Ophion: The Hypervisor That Lies to the Clock
How a stealth Type-2 hypervisor uses micro-architectural time compensation and private memory boundaries to subsume Windows and evade modern anti-cheats.

Intel VT-x Type-2 hypervisor that virtualizes an already running Windows system. Designed for stealth: passes common hypervisor detection checks and works with **EAC/BE/AVs out of the box.**
- Ophion defeats Ring-0 anti-cheats by mathematically subtracting its own computational overhead from the CPU's timekeeping.
- It protects itself from hostile guest operating systems by deep-copying the kernel page tables into a private, isolated memory space.
- Unlike educational reference hypervisors, Ophion is designed as a turn-key stealth platform capable of bypassing major anti-cheat systems without modification.
The Stopwatch Problem
Modern anti-cheats operate at the lowest levels of the Windows kernel. When they look for hidden hypervisors, they do not search for files or memory signatures. They simply measure time. By executing a sensitive instruction like CPUID, the guest operating system forces the CPU to transition into hypervisor mode. This transition is called a VM-exit.
A VM-exit takes thousands of clock cycles to process. Security software records the exact timestamp before and after the instruction bounds. If the execution takes abnormally long, the anti-cheat concludes a hypervisor is present and immediately crashes the game. To survive, a hypervisor cannot just be invisible. It must counterfeit the latency of bare-metal hardware.
The Trap-and-Compensate Engine
Ophion solves the stopwatch problem using a dynamic trap-and-compensate strategy. When an instruction triggers a VM-exit, the engine calculates the exact computational cost of its own intervention. It then arms a flag to intercept the very next time-stamp counter request.
When the anti-cheat asks the CPU for the current time via the RDTSC instruction, Ophion steps in. It takes the true hardware time, subtracts the exact microsecond overhead of the previous VM-exit, and passes the spoofed value back to the guest. The execution appears perfectly native.
Building a Private Universe
A hypervisor that subsumes an active OS cannot trust the kernel it sits beneath. Aggressive security drivers often intentionally corrupt system Page Table Entries to probe for hidden virtualization layers. If a naive hypervisor relies on the guest's memory structures, it will crash the machine.
Ophion neutralizes this threat by deep-copying the critical kernel page tables. It establishes a private Host CR3, alongside a private Global Descriptor Table and Interrupt Descriptor Table. This creates a ghost version of the kernel that only exists when the CPU is in VMX-root mode. The hypervisor maintains perfect state regardless of what the guest OS attempts to corrupt.
The Turn-Key Ghost
The open-source hypervisor landscape is split into two distinct camps. On one side are educational reference models like SimpleVisor. They are excellent learning tools but lack stealth features, making them instantly detectable by security software. On the other side are heavy research tools like DHypervisor, which require massive custom coding to hide effectively.
Ophion occupies a unique niche. It implements complex Intel manual requirements that educational tools skip, providing a stable, invisible foundation out of the box. It is a purpose-built platform for developers who need extreme stealth without writing thousands of lines of custom evasion logic.
| Hypervisor | Primary Focus | Out-of-the-box Stealth | TSC Mitigation |
|---|---|---|---|
| Ophion | Evasion & Game Hacking | Yes | Dynamic Compensation |
| DHypervisor | Advanced Research | No | Manual Implementation Required |
| SimpleVisor | Educational Reference | No | None |