# Standard vs High Threshold Modes in VMAware: Detection Sensitivity Explained

> Understand VMAware detection sensitivity: standard vs high threshold modes. Learn how to balance false positives and detection accuracy for your VMs.

- Repository: [Louis/vmaware](https://github.com/kernelwernel/vmaware)
- Tags: deep-dive
- Published: 2026-03-05

---

**The standard mode uses a 150-point threshold to declare a VM detection, while high-threshold mode doubles this to 300 points, requiring significantly more evidence and reducing false positives at the cost of potentially missing stealthy VMs.**

VMAware is an open-source C++ library that detects virtual machine environments through a weighted scoring system. The library accumulates points from various low-level and high-level detection techniques, declaring a VM present only when the score reaches a configurable threshold. Understanding the difference between **standard** and **high threshold modes** is critical for balancing detection accuracy against false-positive rates in security-sensitive applications.

## How VMAware Detection Scoring Works

VMAware implements a consensus-based detection mechanism where individual checks contribute fixed point values to a running total. Each technique that identifies virtual machine artifacts—such as hypervisor signatures, CPU inconsistencies, or firmware anomalies—adds weight to the accumulator.

The library compares this accumulated score against a threshold constant to determine VM presence:

```cpp
static constexpr u16 threshold_score      = 150; // standard threshold score
static constexpr u16 high_threshold_score = 300; // new threshold score from 150 to 300 if VM::HIGH_THRESHOLD flag is enabled

```

*(source: [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp) lines 745-747)*

When the accumulated points meet or exceed the active threshold, the library returns a positive detection result.

## Standard Threshold Mode (150 Points)

The **standard threshold** of 150 points provides balanced detection suitable for most use cases. This default setting requires a moderate amount of corroborating evidence before declaring a VM environment, offering a compromise between detection speed and false-positive avoidance.

In [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp), the detection logic evaluates the standard threshold during the final scoring phase:

```cpp
u16 threshold_points = threshold_score;
if (points >= threshold_points) {
    // VM detected
}

```

This 150-point bar captures most common virtualization platforms—including VMware, VirtualBox, Hyper-V, and KVM—without requiring exhaustive forensic evidence.

## High Threshold Mode (300 Points)

The **high threshold mode** raises the detection bar to 300 points, effectively requiring twice the evidence volume of the standard mode. This conservative approach minimizes false positives in environments where legitimate hardware might occasionally trigger single detection artifacts.

The mode activates when the `VM::HIGH_THRESHOLD` flag is passed to detection functions. Internally, the library swaps the threshold constant:

```cpp
u16 threshold_points = threshold_score;
if (high_threshold_flag_is_set) {
    threshold_points = high_threshold_score;   // 300 points
}
if (points >= threshold_points) {
    // VM detected with high confidence
}

```

*(source: [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp) lines 11736-11740)*

According to the project documentation, this flag sets the threshold bar to confidently detect a VM by **2× higher**, making the library significantly more conservative in its positive declarations.

### Enabling via Command Line Interface

For CLI usage, append the `--high-threshold` flag to detection commands:

```bash

# Standard detection (150-point threshold)

vmaware --detect

# High-threshold detection (300-point threshold)

vmaware --detect --high-threshold

```

The CLI parser in [`src/cli.cpp`](https://github.com/kernelwernel/vmaware/blob/main/src/cli.cpp) (line 346) maps this argument to the internal `VM::HIGH_THRESHOLD` flag before invoking the detection engine.

### Enabling via C++ API

When integrating VMAware programmatically, pass `VM::HIGH_THRESHOLD` as a secondary argument to detection functions:

```cpp
#include "vmaware.hpp"

int main() {
    // Standard 150-point detection
    bool vm_standard = VM::detect(VM::ALL);
    
    // High-threshold 300-point detection
    bool vm_strict = VM::detect(VM::ALL, VM::HIGH_THRESHOLD);
    
    // High-threshold percentage confidence
    float confidence = VM::percentage(VM::ALL, VM::HIGH_THRESHOLD);
    std::cout << "VM confidence: " << confidence << "%\n";
}

```

All detection entry points—including `VM::detect()`, `VM::percentage()`, and `VM::brand()`—respect this flag and adjust their threshold calculations accordingly.

## When to Use Each Mode

Select the appropriate threshold based on your security requirements and environment characteristics:

- **Standard mode (150 points)**: Deploy this default when you need broad VM detection coverage and can tolerate occasional false positives. This setting catches most commercial and open-source hypervisors with minimal computational overhead.

- **High-threshold mode (300 points)**: Enable this stricter setting when investigating potential sandbox evasion or when operating in environments with unusual hardware configurations that might trigger individual detection artifacts. The doubled threshold reduces false alarms but may miss lightly virtualized or heavily obfuscated VMs.

## Summary

- VMAware uses a point-based scoring system where detection techniques accumulate evidence toward a threshold.
- **Standard mode** requires **150 points** to declare a VM, balancing sensitivity and false-positive rates.
- **High-threshold mode** requires **300 points**, doubling the evidence requirement to minimize false positives.
- Enable high-threshold mode via the `--high-threshold` CLI flag or the `VM::HIGH_THRESHOLD` API constant.
- The threshold constants `threshold_score` and `high_threshold_score` are defined in [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp) and evaluated in the core detection logic around line 11736.

## Frequently Asked Questions

### What happens if a VM scores between 150 and 299 points in high-threshold mode?

In high-threshold mode, scores between 150 and 299 points register as negative detections. The library returns `false` for `VM::detect()` and reports a percentage below 100% for `VM::percentage()`, effectively treating these mid-range scores as inconclusive evidence insufficient for high-confidence VM declaration.

### Can I customize the threshold value beyond 150 or 300?

No. VMAware exposes only two predefined thresholds through the `VM::HIGH_THRESHOLD` flag. The constants `threshold_score` (150) and `high_threshold_score` (300) are defined as `static constexpr` values in [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp) and compiled into the library. Modifying these requires editing the source and recompiling.

### Does high-threshold mode affect which detection techniques run?

No. Both modes execute the same comprehensive suite of detection techniques defined by the `VM::ALL` flag or your selected technique bitmask. The only difference is the threshold value against which the final accumulated score is compared. All checks run regardless of the threshold setting, but the higher bar requires more of them to return positive findings before declaring a VM.

### Which mode should I use for malware analysis sandboxes?

Use **high-threshold mode** when analyzing sophisticated malware that may implement anti-VM techniques or when operating in heterogeneous hardware environments. The 300-point threshold prevents single-artifact false positives—such as BIOS quirks or timing anomalies—from triggering false VM alerts, ensuring you only flag systems with strong, multi-factor virtualization evidence.