Skip to main content
Version: v3.x

Eval Stack Obfuscation

warning

Starting from v3.0.0, the eval stack obfuscation pass is disabled. Enabling EvalStackObfus in ObfuscationPasses has no effect. The reason is that this pass has a poor cost-benefit ratio. If it cannot be optimized in the future, the feature may be removed.

Randomly obfuscate the execution stack during virtual machine runtime to increase reverse engineering difficulty.

Implementation Principle​

Check all IL instructions that perform push operations on the execution stack. If the pushed data is of int, long, float, or double types, randomly insert obfuscation code. The inserted obfuscation code has similarities with Expression Obfuscation.

Settings​

ObfuzSettings.EvalStackObfusSettings contains constant encryption related settings, detailed documentation can be found in Configuration.

Rule Files​

By default, Obfuz encrypts all function calls, but also supports rule files to finely control the scope and effects of constant encryption. The EvalStackObfusSettings.RuleFiles option can configure 0-N rule files. Rule file relative paths are from the project directory, valid rule file paths look like: Assets/XXX/YYY.xml.

Configuration example:

<?xml version="1.0" encoding="UTF-8"?>

<obfuz>

<global obfuscationLevel="Basic" obfuscationPercentage="0.05">

</global>

<assembly name="Obfus2">
<type name="*.TestNotObfusAnyMethods" obfuscationLevel="None"/>
<type name="*.TestObfusAll" obfuscationLevel="Advanced"/>
<type name="*.TestObfusSomeMethods" >
<method name="Foo" obfuscationLevel="MostAdvanced"/>
</type>
</assembly>
</obfuz>
  • Top-level tag must be obfuz
  • Second-level tags can be global and assembly

global​

Global defines global default encryption parameters.

AttributeNullableDefaultDescription
obfuscationLevelYesNoneObfuscation level, can take values None, Basic, Advanced, MostAdvanced
obfuscationPercentageYes0.05Obfuscation probability. Value range [0 - 1]. Since Eval Stack Obfuscation will dramatically increase final dll size, it's recommended that this parameter value should not exceed 0.1

assembly​

AttributeNullableDefaultDescription
nameNoAssembly name, must be in the obfuscated assembly list
OthersYesInherit same-named options from globalAll options in global can be used, if not defined, inherit the value of same-named option in global

Assembly's child elements can only be type.

type​

AttributeNullableDefaultDescription
nameNoType name wildcard string, if empty means match all types
OthersYesInherit same-named options from assemblyAll options in global can be used, if not defined, inherit the value of same-named option in assembly

Since function calls can only appear in function code, type's child elements can only be method.

method​

AttributeNullableDefaultDescription
nameNoType name wildcard string, if empty means match all types
OthersYesInherit same-named options from assemblyAll options in global can be used, if not defined, inherit the value of same-named option in assembly