sliver
sliver copied to clipboard
Implant: add virtualization detection
Summary
This PR adds virtualization detection to the implant On startup, during the registration request, the implant now sends a field indicating whether it is running inside a virtual machine
Details
- Added lightweight virtualization checks
- Added new field to the registration struct
- Updated server side to read/store the new field
- Updated related protobuffs
Why
Operators gain immediate insight into whether the compromised host is virtualized,
Related Issue
Feature #2055
This is cool but i would suggest having an optional parameter in the generate just in case it creates IOC for EDR to pick