Your business’ toughest competition might be criminal. See why.
Utility navigation bar redirect icon
Portal LoginSupportContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response

    Managed EDR

    Get full endpoint visibility, detection, and response

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed ITDR

    Protect your Microsoft 365 identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training

    Empower your teams with science-backed security awareness training.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    ebooks
    ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    Huntress Lands on the Microsoft Marketplace
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    How Huntress & DEFCERT Are Streamlining CMMC Assessment Prep
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
    Live Hacking Into Microsoft 365 with Kyle Hanslovan
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Datto
    Datto
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportContact
Search
Close search
Get a Demo
Start for Free
HomeCybersecurity 101
Virtualization-Based Security (VBS)

Virtualization-Based Security (VBS) Explained for Cybersecurity Pros

Published: June 17, 2025

Written by: Lizzie Danielson

Glitch effectGlitch effect

Cyber threats are getting smarter, but so are our defenses. If you’re a cybersecurity professional, you’ve probably heard rumors about Virtualization-Based Security (VBS) and how it can transform endpoint protection. But is it worth enabling, and how much of your system should you entrust to this emerging Microsoft security frontier? This guide will break down what Virtualization-Based Security (VBS) really does, how it works, its advantages, drawbacks, and what you should know before flipping the switch.


Demystifying virtualization-based security (VBS)

What's VBS?


At its core, Virtualization-Based Security is Microsoft’s answer to a gnawing problem in endpoint protection. Conventional antivirus and firewalls protect your operating system’s open doors, but what about critical secrets stored within? VBS uses hardware virtualization to construct a fortified chamber inside a system, isolating sensitive assets from malware, even if malware slips past the front line.

Here’s the analogy: imagine your computer as an office building. The main OS is reception, open, and bustling. VBS builds a locked vault inside, guarded by its security crew, where your company’s secrets are stored. Any outsider—even one who sweet-talked the receptionist—isn’t getting in.

How VBS works

VBS operates by leveraging your machine’s hardware virtualization capabilities, most commonly Intel VT-x or AMD-V, and the Windows hypervisor. It creates a lightweight virtual “secure mode” (sometimes called Virtual Secure Mode or VSM). Within this zone, Windows fences off critical functions (like credential management and code integrity) from the main OS, even if the OS is compromised.


Key Components of VBS


  • Credential guard

This feature takes your operating system’s credentials (NTLM hashes, Kerberos tickets, etc.) and hides them in VBS’s isolated vault. If malware tries to run a pass-the-hash attack or dump credentials, it’s locked outside.

  • Hypervisor-enforced code integrity (HVCI)

Only code that’s properly signed and trusted can be executed in kernel mode. This stops rootkits and unsigned drivers in their tracks, blocking many attack chains before they gain a foothold.


Benefits of implementing VBS

It’s tempting to dismiss security features as “just another upgrade,” but VBS shifts the security model itself. Here’s how:

Enhanced protection from sophisticated threats

VBS is especially effective against credential theft, a favored move among advanced persistent threats (APTs) and ransomware gangs. By ring-fencing secrets in virtualized memory, VBS dramatically cuts the odds of lateral movement after an initial breach.

Critical process isolation

If your main OS is breached, malware still can’t reach the protected credentials or execute unsigned code in kernel mode. It’s like locking your valuables in a bank vault, even if a thief finds their way into the building lobby.

Enabler for advanced security features

VBS is the prerequisite for flagship protections like Credential Guard and HVCI, both of which require strong virtual isolation for their magic to work. Trying to enable these features without VBS is like installing a lock without putting in the door.

Examples of real-world protection:

  • Stopping pass-the-hash attacks that target domain credentials

  • Preventing drivers with known vulnerabilities from running in kernel mode

  • Reducing the risks from kernel exploits in malware like TrickBot or NotPetya


VBS drawbacks and considerations

No solution is flawless. Before making VBS your new favorite, pause for these practical realities.

Performance impact

Running VBS doesn’t come for free. On average, expect a five-15% performance overhead, especially in CPU- or graphics-intensive tasks like gaming or high-frequency trading applications. Some users have reported noticeable lag in demanding scenarios. For business-critical servers, weigh the security gain against potential slowdowns.

Hardware compatibility

VBS is picky. You’ll need:

  • A 64-bit processor with hardware virtualization support (Intel VT-x or AMD-V)

  • Second Level Address Translation (SLAT) for virtualization acceleration

  • Secure Boot, TPM 2.0, and sometimes a newer motherboard BIOS

Not every system qualifies. Old desktops or laptops can’t play, and even newer models sometimes need firmware updates.

Software compatibility

Applications that interact directly with hardware (certain performance monitoring tools, custom drivers, in-depth system utilities) might run into issues. VBS’s isolation blocks some of these functions, forcing developers and users to choose between compatibility and security.

Real-world scenario: 

A development team finds that their custom PCIe diagnostics tool no longer functions because VBS blocks the low-level direct memory access it needs.

How to check if VBS is enabled

Before you can take advantage of VBS, you need to know whether it’s active on your system.

Using system information

  1. Press Win + R, type “msinfo32,” and hit Enter.

  2. Look for the “Virtualization-based Security” entry in System Summary.

  • “Running” means you’re protected.

  • “Not enabled” means you’re not.

Using Windows security settings

  1. Go to “Settings” → “Update & Security” → “Windows Security.”

  2. Select “Device Security.”

  3. View the “Core Isolation” or “Security processor” details for VBS status.

If you see “Memory Integrity” enabled, you’re likely running HVCI, a key VBS feature.

Enabling or disabling VBS

If your system is compatible, here’s how to take control of VBS settings.

Enabling VBS

  • Confirm that Intel VT-x/AMD-V and SLAT are enabled in BIOS/UEFI.

  • Enable Secure Boot and TPM 2.0.

  • Use the Group Policy Editor:

  1. Open credit.MSC.

  2. Navigate to “Computer Configuration” → “Administrative Templates” → “System” → “Device Guard.”

  3. Enable “Turn on Virtualization Based Security.”

  • Or, in Windows Security:

    • Go to “Device Security,” select “Core Isolation,” and toggle “Memory Integrity.”

Disabling VBS

Warning: Disabling VBS makes your system more vulnerable to sophisticated attacks.

  • Open “Windows Features” and uncheck “Virtual Machine Platform” and “Windows Hypervisor Platform.”

  • Use Group Policy Editor to disable Device Guard and Credential Guard.

  • A system restart will be required to apply changes.

Actionable insights for security professionals

It’s easy to be lulled into a false sense of security by traditional defenses. VBS challenges that by pushing for a layered approach, isolating what matters most, and fortifying weaknesses that legacy solutions ignore.

  • For enterprise endpoints, VBS combined with Credential Guard can limit the fallout from credential compromise.

  • For individuals who handle sensitive data on their machines, enabling VBS adds an essential layer of security, even if it means sacrificing a few frames per second in demanding applications.

  • For system architects and admins, a hardware compatibility audit should precede any VBS rollout to prevent surprises.

Weigh the benefits and make an informed choice

There’s no silver bullet in cybersecurity. Virtualization-Based Security is a powerful, evolving tool that shifts the security landscape, giving professionals a robust way to shield critical processes and credentials, even when the first line of defense is breached.

The trade-off for enhanced protection? A modest hit to performance and a few hardware and software headaches. Whether VBS is worth enabling depends on your environment’s risk profile, asset criticality, and performance demands. But as threats grow more advanced and attackers become more persistent, staying ahead means being informed and proactive about next-generation features like VBS.

Staying vigilant, making strategic decisions, and continuously strengthening your defense layers will keep you ahead of cybercriminals who are always one step away from breaching your conventional lines











FAQs about virtual machines


  • Software development: Testing software in multiple environments.
  • Cybersecurity: Running penetration tests or analyzing malware safely.
  • Legacy systems: Running outdated applications on older operating systems.
  • Education: Experimenting with different OS without purchasing additional hardware.

While both VMs and Docker enable isolation, Docker is better suited for lightweight, containerized applications. However, VMs are ideal when you need a fully functional OS

Yes! Though gaming on a VM comes with limitations (e.g., reduced graphics performance), advancements in GPU passthrough now make it feasible for certain setups.

Absolutely. Many security-conscious users browse the web via a VM to isolate their primary system from potential threats.

Several factors can slow down a VM:

  • Insufficient RAM or CPU allocation.
  • High disk usage on the host machine.
  • Too many VMs are running simultaneously.
  • Outdated virtualization software or VM OS.


The number of VMs you can run depends entirely on your hardware specifications. For most systems, running 2–3 VMs concurrently is realistic with mid-range specs. Servers will handle significantly more.

Glitch effectGlitch effectBlurry glitch effect

Safely virtualizing your way forward

Virtual machines are a versatile tool that can benefit individuals and businesses alike. From safer web browsing to scalable enterprise solutions, the use cases for VMs are nearly limitless. But don’t be fooled by their versatility; setting up a VM properly and following best practices for security is essential to making the most of them. 


Glitch effect

Related Resources


  • Virtual Machines 101: What They Are and How to Use Them Securely
    Virtual Machines 101: What They Are and How to Use Them Securely
    Learn what virtual machines are, how to set one up, optimize performance, and ensure security. A complete guide to mastering VMs!
  • What is a Hypervisor and Why It Matters for Cybersecurity in Virtualized Environments
    What is a Hypervisor and Why It Matters for Cybersecurity in Virtualized Environments
    Learn what a hypervisor is, how it works, and the essential security practices to protect virtualized environments from advanced threats.
  • Containerization in Cybersecurity Explained
    Containerization in Cybersecurity Explained
    Learn how containerization improves cybersecurity through app isolation, reduced vulnerabilities, and seamless deployment. Explore best practices for secure containers.
  • What Is Sandbox Escape in Cybersecurity?
    What Is Sandbox Escape in Cybersecurity?
    Sandboxing is a technique that cybersecurity experts use to isolate code execution in a controlled environment to prevent a bigger impact of malicious code.
  • What is Cloud Computing? An Essential Guide For Businesses
    What is Cloud Computing? An Essential Guide For Businesses
    Learn what cloud computing is, how it differs from virtualization, AI, and why it’s vital for modern businesses. Discover the benefits and key concepts in this complete guide.
  • What is Root Access? A Complete Cybersecurity Guide
    What is Root Access? A Complete Cybersecurity Guide
    Learn what root access means in cybersecurity, how it works across operating systems, security risks, and best practices for protection.
  • What is a Network Redirector?
    What is a Network Redirector?
    Learn what a network redirector is, why it matters for cybersecurity, and how attackers target them. Simple guide for pros and learners.
  • Understanding Agent-Based vs. Agentless Security
    Understanding Agent-Based vs. Agentless Security
    Learn the key differences between agent-based and agentless security approaches. Learn when to deploy each, the pros and cons, and how to build a resilient cybersecurity strategy.
  • What Is Network Segmentation?
    What Is Network Segmentation?
    Learn how breaking your network into smaller parts can amp up security by limiting risks and isolating sensitive data.

Protect What Matters

Secure endpoints, email, and employees with the power of our 24/7 SOC. Try Huntress for free and deploy in minutes to start fighting threats.
Try Huntress for Free
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 215k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy