# EXP Variant Anti-VM-Detection Strategy in vPhone-CLI: 6 Kernel and User-Space Techniques

> Discover the EXP variant's anti-VM detection strategy in vPhone-CLI. Learn 6 kernel and user-space techniques that help evade virtual machine detection for a seamless experience.

- Repository: [Lakr/vphone-cli](https://github.com/Lakr233/vphone-cli)
- Tags: deep-dive
- Published: 2026-09-13

---

**The EXP variant in Lakr233/vphone-cli evades virtual machine detection by renaming the `kern.hv_vmm_present` sysctl, mangling kernel-internal string references, patching the watchdogd cache, rewriting the DeviceTree after restore, and spoofing system build versions to present the iOS guest as physical hardware.**

The **EXP** (experimental) firmware variant in the `Lakr233/vphone-cli` repository extends the standard jailbreak build with a comprehensive anti-VM-detection strategy. Orchestrated by the `KernelEXPPatcher` class and the [`cfw_install_exp.sh`](https://github.com/Lakr233/vphone-cli/blob/main/cfw_install_exp.sh) installation script, these modifications hide the fact that the iOS guest is running inside a virtual machine while preserving critical system functionality for graphics acceleration and sandbox enforcement.

## Overview of the EXP Variant Architecture

Unlike the standard jailbreak (JB) build, the EXP variant applies modifications across both kernel and user-space boundaries. The [`KernelEXPPatcher.swift`](https://github.com/Lakr233/vphone-cli/blob/main/KernelEXPPatcher.swift) orchestration class manages kernel-level patches, while [`cfw_install_exp.sh`](https://github.com/Lakr233/vphone-cli/blob/main/cfw_install_exp.sh) handles post-restore identity rewriting and daemon patching. Together, these components ensure that internal iOS services and external detection mechanisms receive consistent "non-VM" signals.

## Kernel-Space Anti-VM Techniques

The foundation of the EXP variant's anti-VM-detection strategy rests on manipulating how the kernel advertises and queries virtualization status.

### Sysctl OID Rename (kern.hv_vmm_present)

The primary mechanism occurs in [`KernelEXPPatchHvVmmRename.swift`](https://github.com/Lakr233/vphone-cli/blob/main/KernelEXPPatchHvVmmRename.swift), where the `KernelEXPPatcher.patchHvVmmRename` method renames the critical `kern.hv_vmm_present` sysctl to `kern.Xv_vmm_present`. 

When unprivileged processes call `sysctlbyname("kern.hv_vmm_present")`, the system returns **ENOENT** (entry not found), effectively hiding VM presence from standard detection scripts. However, the renamed sysctl remains accessible at the new OID, still returning the original value (1) for internal components that require it.

### Internal Caller Mangling

Beyond the OID rename, the same patch implements byte-level string rewriting for every hard-coded reference to `"kern.hv_vmm_present"` inside the kernel binary. As detailed in [`KernelEXPPatchHvVmmRename.swift`](https://github.com/Lakr233/vphone-cli/blob/main/KernelEXPPatchHvVmmRename.swift), the patch alters each occurrence by changing the first character: `'h'` → `'X'`.

This forces internal kernel components—including **AMFI**, the crypto accelerator, sandbox profiles, and APFS—to query the renamed OID automatically. External checks see a missing sysctl, while internal functionality expecting VM-aware behavior continues operating correctly.

## User-Space and Daemon Patching

The EXP variant extends anti-VM camouflage into user-space to prevent consistency errors that could leak virtualization state.

### Watchdogd Cache Patch

Located in [`cfw_install_exp.sh`](https://github.com/Lakr233/vphone-cli/blob/main/cfw_install_exp.sh) at step **[EXP-JB-3.5]** (lines 508-511), this patch targets the `watchdogd` daemon. A two-instruction rewrite modifies the daemon's cached `hv_vmm_present` value, ensuring it remains synchronized with the renamed sysctl. Without this patch, `watchdogd` might cache the original sysctl value, causing mismatches that reveal the VM environment to system integrity checks.

### Dynamic Shared Cache Mangling

The Python script [`cfw_patch_hv_vmm_dsc.py`](https://github.com/Lakr233/vphone-cli/blob/main/cfw_patch_hv_vmm_dsc.py) mirrors the kernel's rename operation across the user-space **Dynamic Shared Cache (DSC)**. Every DSC binary (except whitelisted system libraries) undergoes c-string rewriting to reference `kern.Xv_vmm_present` instead of the original OID.

This creates a selective visibility model: most applications receive non-VM responses, while a small blacklist of graphics and acceleration paths continue querying the original sysctl to enable hardware-specific optimizations. This approach provides false-negative VM detection for security tools while maintaining performance-critical code paths.

## Hardware Identity Spoofing

After restoring from snapshots, the EXP variant rewrites hardware-identifying metadata to simulate physical iPhone characteristics.

### DeviceTree Post-Restore Rewrite

Step **[EXP-JB-6]** in [`cfw_install_exp.sh`](https://github.com/Lakr233/vphone-cli/blob/main/cfw_install_exp.sh) (lines 722-749) executes immediately after VM restoration. The script rewrites `devicetree.img4` to inject "device-like" properties, including camera nodes and physical product identifiers. These modifications make the virtual machine appear as genuine hardware to iOS kernel routines that inspect the DeviceTree structure during boot and runtime.

### SystemVersion Build Spoofing

At step **[EXP-JB-7]** (lines 793-811), the installation script checks for the `SPOOF_BUILD` environment variable. When present, it replaces the `ProductBuildVersion` key in `SystemVersion.plist` with a user-specified build ID. This prevents services from detecting generic VM image builds that typically expose virtualized environments in enterprise or testing scenarios.

## Implementation Workflow

To build and deploy the EXP variant with its anti-VM-detection capabilities:

```bash

# Enable the experimental pipeline and apply patches

make setup_machine EXP=1
make fw_patch_exp
make cfw_install_exp

```

Programmatically enabling EXP mode in Swift:

```swift
// Configure VM options for anti-VM detection
let options = VPhoneVirtualMachine.Options(
    variant: .exp,  // Triggers KernelEXPPatcher
    enableFrida: false
)

```

Manually applying the sysctl rename via Python:

```python
from patchers.cfw_patch_hv_vmm_dsc import rename_hv_vmm_sysctl

# Apply DSC-level patches

rename_hv_vmm_sysctl('/path/to/kernelcache')

```

## Summary

- **Sysctl renaming** in [`KernelEXPPatchHvVmmRename.swift`](https://github.com/Lakr233/vphone-cli/blob/main/KernelEXPPatchHvVmmRename.swift) hides `kern.hv_vmm_present` from external queries while preserving it internally as `kern.Xv_vmm_present`.
- **Kernel string mangling** redirects internal components to the renamed OID, ensuring AMFI, sandbox, and APFS functionality remains intact.
- **Watchdogd patching** maintains cache consistency to prevent daemon-level VM detection leaks.
- **DSC mangling** extends the sysctl rename to user-space libraries, creating selective visibility for apps versus graphics accelerators.
- **DeviceTree rewriting** post-restore injects physical device properties to mask VM hardware signatures.
- **Build version spoofing** via `SPOOF_BUILD` environment variable eliminates generic VM image identifiers from `SystemVersion.plist`.

## Frequently Asked Questions

### How does the EXP variant prevent apps from detecting virtualization?

The EXP variant renames the `kern.hv_vmm_present` sysctl to `kern.Xv_vmm_present` in both kernel and user-space DSC binaries. Standard detection calls return ENOENT, indicating the sysctl does not exist, while internal system components query the renamed OID to maintain expected behavior.

### What is the purpose of mangling kernel-internal string references?

Kernel-internal caller mangling ensures that hard-coded queries for `"kern.hv_vmm_present"` inside AMFI, the crypto accelerator, and sandbox profiles automatically target the renamed `kern.Xv_vmm_present` without requiring source code changes. This preserves system functionality while preventing external detection.

### Can the EXP variant spoof specific iPhone hardware models?

Yes. During step **[EXP-JB-6]** in [`cfw_install_exp.sh`](https://github.com/Lakr233/vphone-cli/blob/main/cfw_install_exp.sh), the script rewrites `devicetree.img4` to include physical device properties such as camera nodes and product identifiers. Additionally, setting the `SPOOF_BUILD` environment variable allows customization of the `ProductBuildVersion` in `SystemVersion.plist` to match specific hardware builds.