# Can VMAware Detect Multiple Virtual Machines Running Simultaneously?

> Discover if VMAware detects multiple virtual machines simultaneously. Learn why this single-process library only identifies the current VM environment.

- Repository: [Louis/vmaware](https://github.com/kernelwernel/vmaware)
- Tags: deep-dive
- Published: 2026-03-05

---

**No, VMAware cannot detect multiple virtual machines running simultaneously; it is architected as a single-process library that identifies only the virtualization environment of the current process.**

VMAware is a C++ library maintained in the `kernelwernel/vmaware` repository that determines whether the executing process is running inside a hypervisor. While it employs over 150 detection techniques to identify specific brands like VirtualBox, VMware, or QEMU, its design fundamentally aggregates results into a **single VM brand** for the current environment, not an inventory of all VMs on a physical host.

## How Single-Process Detection Works

The library centers on the `VM::detect()` function, which triggers the core detection routine. Inside [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp), the `core::run_all()` method (lines 11946-11950) executes the technique table—an enumeration of checks defined in `enum enum_flags` (lines 00557-00653)—that inspect CPU features, firmware signatures, BIOS tables, and device names.

Results are stored in a **brand score array** (`brand_array_t`, defined at lines 00884-00886), where each technique contributes points to specific hypervisor brands. After execution, the highest-scoring brand is returned as the definitive result. This architecture inherently limits output to one environment per process execution.

## The MULTIPLE Flag Misconception

The `MULTIPLE` flag does not enable detection of multiple VMs. According to the source code at lines 11861-11876 in [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp), this flag only controls internal default flag-generation behavior during library initialization.

Furthermore, the public `VM::check()` function explicitly rejects `MULTIPLE` when passed as a technique argument (lines 12027-12033). This confirms that the library treats every query as a question about **one specific environment**—the virtualization layer hosting the current process.

## Nested Virtualization vs. Concurrent VMs

VMAware handles nested virtualization (a VM inside another VM) by reporting only the **innermost visible hypervisor**. For instance, if the process runs inside a VirtualBox VM that itself runs on a VMware host, VMAware identifies the immediate VirtualBox environment rather than listing both hypervisors. This differs fundamentally from detecting multiple independent VMs running side-by-side on a physical host, which remains outside the library's scope.

## Code Example

The following demonstrates VMAware's single-environment API:

```cpp
#include "vmaware.hpp"
#include <iostream>

int main() {
    // Detects whether the current process runs inside *any* VM.
    bool vm_present = VM::detect();                // Single-environment detection
    std::cout << "VM detected? " << vm_present << '\n';

    // Retrieves the most likely VM brand for this process.
    std::string brand = VM::brand();               // e.g., "VirtualBox", "VMware"
    std::cout << "Detected brand: " << brand << '\n';

    // Queries a specific technique, still referring to *this* VM only.
    bool hypervisor_bit = VM::check(VM::HYPERVISOR_BIT);
    std::cout << "CPUID hypervisor bit set? " << hypervisor_bit << '\n';
}

```

When executed on a host running multiple concurrent VMs, this code reports exclusively on the virtualization layer containing the process itself. There is no API to retrieve a list of other active VMs or query their individual configurations.

## Core Implementation Files

- **[`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp)**: Contains all public APIs (`VM::detect()`, `VM::brand()`, `VM::check()`), the `enum_flags` technique enumeration, and the detection engine including `cpu::vmid_template` (lines 01136-01197) for mapping hypervisor signatures like `"Microsoft Hv"` to specific brands.
- **[`src/cli.cpp`](https://github.com/kernelwernel/vmaware/blob/main/src/cli.cpp)**: Command-line wrapper demonstrating library usage.
- **[`docs/documentation.md`](https://github.com/kernelwernel/vmaware/blob/main/docs/documentation.md)**: Human-readable descriptions of detection techniques and settings.

## Summary

- VMAware operates as a **single-process library** that inspects its own execution environment, not the entire host system.
- The **technique table** and **brand scoring array** (`brand_array_t`) aggregate evidence into one definitive hypervisor brand per execution.
- The **`MULTIPLE` flag** controls internal API behavior during initialization, not multiple VM enumeration, and is explicitly rejected by `VM::check()`.
- **Nested virtualization** is reported as a single hypervisor (the innermost layer), not as multiple simultaneous detections.
- The library **cannot enumerate** external VMs or differentiate between multiple independent virtual machines running concurrently on the same physical hardware.

## Frequently Asked Questions

### Can VMAware list all VMs currently running on a physical host?

No. VMAware lacks any API for enumerating virtual machines present on the host system. It only determines whether the process calling the library is executing inside a VM, returning a single boolean result and brand identifier for that specific environment.

### What does the MULTIPLE flag actually do in VMAware?

The `MULTIPLE` flag modifies how the library generates default flag sets during initialization (lines 11861-11876 in [`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp)). It does not enable detection of multiple virtual machines, and the `VM::check()` function explicitly rejects it as an invalid technique flag (lines 12027-12033).

### How does VMAware handle nested virtualization?

When running inside a nested virtual machine, VMAware identifies only the **innermost hypervisor** that directly hosts the process. It does not return a chain or list of all hypervisors in the stack, as it aggregates detection results into a single brand score via the `brand_array_t` structure.

### Which source file contains the core detection logic?

The primary detection engine resides in **[`src/vmaware.hpp`](https://github.com/kernelwernel/vmaware/blob/main/src/vmaware.hpp)**, specifically within the `core` struct's `run_all()` method and the `VM::detect()` wrapper function. This file also defines the technique enumeration (`enum_flags`), brand scoring array (`brand_array_t`), and CPUID inspection templates like `cpu::vmid_template` (lines 01136-01197).