We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
This article may spark some interest. https://labs.nettitude.com/blog/using-pooltags-to-fingerprint-hosts/
tl;dr; you can built table of specific pool tags used by vm drivers when allocating memory and then use it as vm detection vector.
This article provides complete example and this system information should be available starting from ancient times up to modern Win10 versions.
The text was updated successfully, but these errors were encountered:
Embarrassed to admit that I didn't know this trick, since I not only work at Nettitude but have worked with Kyriakos at two different companies!
Sorry, something went wrong.
Thanks @hfiref0x
When I saw the link, my initial taught that it was your post @gsuberland :)
Speaking of which, part 3 of my series is out. I'll open a new issue for it.
No branches or pull requests
This article may spark some interest.
https://labs.nettitude.com/blog/using-pooltags-to-fingerprint-hosts/
tl;dr; you can built table of specific pool tags used by vm drivers when allocating memory and then use it as vm detection vector.
This article provides complete example and this system information should be available starting from ancient times up to modern Win10 versions.
The text was updated successfully, but these errors were encountered: