Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
sogen — 🪅 Windows & Linux userspace emulator | Kitploit
도구/GitHubGitHub/momo5502/sogen
Dynamic Analysis (Sandboxing)Reverse EngineeringDebuggersSecurity VirtualizationMalware AnalysisBinary Analysis
GitHubmomo5502/sogen

sogen

🪅 Windows & Linux userspace emulator

저장소 보기
3.5k2261일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.


inspect.software score badge for momo5502/sogen

Sogen runs Windows and Linux programs without a real operating system, and lets you see and control everything they do.

Instead of reimplementing thousands of OS APIs, Sogen emulates binaries at CPU and syscall level and runs the real system DLLs, so behavior closely matches the real OS.

Every instruction, memory access and API call can be hooked, inspected or rewritten, runs are fully deterministic, and the entire emulator state can be snapshotted and restored.

Built in C++ and powered by the CPU backend of your choice:

  • Unicorn Engine
  • icicle-emu
  • Hyper-V (WHP)
  • KVM
  • FEX

Try it out: sogen.dev
 

Key Features

  • Real system DLLs: runs the actual ntdll, kernel32 and user32, not reimplemented stubs
  • Hook & rewrite: intercept and change memory, instructions, syscalls and API calls
  • Faithful Windows internals: PE loading (relocations, TLS), Windows memory types, SEH, threading, the registry, filesystem and networking
  • Snapshot & restore: full state serialization, fast in-memory snapshots and minidump loading
  • Runs everywhere: Windows, Linux, macOS, Android, iOS and the browser, on x86-64 and arm64
  • Deterministic: every run is reproducible, down to the instruction
     

Preview

Preview

Undetectable Debugging

Debug with the tools you already know, like IDA Pro or GDB, over the GDB protocol, or use the built-in in-browser debugger.
The debugger runs at the emulator level, outside the process, so it stays invisible to anti-debug checks.

Debugging a process running in Sogen from an IDA Pro remote GDB session  

Run Games in a Sandbox

Native GUI apps run, with working windows, dialogs and controls.
GPU paravirtualization enables 3D acceleration on your real GPU, while the Hyper-V backend runs the code natively on your CPU. Fast enough for games.
Direct3D 8/9/10/11 titles run through DXVK, which translates Direct3D to Vulkan on top of the GPU bridge.

A game running inside the Sogen emulator  

Project Overview

YouTube Video

Click here for the slides.
 

Python Bindings

Install with:

root@kitploit:~
pip install sogen

Python bindings require an emulation root. You can download a ready-made root here, or create your own by following the instructions in the wiki.

Example:

root@kitploit:~
import sogen

emu = sogen.windows.create_application("c:/test-sample.exe", emulation_root="./root")


def on_module_load(module):
    if module.name.lower() == "test-sample.exe":
        emu.hooks.memory_execution_at(module.entry_point, lambda address: print(f"hit entry point: 0x{address:x}"))

emu.callbacks.on_module_load = on_module_load
emu.start()
print(emu.process.exit_status)

See examples/python/README.md for setup details and a larger example.
 

Unofficial Bindings

Dart bindings are available in a separate repository.
 

Quick Start (Windows + Visual Studio)

[!TIP]
Checkout the Wiki for more details on how to build & run the emulator on Windows, Linux, macOS, ...

1. Checkout the code:

root@kitploit:~
git clone --recurse-submodules https://github.com/momo5502/sogen.git

2. Run the following command in an x64 Development Command Prompt in the cloned directory:

root@kitploit:~
cmake --preset=vs2022

3. Build the solution that was generated at build/vs2022/sogen.sln

4. Create a registry dump by running the grab-registry.bat as administrator and place it in the artifacts folder next to the analyzer.exe

5. Run the program of your choice:

root@kitploit:~
analyzer.exe C:\example.exe
도구 다운로드