| Option | Arguments | Description |
| --Transform |
AntiBranchAnalysis |
Replace branches with other constructs. |
| --AntiBranchAnalysisKinds |
branchFuns, goto2call, goto2push, goto2push2, goto2nopSled, * |
Comma-separated list of the kinds of constructs branches can be replaced with. Default=branchFuns.
- branchFuns = Generate calls to branch functions. --Transform=InitBranchFuns must be given prior to this transform
- goto2call = Replace goto L with push L; call lab; ret; lab: ret
- goto2push = Replace goto L with push L; ret
- goto2push2 = Replace goto L with push L; leal; jmp
- goto2nopSled = Replace goto L with goto *p where p is the address of a sequence of nop:s that eventually lead to L
- * = Same as branchFuns,goto2call,goto2push
|
| --AntiBranchAnalysisOpaqueStructs |
|
Deprecated spelling of --AntiBranchAnalysisOpaqueInvariantKinds Kept for compatibility. Replace --AntiBranchAnalysisOpaqueStructs=list,array with --AntiBranchAnalysisOpaqueInvariantKinds=structure_state. Replace --AntiBranchAnalysisOpaqueStructs=env with --AntiBranchAnalysisOpaqueInvariantKinds=environment. The input kind was removed in 4.1. Default=The kinds specified at InitOpaque.. |
| --AntiBranchAnalysisObfuscateBranchFunCall |
BOOLSPEC |
Obfuscate the body of the branch function. Default=false. |
| --AntiBranchAnalysisBranchFunFlatten |
BOOLSPEC |
Flatten before replacing jumps. This opens up more opportunities for replacing unconditional branches. From version 4.0.12 this is obsolete. Use --AntiBranchAnalysisFlatten instead. Default=false. |
| --AntiBranchAnalysisFlatten |
BOOLSPEC |
Flatten before replacing jumps. This opens up more opportunities for replacing unconditional branches. Default=false. |
| --AntiBranchAnalysisBranchFunAddressOffset |
integer |
The offset (in bytes) of the return address on the stack, for branch functions. May differ based on operating system, word size, and compiler. Default=8 on x86_64, 0 on Arm. |
| --AntiBranchAnalysisFraction |
FRACSPEC |
How many unconditional branches should be encoded. Default=%100. |
| --AntiBranchAnalysisOpaqueInvariantKinds |
identity, modular, mba, structure_state, scalar_state, environment, plugin, * |
Comma-separated list of the kinds of opaque invariant the NOP sled may draw from, named by the hardness family they rest on. Constrained to the kinds set up by --InitOpaqueInvariantKinds. From version 4.1 Default=The kinds specified at InitOpaque..
- identity = Universally-true arithmetic identities.
- modular = Residue and modular-arithmetic facts.
- mba = Mixed boolean-arithmetic.
- structure_state = A data structure that maintains an invariant as the program runs and is then queried structurally. Replaces pre-4.1 list and array.
- scalar_state = Evolving scalar state.
- environment = Opaque expressions from entropy. Requires --InitEntropy. Replaces env.
- plugin = Invariants supplied by a user plugin.
- * = Same as identity,modular,mba,structure_state,scalar_state,environment,plugin
|
| --AntiBranchAnalysisOpaqueInvariantResilience |
trivial, local, global, interprocedural, inter_process, * |
Comma-separated list of the resilience levels the NOP sled may draw from -- the scope of analysis an attacker must run to decide the invariant. Constrained to the levels set up by --InitOpaqueInvariantResilience. From version 4.1 Default=The levels specified at InitOpaque..
- trivial = One expression decides it, AND a stock compiler at -O2 folds it to a constant.
- local = One expression decides it, but -O2 does not fold it.
- global = Deciding it needs analysis of the whole procedure.
- interprocedural = Deciding it needs whole-program analysis.
- inter_process = Deciding it needs reasoning about concurrent interleavings. Reserved -- no invariant is at this level yet.
- * = Every level, trivial included.
|
| --AntiBranchAnalysisOpaqueMaxSize |
INTSPEC |
The largest number of sub-opaques one opaque may be composed of. See --AddOpaqueMaxSize. From version 4.1 Default=The value set by --InitOpaqueMaxSize.. |
| --AntiBranchAnalysisOpaqueSelect |
|
(Deity mode only.) Comma-separated list of exact invariant names to draw from, bypassing the kind and resilience selection entirely. Names come from --InitOpaqueList. Silently inert unless the deity key is supplied with --DeityMode. The named invariants must have been set up by InitOpaque, so pair this with a permissive --InitOpaqueInvariantKinds/--InitOpaqueInvariantResilience. From version 4.1 Default=none. |