Hunting for VMware artifacts based on its valid file,drivers certificate and registry keys value & description , running processes & services, Serial Number ,address MAC, , it's usefull for detecting Sandbox environment (VMware hypervisor in this case) -
View it on GitHub