Standard vs High Threshold Modes in VMAware: Detection Sensitivity Explained
The standard mode uses a 150-point threshold to declare a VM detection, while high-threshold mode doubles this to 300 points, requiring significantly more evidence and reducing false positives at the cost of potentially missing stealthy VMs.
VMAware is an open-source C++ library that detects virtual machine environments through a weighted scoring system. The library accumulates points from various low-level and high-level detection techniques, declaring a VM present only when the score reaches a configurable threshold. Understanding the difference between standard and high threshold modes is critical for balancing detection accuracy against false-positive rates in security-sensitive applications.
How VMAware Detection Scoring Works
VMAware implements a consensus-based detection mechanism where individual checks contribute fixed point values to a running total. Each technique that identifies virtual machine artifacts—such as hypervisor signatures, CPU inconsistencies, or firmware anomalies—adds weight to the accumulator.
The library compares this accumulated score against a threshold constant to determine VM presence:
static constexpr u16 threshold_score = 150; // standard threshold score
static constexpr u16 high_threshold_score = 300; // new threshold score from 150 to 300 if VM::HIGH_THRESHOLD flag is enabled
(source: src/vmaware.hpp lines 745-747)
When the accumulated points meet or exceed the active threshold, the library returns a positive detection result.
Standard Threshold Mode (150 Points)
The standard threshold of 150 points provides balanced detection suitable for most use cases. This default setting requires a moderate amount of corroborating evidence before declaring a VM environment, offering a compromise between detection speed and false-positive avoidance.
In src/vmaware.hpp, the detection logic evaluates the standard threshold during the final scoring phase:
u16 threshold_points = threshold_score;
if (points >= threshold_points) {
// VM detected
}
This 150-point bar captures most common virtualization platforms—including VMware, VirtualBox, Hyper-V, and KVM—without requiring exhaustive forensic evidence.
High Threshold Mode (300 Points)
The high threshold mode raises the detection bar to 300 points, effectively requiring twice the evidence volume of the standard mode. This conservative approach minimizes false positives in environments where legitimate hardware might occasionally trigger single detection artifacts.
The mode activates when the VM::HIGH_THRESHOLD flag is passed to detection functions. Internally, the library swaps the threshold constant:
u16 threshold_points = threshold_score;
if (high_threshold_flag_is_set) {
threshold_points = high_threshold_score; // 300 points
}
if (points >= threshold_points) {
// VM detected with high confidence
}
(source: src/vmaware.hpp lines 11736-11740)
According to the project documentation, this flag sets the threshold bar to confidently detect a VM by 2× higher, making the library significantly more conservative in its positive declarations.
Enabling via Command Line Interface
For CLI usage, append the --high-threshold flag to detection commands:
# Standard detection (150-point threshold)
vmaware --detect
# High-threshold detection (300-point threshold)
vmaware --detect --high-threshold
The CLI parser in src/cli.cpp (line 346) maps this argument to the internal VM::HIGH_THRESHOLD flag before invoking the detection engine.
Enabling via C++ API
When integrating VMAware programmatically, pass VM::HIGH_THRESHOLD as a secondary argument to detection functions:
#include "vmaware.hpp"
int main() {
// Standard 150-point detection
bool vm_standard = VM::detect(VM::ALL);
// High-threshold 300-point detection
bool vm_strict = VM::detect(VM::ALL, VM::HIGH_THRESHOLD);
// High-threshold percentage confidence
float confidence = VM::percentage(VM::ALL, VM::HIGH_THRESHOLD);
std::cout << "VM confidence: " << confidence << "%\n";
}
All detection entry points—including VM::detect(), VM::percentage(), and VM::brand()—respect this flag and adjust their threshold calculations accordingly.
When to Use Each Mode
Select the appropriate threshold based on your security requirements and environment characteristics:
-
Standard mode (150 points): Deploy this default when you need broad VM detection coverage and can tolerate occasional false positives. This setting catches most commercial and open-source hypervisors with minimal computational overhead.
-
High-threshold mode (300 points): Enable this stricter setting when investigating potential sandbox evasion or when operating in environments with unusual hardware configurations that might trigger individual detection artifacts. The doubled threshold reduces false alarms but may miss lightly virtualized or heavily obfuscated VMs.
Summary
- VMAware uses a point-based scoring system where detection techniques accumulate evidence toward a threshold.
- Standard mode requires 150 points to declare a VM, balancing sensitivity and false-positive rates.
- High-threshold mode requires 300 points, doubling the evidence requirement to minimize false positives.
- Enable high-threshold mode via the
--high-thresholdCLI flag or theVM::HIGH_THRESHOLDAPI constant. - The threshold constants
threshold_scoreandhigh_threshold_scoreare defined insrc/vmaware.hppand evaluated in the core detection logic around line 11736.
Frequently Asked Questions
What happens if a VM scores between 150 and 299 points in high-threshold mode?
In high-threshold mode, scores between 150 and 299 points register as negative detections. The library returns false for VM::detect() and reports a percentage below 100% for VM::percentage(), effectively treating these mid-range scores as inconclusive evidence insufficient for high-confidence VM declaration.
Can I customize the threshold value beyond 150 or 300?
No. VMAware exposes only two predefined thresholds through the VM::HIGH_THRESHOLD flag. The constants threshold_score (150) and high_threshold_score (300) are defined as static constexpr values in src/vmaware.hpp and compiled into the library. Modifying these requires editing the source and recompiling.
Does high-threshold mode affect which detection techniques run?
No. Both modes execute the same comprehensive suite of detection techniques defined by the VM::ALL flag or your selected technique bitmask. The only difference is the threshold value against which the final accumulated score is compared. All checks run regardless of the threshold setting, but the higher bar requires more of them to return positive findings before declaring a VM.
Which mode should I use for malware analysis sandboxes?
Use high-threshold mode when analyzing sophisticated malware that may implement anti-VM techniques or when operating in heterogeneous hardware environments. The 300-point threshold prevents single-artifact false positives—such as BIOS quirks or timing anomalies—from triggering false VM alerts, ensuring you only flag systems with strong, multi-factor virtualization evidence.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →