Sirocco-Obfuscator
2.0.0
dotnet tool install --global Sirocco-Obfuscator --version 2.0.0
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
dotnet tool install --local Sirocco-Obfuscator --version 2.0.0
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=Sirocco-Obfuscator&version=2.0.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
nuke :add-package Sirocco-Obfuscator --version 2.0.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Sirocco-Obfuscator
Version: 2.0 (2026.08)
Program Overview
Sirocco-Obfuscator is a .NET assembly obfuscator that supports renaming, string encryption, control flow obfuscation, anti-debugging, anti-VM, memory protection, packing, resource encryption, reference proxy, and tamper protection. It effectively enhances the reverse-engineering resistance of .NET applications.
System Requirements
- Windows 10 / 11 (includes .NET Framework 4.8, compatible with 4.7.2)
- No additional .NET runtime installation required on Windows 10/11 (pre-installed by the OS)
- Supports obfuscating .NET Framework / .NET Core / .NET 5+ assemblies (
.exe/.dll) - Packing (
--pack) requires Visual C++ Redistributable for Visual Studio 2015-2022 (usually pre-installed on Windows 10/11)
Usage
The program supports two operation modes:
1. Interactive Mode (for beginners)
Double-click Sirocco.exe and follow the prompts to select each feature.
2. Command-Line Mode (for batch or automated processing)
Run in Command Prompt:
Sirocco.exe <input_file_path> [options]
Note: The input file path must be placed first! Options can follow in any order.
Common Parameters
Parameter Description
--rename Enable basic renaming (private fields/methods/nested types)
--rename-types Rename class names (requires --rename)
--rename-namespaces Rename namespaces (requires --rename, may affect reflection)
--public Obfuscate public/protected members (requires --rename, use with caution)
--strings Use XOR encryption (lightweight)
--stringsAES Use AES-256 encryption (more secure, recommended)
--res-enc Encrypt embedded resource files (e.g., images, config files)
--controlflow Enable control flow obfuscation (increases reverse-engineering difficulty)
--ref-proxy Enable reference proxy (experimental) �C hides direct call relationships
--antidebug Inject anti-debugging protection (exits when debugger detected)
--antivm Inject anti-VM detection (exits when conditions are met)
--antitamper Inject anti-tamper protection (detects IL modification). Conflicts with --pack.
--memory-erasure Clear temporary byte arrays after AES decryption (prevents plaintext residue)
--anti-dump Anti-memory dumping (may affect debugging)
--pack Pack the obfuscated output (requires Stub.exe; primarily for DLLs, also compatible with EXEs). 64-bit only.
--outdir <directory> Specify output directory (file name automatically gets _obf suffix)
--help Display help information
Examples
1. Basic renaming only:
Sirocco.exe MyApp.exe --rename
2. Full protection (recommended for v2.0):
Sirocco.exe MyApp.exe --rename --stringsAES --res-enc --ref-proxy --controlflow --antidebug --pack
3. Tamper protection (without packing):
Sirocco.exe MyApp.exe --rename --stringsAES --antitamper
4. Specify output directory:
Sirocco.exe MyApp.exe --outdir C:\Output
5. View help:
Sirocco.exe --help
Output Files
Obfuscated file is generated in the same directory as the original, named: original_name_obf.extension
If --pack is used, an additional file is generated: original_name_obf_packed.exe (packed executable)
If packing succeeds, the original obfuscated file (_obf.dll) is automatically deleted
Strong name signatures are automatically removed from obfuscated assemblies. Re-sign with your own key if needed.
Important Notes
If the input file path contains spaces, enclose it in double quotes, e.g.: "My App.exe"
--public breaks external API compatibility; only use for final executables or DLLs with no external callers.
Namespace renaming (--rename-namespaces) may affect reflection and serialization; use with caution.
--antitamper cannot be used with --pack. The tool will explicitly reject this combination.
--antitamper only works for EXEs with an entry point method; it will be skipped for DLLs.
--ref-proxy is an experimental feature; it may affect performance. Test before production use.
--res-enc slightly increases startup time; resources are decrypted only on first access.
Packing (--pack) is for 64-bit applications only, and requires Stub.exe in the same directory or in system PATH.
Anti-memory dumping (--anti-dump) may conflict with some debugging tools; disable if issues arise.
Obfuscated programs may be flagged by antivirus software as false positives (packing or control flow obfuscation can alter behavioral patterns).```
# FAQ
Q: What if the obfuscated program doesn't run?
A: First try without --public and --anti-dump, then gradually add options to isolate the issue. You can also enable options one by one in interactive mode.
Q: What files are needed for packing?
A: Stub.exe (an executable loader template) is required. Place it in the same directory as Sirocco.exe.
Q: Does it support obfuscating .NET Core / .NET 5+ assemblies?
A: Yes. However, packing may require adjustments; it's recommended to test obfuscation without packing first.
Q: What's the difference between --strings and --stringsAES?
A: --strings uses XOR with a fixed key (lightweight). --stringsAES uses AES-256 with per-string dynamic keys (more secure).
Q: Can I use --antitamper and --pack together?
A: No. They are mutually exclusive. The tool will exit with an error if both are specified.
# Feedback
If you encounter any bugs or issues, please report them at:
**https://github.com/Ricespoon-y/SiroccoNET**
# Acknowledgments
Sirocco-Obfuscator would not exist without the following open-source projects:
- **[dnlib](https://github.com/0xd4d/dnlib)** �C Licensed under the MIT License.
Used for reading, writing, and modifying .NET assemblies.
We are grateful to all contributors and maintainers of these projects!
**Thank you for using SiroccoNET Obfuscator!**
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 2.0.0 | 135 | 9/5/2026 |