VM : disable-monitor-control

Information

When Virtual Machines are running on a hypervisor they are 'aware' that they are running in a virtual environment and this and this information is available to tools inside the guest OS. This can give attackers information about the platform that they are running on that they may not get from a normal physical server. This option completely disables all hooks for a virtual machine and the guest OS will not be aware that it is running in a virtual environment at all.

Solution

Set isolation.monitor.control.disable to true in the virtual machine configuration file.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: VMware

Control ID: 7d33d2f1d6ee4807710a68c072a4f3a0c32c24daeb811eae24bf00c89abc1751