed Hyper-V virtualisation (by default unless specified with
VM::WIN_HYPERV_DEFAULTdue to false positives associated with default virtualisation for every program when Hyper-V is enabled)
Full Changelog: https://github.com/kernelwernel/VMAware/compare/v1.3...v1.4
1.3.0 🎉
- added specific VMware products (ESX, GSX, etc...) as potential brands
- added
--conclusionflag to cli to return just the conclusion message - added 12 new techniques
- added "
Microsoft Virtual PC/Hyper-V" as possible brand string - added 32-bit support
- added
VM::MULTIPLEflag for multiple brand outputs - fixed
VM::ALLandVM::DEFAULTflags being private - improved cpuid hypervisor leaf detections
