Skip to content

feature: randomize anti-tamper key-derivation rotation shifts (#69) - #108

Merged
mcpolo99 merged 1 commit into
developfrom
69-antitamper-rotation-shifts
Sep 21, 2026
Merged

mcpolo99 merged 1 commit into
developfrom
69-antitamper-rotation-shifts

Conversation

@mcpolo99

Copy link
Copy Markdown
Owner

Level 2 constant randomization — Anti-tamper rotation shifts (#69)

Removes the fixed 5/3/7/11 rotation amounts from the anti-tamper key-derivation mixer. The mixer rotates its four state registers over 16 iterations to expand the key, identically on the obfuscator (*Mode.DeriveKey) and the injected runtime (AntiTamper*.Initialize), in all three modes (Normal, Anti, JIT). The fixed shifts let de4dot/AV pattern-match the stub.

Change

  • Four rotation amounts chosen distinct per module and injected into the runtime via Mutation.KeyI6..KeyI9 (slots 6–9 were free; modes use 0–5).
  • Runtime forms each rotation as (r >> amount) | (r << (32 - amount)); obfuscator DeriveKey uses the same amounts, so the round-trip holds.
  • Shared RotationKey.PickShifts helper picks the four amounts.

No curated set needed (unlike xorshift/primes)

A bit rotation is a bijection for any amount in 1..31 — there's no full-period/primality validity constraint like the xorshift (#107) or compressor primes (#106). So the amounts are simply picked distinct and non-trivial at obfuscation time; no baked table or generator script is required. ~4 distinct amounts from 1..31 → several bits of per-module identity.

Validation

  • Builds clean (Runtime + Protections).
  • AntiTamper.Test: normal + anti pass (obfuscate → run → the self-check decrypts its section with the randomized rotations and the app runs).
  • jit stays skipped — it is a pre-existing known-broken/untested mode (Skip = "Runtime Component of the JIT AntiTamper protection is broken."). The JIT change mirrors the two validated modes and is compile-checked only.

Remaining on #69 (follow-ups)

  • JIT-specific fingerprints: HookHandler counter rotation (>>5|<<27) and feedback 0x3dbb2819 — grouped with the JIT-hook hard-fingerprint concerns.
  • Level 1 tool-identity script (planned as .sh).

Part of #69. Related: #106 (compressor moduli), #107 (constants xorshift).

The anti-tamper key-derivation mixer rotates its four state registers by
the fixed amounts 5/3/7/11 on both the obfuscator (mode DeriveKey) and
the injected runtime (Initialize), across all three modes (Normal, Anti,
JIT). de4dot/AV pattern-match these fixed shifts.

The four amounts are now chosen distinct per module and injected into the
runtime via mutation keys (KeyI6..KeyI9); the runtime forms each rotation
as (r >> amount) | (r << (32 - amount)). Both sides share the amounts, so
the round-trip holds.

Unlike the xorshift/prime constants, a bit rotation is a bijection for any
amount in 1..31, so no curated set is required -- the shared RotationKey
helper just picks four distinct non-trivial amounts.

Validated by AntiTamper.Test (normal + anti pass; jit stays skipped as it
is a pre-existing known-broken/untested mode -- its change mirrors the two
validated modes and is compile-checked only).
@mcpolo99
mcpolo99 merged commit a6a113f into develop Sep 21, 2026
3 checks passed
@mcpolo99
mcpolo99 deleted the 69-antitamper-rotation-shifts branch September 29, 2026 19:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant