Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Can someone explain what AntiMode does in AntiTamper #52

Open
rollsch opened this issue Jul 3, 2019 · 2 comments
Open

Can someone explain what AntiMode does in AntiTamper #52

rollsch opened this issue Jul 3, 2019 · 2 comments

Comments

@rollsch
Copy link

rollsch commented Jul 3, 2019

Can someone explain what the "anti" mode in anti tamper protection does? The documentation only describes the NormalMode and JITMode, Anti mode appears to be new and only available in neo-confuserex.

Is this meant to be hidden?

The reason I ask is all 3 modes of anti-tamper cause my executable to crash with no exception. If I debug it using dnspy and break at the entry point (or create process) I get "Exception ???" and no more information.

I will try building with debug symbols to see if I can get any more information where and why it is crashing.

@rollsch
Copy link
Author

rollsch commented Jul 3, 2019

Also I realise these protections are easily removed but any extra step increases the time required to de-obfuscate a program.

@XenocodeRCE
Copy link
Owner

Hello

just read the code and compare it to original.

It adds extra debugger checks, hence why the "anti" for "antidebug".

It's old code from 15 Jul 2018 however, and the project is meant to be modified, not used as it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants