Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most virtual machine detection boils down to checking the CPUID hypervisor bit and vendor string. Luckily, it is possible to configure VMWare, VirtualBox and QEMU to spoof those values in the guest machine.


This sent me down the rabbit hole on defeating this... I cannot stand this sort of authoritarian horsesh...

Defeating malware's VM detection is very interesting.

Links for others if they're interested:

https://github.com/a0rtega/pafish collects all the best-known detection methods into a test suite.

This issue is interesting/has links for sure: https://github.com/spender-sandbox/cuckoo-modified/issues/45...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: