Implement a working binary-to-binary obfuscation pipeline for Windows PE executables. The pipeline will lift binaries to LLVM IR, apply obfuscation passes, and recompile to an obfuscated PE binary.
Currently oaas only supports source-to-binary obfuscation. Many real-world scenarios require obfuscating existing binaries where source code is unavailable:
- Legacy software protection
- Third-party library hardening
- Security research and CTF challenges
- Protecting pre-compiled dependencies
The pipeline architecture is documented in docs/PIPELINES.md (Section 2: Windows Binary Lifting Pipeline). The planned stages are:
-
Stage 1 - Safe Windows Build (
binary_obfuscation_pipeline/windows_build/)- Validate binary for unsupported constructs
- Reference: MinGW-w64 toolchain with
-O0 -g -fno-inline -fno-exceptions
-
Stage 2 - Ghidra CFG Export (
binary_obfuscation_pipeline/mcsema_impl/ghidra_lifter/)- Headless Ghidra script to export McSema-compatible CFG JSON
- Reference: Ghidra Headless Analyzer docs
-
Stage 3 - Binary Lifting (
binary_obfuscation_pipeline/mcsema_impl/lifter/)- Lift CFG to LLVM IR using McSema or alternative (RetDec, rev.ng)
- Upgrade bitcode to LLVM 22 dialect for compatibility with existing passes
-
Stage 4 - OLLVM Pass Application (
binary_obfuscation_pipeline/mcsema_impl/ollvm_stage/)- Apply safe subset of passes:
substitution,linear_mba, limitedflattening - Integrate with existing pass infrastructure in
cmd/llvm-obfuscator/plugins/
- Apply safe subset of passes:
-
Stage 5 - Recompilation
- Compile obfuscated LLVM IR back to PE binary
- Integrate with existing CLI via new
--input-binaryflag
- Implement end-to-end pipeline for simple C binaries (no exceptions, no complex C++)
- Dockerized environment for reproducible builds
- CLI integration with existing
obfuscatecommand - Test suite with sample PE binaries
- Documentation on limitations and supported constructs
| Deliverable | Description |
|---|---|
| Working pipeline | PE binary in, obfuscated PE binary out |
| Ghidra scripts | Headless CFG extraction for PE files |
| Lifting stage | McSema/RetDec integration with LLVM 22 |
| CLI integration | --input-binary flag for binary input |
| Test suite | Sample binaries with validation |
| Documentation | Usage guide and known limitations |
| Attribute | Value |
|---|---|
| Skill level | Intermediate |
| Languages | Python, C++, Bash |
| Size | Medium (~175 hours) |
| Prerequisites | Familiarity with PE format, basic reverse engineering, LLVM IR concepts |
| Mentors | TBD |
- McSema - Binary lifter (LLVM 10-17)
- RetDec - Retargetable decompiler with LLVM backend
- rev.ng - Modern binary analysis platform
- Ghidra - NSA's reverse engineering framework
- LIEF - Library for PE/ELF parsing and modification
- Read
docs/PIPELINES.mdanddocs/ARCHITECTURE.md - Set up the development environment per
CONTRIBUTING.md - Experiment with Ghidra headless analysis on a simple PE binary
- Try lifting a minimal binary with McSema or RetDec
- Open an issue to discuss your approach before starting implementation