How VMAware Detects VMware, VirtualBox, and QEMU Hypervisors: 90+ Techniques Explained

VMAware uses a multi-layered detection framework with over 90 techniques that combine CPUID hypervisor bits, OS-level artifacts in /proc and /sys, kernel module inspection, and hardware backdoor commands to identify VMware, VirtualBox, and QEMU with configurable certainty thresholds.

VMAware is an open-source C++ library that implements a comprehensive hypervisor detection framework. According to the kernelwernel/vmaware source code, the library analyzes low-level hardware fingerprints, CPU instruction behaviors, and operating system artifacts to determine if code is running inside a virtual machine. This article examines the specific techniques VMAware uses to detect the three most common hypervisors.

CPU-Based Detection Foundations

Hypervisor Bit Verification

The most reliable initial check is the HYPERVISOR_BIT technique. This examines CPUID leaf 0x1, specifically the ECX register bit 31. On physical hardware, this bit is always cleared, but every modern hypervisor—including VMware, VirtualBox, and QEMU—sets this bit to indicate the presence of a virtual machine monitor. This provides a 100% certainty trigger before deeper analysis begins.

CPUID Vendor String Analysis

VMAware implements the VM::VMID technique to read hypervisor-specific vendor strings from CPUID leaves 0x40000000 through 0x40000100. These extended leaves contain identifying strings that hypervisors optionally expose:

  • VMware and VirtualBox embed their brand identifiers in these leaves
  • QEMU injects "QEMU" specifically in leaf 0x40000001, which is isolated by the VM::CPUID_SIGNATURE check at line 5033 of src/vmaware.hpp

VMware Detection Techniques

VMAware targets VMware through a combination of procfs artifacts, SCSI device enumeration, and proprietary backdoor protocols.

Memory and I/O Port Scanning

Two high-certainty Linux-specific techniques inspect kernel resource mappings:

  • VM::VMWARE_IOMEM (line 5842): Scans /proc/iomem for the "VMware" string identifier with 65% certainty
  • VM::VMWARE_IOPORTS (line 6353): Examines /proc/ioports for VMware-specific I/O reservations with 70% certainty

Device and Kernel Artifacts

Additional VMware signatures appear in device listings and kernel logs:

  • VM::VMWARE_SCSI (line 6151): Parses /proc/scsi/scsi for VMware-specific SCSI device names (40% certainty)
  • VM::VMWARE_DMESG (line 6170): Greps the kernel ring buffer (dmesg) for VMware device strings (65% certainty), though this technique is disabled by default

Hardware Backdoor Commands

On Windows, VMAware employs the official VMware I/O-port backdoor:

  • VM::VMWARE_BACKDOOR (line 8192): Issues a handshake to I/O port 0x5658 using the VMware-defined backdoor protocol, providing 100% certainty through direct hypervisor communication

On Linux, the library uses an alternative low-level approach:

  • VM::VMWARE_STR (line 8167): Executes an inline str assembly instruction that behaves differently when intercepted by VMware's hypervisor handling mechanisms (35% certainty)

VirtualBox Detection Techniques

VirtualBox detection relies primarily on kernel module presence and CPUID branding.

Kernel Module Verification

  • VM::VBOX_MODULE (line 6128): Checks for loaded kernel modules named vboxdrv on Linux or VBoxGuest on macOS. While this has only 15% certainty in isolation due to potential module name variations, it serves as a strong corroborating signal when combined with other techniques.

CPUID Vendor Identification

  • VM::VMID (line 4774): Reads the CPUID vendor string "VBox" from the hypervisor leaves, providing 100% certainty when present.

QEMU Detection Techniques

QEMU detection focuses on DMI (Desktop Management Interface) artifacts, USB descriptors, and firmware configuration interfaces.

DMI and Firmware Inspection

  • VM::QEMU_VIRTUAL_DMI (line 5939): Examines /sys/devices/virtual/dmi/id for "QEMU" identifiers in the system management BIOS data (40% certainty)
  • VM::QEMU_FW_CFG (line 6398): Detects the fw_cfg interface through device-tree nodes or the qemu_fw_cfg kernel module, which is unique to QEMU's configuration mechanism (70% certainty)

USB Subsystem Analysis

  • VM::QEMU_USB (line 5968): Reads /sys/kernel/debug/usb/devices for QEMU-specific USB descriptors. This requires administrative privileges and carries 20% certainty, but helps distinguish QEMU from other Type-2 hypervisors.

