2.4.0 Release ๐
-
removed:
VM::ACPI_TEMPERATUREVM::BAD_POOLSVM::COMPUTER_NAMEVM::DEVICE_TREEVM::DRIVER_NAMESVM::GPU_VM_STRINGSVM::HKLM_REGISTRIESVM::HOSTNAMEVM::KVM_BITMASKVM::KVM_DIRSVM::LSHW_QEMUVM::MSSMBIOSVM::NATIVE_VHDVM::NETTITUDE_VM_MEMORYVM::NUMBER_OF_CORESVM::OSXSAVEVM::PCI_VMVM::PORT_CONNECTORSVM::PROCESSOR_NUMBERVM::QEMU_DIRVM::REGISTRYVM::SCREEN_RESOLUTIONVM::SETUPAPI_DISKVM::THREADCOUNTVM::UNKNOWN_MANUFACTURERVM::VM_DEVICESVM::VM_FILESVM::VM_PROCESSESVM::VM_PROCSVM::VMWARE_PORT_MEMVM::WINE_CHECKVM::PROCESSES(Windows section)VM::TEMPERATURE(Windows section)
-
undisabled:
VM::TEMPERATURE
-
added:
VM::DEVICE_HANDLESVM::DISPLAYVM::DRIVERSVM::LOGICAL_PROCESSORSVM::PCI_DEVICESVM::PHYSICAL_PROCESSORSVM::PROCESSESVM::QEMU_PASSTHROUGH(world's first ever device passthrough detection)VM::REGISTRY_KEYSVM::REGISTRY_VALUESVM::THREAD_COUNTVM::TRAP
-
added compile-time filters for unsupported techniques based on platforms
-
added compatibility for Windows 7 and above
-
made the library fully MIT
-
improved every vm detection technique, focusing on:
- Timing attacks
- Firmware analysis
- Device passthrough detection
- PCIe scanning
- GPU capabilities
VirusTotal results
The Windows binaries were generated in the CI/CD purely from the source code here.
The Linux binaries on the other hand, were generated through the cmake file present in the root directory of the repository.
Credits
Extra
For any inquiries, contact me on discord at kr.nl or email me at jeanruyv@gmail.com