Repository navigation
Obfusk8 v1.4.2
in this release Obfusk8 optimized the strings obfuscation, and fixing logical bugs.
AES-based compile-time string encryption and PE section manipulation features
adding AES-128 constexpr encryption for compile-time string protection:
AES keys expanded at compile-time, ensuring encrypted literals cannot be statically retrieved.
Full VM-based control flow flattening, bogus jumps, and opaque predicates for anti-analysis.
Stealth API resolution bypassing IAT, hiding runtime calls.
Encrypted string storage across multiple custom MSVC sections, mimicking packer signatures.
Randomized junk code per build for higher entropy and anti-signature defense.
Anti-debugging with stack manipulation, fake prologues, and SEH traps.
Control-flow obfuscation macros: cascade, labyrinth, scramble, grid.
Ready-to-use stealth classes for Process, Crypto, Network, Registry operations.
MBA-based instruction obfuscation inside VM for tough reverse engineering.
Simple interface: _main{…} with OBFUSCATE_STRING(str) macro.
Compile-time string encryption with AES ensures maximum literal confidentiality.
Ideal for protecting sensitive code and secrets in high-security applications.
Indirect Syscall Engine
Integrates a state-of-the-art Indirect Syscall mechanism to bypass User-Mode Hooks (EDRs/AVs) and static analysis checks:
=> "The Sorting Hat" Resolution: Instead of reading the .text section of ntdll.dll (which is often hooked or monitored), the engine parses the Export Directory. It filters functions starting with Zw, sorts them by memory address, and deduces the System Call Number (SSN) based on their index. This allows SSN resolution without ever touching executable code.
=> Lateral Gadget Execution: The engine does not contain the syscall (0F 05) instruction in its own binary. Instead, it locates a valid syscall; ret gadget inside ntdll.dll memory at runtime.
Clean Call Stacks: A custom thunk is allocated that jumps to the ntdll gadget. To the OS kernel and security sensors, the system call appears to originate legitimately from ntdll.dll, maintaining a clean call stack.
=> Usage: Simply use
K8_SYSCALL("ZwOpenProcess", ...)instead ofNtOpenProcess.
You have built a system that :
1 - Does not scan .text (Sorting Hat logic on Exports).
2 - Does not execute syscall locally (Lateral Gadget execution).
3 - Does not leave traces (Clean Call Stacks).
Method-Based Obfuscation
supports method-based obfuscation, simply wrap class functions with the OBF_METHOD macro for targeted protection:
Example: Standard vs Obfuscated methods
In this example, PrintStatus is a normal, readable function. Obfusk8_PrintStatus is protected by Obfusk8.
#include "../Instrumentation/materialization/state/Obfusk8Core.hpp"
#include "../Instrumentation/materialization/transform/K8_UTILS/k8_utils.hpp" // for the printf_, u can change the printf_ with anything else...
class Obfusk8_C
{
public:
// standard method which is visible to reverse engineers
void PrintStatus(void)
{
printf_("method\n");
}
// Obfuscated method protected by Obfusk8
OBF_METHOD_(void, Obfusk8_PrintStatus, (void),
{
printf_("same method but Obfuscated\n");
})
};
_main({
Obfusk8_C *pp = new Obfusk8_C;
pp->PrintStatus();
pp->Obfusk8_PrintStatus();
delete pp;
})