Hyper-V Virtual Machine Hardening

From Elvis Wiki
Revision as of 14:58, 20 January 2025 by CHoerhan (talk | contribs)

This article shows how a virtual machin(VM) can be modified to evade detection from malware. This process is also called VM hardening. In dynamic malware analysis, researchers use virtual machines to execute malware in a safe and isolated environment in order to monitor and investigate its behavior. This is why malware author started to use Anit-VM techniques to detect if their programs are running inside a virtual environment and subsequently evade the analysis process. In this article a virtual machine is set up and a number of open-source VM-detection tools is executed to see how the VM can be detected by malware. Afterwards countermeasures are implemented to mitigate the detection rate of the tools.

Setup

  • Host OS: Windows 11
  • Hypervisor: Microsoft Hyper-V
  • Guest OS (VM OS): Windows 10

Three tools are used for the VM detection. They are all open-source and can be found on GitHub:

  • Pafish (Paranoid Fish)
  • VMAware
  • Al-Khaser