Sirocco-Obfuscator 2.0.0

dotnet tool install --global Sirocco-Obfuscator --version 2.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local Sirocco-Obfuscator --version 2.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=Sirocco-Obfuscator&version=2.0.0
                    
nuke :add-package Sirocco-Obfuscator --version 2.0.0
                    

Sirocco-Obfuscator

Version: 2.0 (2026.08)


Program Overview

Sirocco-Obfuscator is a .NET assembly obfuscator that supports renaming, string encryption, control flow obfuscation, anti-debugging, anti-VM, memory protection, packing, resource encryption, reference proxy, and tamper protection. It effectively enhances the reverse-engineering resistance of .NET applications.


System Requirements

  • Windows 10 / 11 (includes .NET Framework 4.8, compatible with 4.7.2)
  • No additional .NET runtime installation required on Windows 10/11 (pre-installed by the OS)
  • Supports obfuscating .NET Framework / .NET Core / .NET 5+ assemblies (.exe / .dll)
  • Packing (--pack) requires Visual C++ Redistributable for Visual Studio 2015-2022 (usually pre-installed on Windows 10/11)

Usage

The program supports two operation modes:

1. Interactive Mode (for beginners)

Double-click Sirocco.exe and follow the prompts to select each feature.

2. Command-Line Mode (for batch or automated processing)

Run in Command Prompt:

Sirocco.exe <input_file_path> [options]
Note: The input file path must be placed first! Options can follow in any order.

Common Parameters
Parameter	Description
--rename	Enable basic renaming (private fields/methods/nested types)
--rename-types	Rename class names (requires --rename)
--rename-namespaces	Rename namespaces (requires --rename, may affect reflection)
--public	Obfuscate public/protected members (requires --rename, use with caution)
--strings	Use XOR encryption (lightweight)
--stringsAES	Use AES-256 encryption (more secure, recommended)
--res-enc	Encrypt embedded resource files (e.g., images, config files)
--controlflow	Enable control flow obfuscation (increases reverse-engineering difficulty)
--ref-proxy	Enable reference proxy (experimental) �C hides direct call relationships
--antidebug	Inject anti-debugging protection (exits when debugger detected)
--antivm	Inject anti-VM detection (exits when conditions are met)
--antitamper	Inject anti-tamper protection (detects IL modification). Conflicts with --pack.
--memory-erasure	Clear temporary byte arrays after AES decryption (prevents plaintext residue)
--anti-dump	Anti-memory dumping (may affect debugging)
--pack	Pack the obfuscated output (requires Stub.exe; primarily for DLLs, also compatible with EXEs). 64-bit only.
--outdir <directory>	Specify output directory (file name automatically gets _obf suffix)
--help	Display help information
Examples
1. Basic renaming only:

Sirocco.exe MyApp.exe --rename
2. Full protection (recommended for v2.0):

Sirocco.exe MyApp.exe --rename --stringsAES --res-enc --ref-proxy --controlflow --antidebug --pack
3. Tamper protection (without packing):

Sirocco.exe MyApp.exe --rename --stringsAES --antitamper
4. Specify output directory:

Sirocco.exe MyApp.exe --outdir C:\Output
5. View help:

Sirocco.exe --help
Output Files
Obfuscated file is generated in the same directory as the original, named: original_name_obf.extension

If --pack is used, an additional file is generated: original_name_obf_packed.exe (packed executable)

If packing succeeds, the original obfuscated file (_obf.dll) is automatically deleted

Strong name signatures are automatically removed from obfuscated assemblies. Re-sign with your own key if needed.

Important Notes
If the input file path contains spaces, enclose it in double quotes, e.g.: "My App.exe"

--public breaks external API compatibility; only use for final executables or DLLs with no external callers.

Namespace renaming (--rename-namespaces) may affect reflection and serialization; use with caution.

--antitamper cannot be used with --pack. The tool will explicitly reject this combination.

--antitamper only works for EXEs with an entry point method; it will be skipped for DLLs.

--ref-proxy is an experimental feature; it may affect performance. Test before production use.

--res-enc slightly increases startup time; resources are decrypted only on first access.

Packing (--pack) is for 64-bit applications only, and requires Stub.exe in the same directory or in system PATH.

Anti-memory dumping (--anti-dump) may conflict with some debugging tools; disable if issues arise.

Obfuscated programs may be flagged by antivirus software as false positives (packing or control flow obfuscation can alter behavioral patterns).```

# FAQ
Q: What if the obfuscated program doesn't run?

A: First try without --public and --anti-dump, then gradually add options to isolate the issue. You can also enable options one by one in interactive mode.

Q: What files are needed for packing?

A: Stub.exe (an executable loader template) is required. Place it in the same directory as Sirocco.exe.

Q: Does it support obfuscating .NET Core / .NET 5+ assemblies?

A: Yes. However, packing may require adjustments; it's recommended to test obfuscation without packing first.

Q: What's the difference between --strings and --stringsAES?

A: --strings uses XOR with a fixed key (lightweight). --stringsAES uses AES-256 with per-string dynamic keys (more secure).

Q: Can I use --antitamper and --pack together?

A: No. They are mutually exclusive. The tool will exit with an error if both are specified.

# Feedback
If you encounter any bugs or issues, please report them at:

**https://github.com/Ricespoon-y/SiroccoNET**

# Acknowledgments

Sirocco-Obfuscator would not exist without the following open-source projects:

- **[dnlib](https://github.com/0xd4d/dnlib)** �C Licensed under the MIT License.  
  Used for reading, writing, and modifying .NET assemblies.

We are grateful to all contributors and maintainers of these projects!

**Thank you for using SiroccoNET Obfuscator!**
Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
2.0.0 135 9/5/2026