CPU Signature Verification

  • VM::CPUID_SIGNATURE (line 5033): Isolates CPUID leaf 0x40000001 to verify the "QEMU" signature string, achieving 95% certainty when matched.

Heuristic Scoring and Aggregation

Each technique in src/vmaware.hpp contributes a weighted certainty percentage to an aggregate score. For example:

  • VM::VMWARE_BACKDOOR contributes 100%
  • VM::VMWARE_IOPORTS contributes 70%
  • VM::QEMU_USB contributes 20%

The library's VM::detect() function returns true only when the cumulative score exceeds a configurable threshold (default 70%). This design allows users to balance detection accuracy against false-positive risks by enabling specific technique subsets.

Practical Implementation Examples

The following C++ examples demonstrate how to invoke specific hypervisor detection routines:

// Detect any VM using the default technique subset
bool is_vm = VM::detect();

// Force detection using only VMware-specific checks
bool vmware = VM::detect(
    VM::VMWARE_IOMEM,
    VM::VMWARE_IOPORTS,
    VM::VMWARE_BACKDOOR
);

// Detect VirtualBox via kernel module and CPUID vendor
bool vbox = VM::detect(
    VM::VBOX_MODULE,
    VM::VMID
);

// Detect QEMU using DMI, firmware config, and USB artifacts
bool qemu = VM::detect(
    VM::QEMU_VIRTUAL_DMI,
    VM::QEMU_FW_CFG,
    VM::QEMU_USB
);

// Enable all 90+ techniques for maximum coverage
bool all_checks = VM::detect(VM::ALL);

Summary

  • VMAware implements 90+ detection techniques across multiple abstraction layers to identify VMware, VirtualBox, and QEMU
  • CPU-based detection uses CPUID leaves 0x40000000+ and the hypervisor bit (ECX bit 31) for initial 100% certainty triggers
  • VMware-specific techniques include procfs scans (/proc/iomem, /proc/ioports), SCSI enumeration, dmesg analysis, and the I/O port 0x5658 backdoor protocol
  • VirtualBox is primarily identified through kernel modules (vboxdrv, VBoxGuest) and CPUID "VBox" strings
  • QEMU detection relies on DMI artifacts in /sys/devices/virtual/dmi/id, the fw_cfg interface, and USB subsystem descriptors
  • The library uses weighted heuristic scoring (default threshold 70%) to aggregate evidence from multiple techniques before confirming virtualization

Frequently Asked Questions

How accurate is VMAware at detecting VMware versus VirtualBox?

VMAware achieves 100% certainty for VMware when the VM::VMWARE_BACKDOOR technique succeeds on Windows, as this uses the official VMware I/O port protocol. VirtualBox detection reaches 100% certainty through the VM::VMID CPUID check when the hypervisor exposes the "VBox" string. Both hypervisors can be detected with lower certainty (15-70%) through secondary artifacts like kernel modules and procfs entries alone.

Can VMAware detect hypervisors on both Windows and Linux?

Yes. The library contains platform-specific implementations in src/vmaware.hpp. Windows-specific techniques include the VMware I/O port backdoor (VM::VMWARE_BACKDOOR), while Linux-specific techniques inspect /proc and /sys filesystems (VM::VMWARE_IOMEM, VM::QEMU_VIRTUAL_DMI). CPUID-based techniques work across all platforms.

What is the performance impact of running all 90+ detection techniques?

Running the full VM::ALL set involves multiple file system reads, kernel buffer parsing, and CPUID executions. While individual checks are lightweight, the cumulative overhead increases with techniques requiring administrative access (like VM::QEMU_USB). Users should enable only the necessary technique subsets—such as VM::VMID and VM::HYPERVISOR_BIT—for performance-critical applications.

How does VMAware avoid false positives when detecting QEMU?

The library relies on multiple corroborating signals rather than single artifacts. QEMU detection combines DMI strings (40% certainty), fw_cfg interface detection (70% certainty), and CPUID signatures (95% certainty). The default 70% aggregate threshold requires at least two independent techniques to trigger a positive detection, reducing the chance of false identification from coincidental string matches in system files.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →