logo

WinVisor – A hypervisor-based emulator for Windows x64 user-mode executables

ID: c274e8de-1de7-50c4-93d2-698fce96b454

STIX ID: report--c274e8de-1de7-50c4-93d2-698fce96b454

Feed Name: Elastic Security Labs

Date Published: 2025-01-24

Date Updated: 2026-04-27

...
...

This article presents WinVisor, a user‑mode Windows x64 virtualization framework built on the Windows Hypervisor Platform that clones a target process’s address space, initializes a virtual CPU via a CPL0 bootloader, and intercepts/logs syscalls (including legacy INT 2E) while handling paging, TLB flushes, and interrupts through placeholder traps. It covers VMX/WHP abstractions, GDT/IDT/TSS setup, MSR configuration, on-demand host/guest memory mirroring, a heuristic for syscall parameter counting via WoW64 stubs, and a workaround for a WHP hypervisor shared page bug, and it highlights major limitations (unsafe sandboxing, RWX mirroring, single-thread support, partial GUI virtualization, and lack of virtualized software exception handling), with source code available on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.