CheckPointSW / InviZzzible

InviZzzible is a tool for assessment of your virtual environments in an easy and reliable way. It contains the most recent and up to date detection and evasion techniques as well as fixes for them.
GNU General Public License v3.0
536 stars 79 forks source link

Not all strings cachted? #16

Closed Code-Case closed 1 year ago

Code-Case commented 1 year ago

Hi guys,

thank you so much for this cool tool.

I made the Checks for my vm and fixed them all except the string: ven_15ad, I cant change and save it in my registry or is it possible on another way?

The next thing is that after all the work their still a bunch of vmware strings that can be found, but I ask me, can everybody make a full registry scan with any external installed software or not?

Because of the Admin rights for the installation/running the software it should be so and they can figure out that its a vm?

best regards

chkp-alexanderc commented 1 year ago

Hi,

Changes in the registry is just one approach that could be undertaken and, of course, it is not the best fit for every case. You can use filter driver functionality to address most of the filesystem\registry checks.

If you are aware of any other VMware strings, which are leading to detection, you can issue a pull request and we would definitely consider it.