Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
sogen — 🪅 Windows & Linux userspace emulator | Kitploit
工具/GitHubGitHub/momo5502/sogen
Dynamic Analysis (Sandboxing)Reverse EngineeringDebuggersSecurity VirtualizationMalware AnalysisBinary Analysis
GitHubmomo5502/sogen

sogen

🪅 Windows & Linux userspace emulator

查看仓库
3.5k2261天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站
内容在请求的语言中不可用。显示英文版本。


inspect.software score badge for momo5502/sogen

Sogen runs Windows and Linux programs without a real operating system, and lets you see and control everything they do.

Instead of reimplementing thousands of OS APIs, Sogen emulates binaries at CPU and syscall level and runs the real system DLLs, so behavior closely matches the real OS.

Every instruction, memory access and API call can be hooked, inspected or rewritten, runs are fully deterministic, and the entire emulator state can be snapshotted and restored.

Built in C++ and powered by the CPU backend of your choice:

  • Unicorn Engine
  • icicle-emu
  • Hyper-V (WHP)
  • KVM
  • FEX

Try it out: sogen.dev
 

Key Features

  • Real system DLLs: runs the actual ntdll, kernel32 and user32, not reimplemented stubs
  • Hook & rewrite: intercept and change memory, instructions, syscalls and API calls
  • Faithful Windows internals: PE loading (relocations, TLS), Windows memory types, SEH, threading, the registry, filesystem and networking
  • Snapshot & restore: full state serialization, fast in-memory snapshots and minidump loading
  • Runs everywhere: Windows, Linux, macOS, Android, iOS and the browser, on x86-64 and arm64
  • Deterministic: every run is reproducible, down to the instruction
     

Preview

Preview

Undetectable Debugging

Debug with the tools you already know, like IDA Pro or GDB, over the GDB protocol, or use the built-in in-browser debugger.
The debugger runs at the emulator level, outside the process, so it stays invisible to anti-debug checks.

Debugging a process running in Sogen from an IDA Pro remote GDB session  

Run Games in a Sandbox

Native GUI apps run, with working windows, dialogs and controls.
GPU paravirtualization enables 3D acceleration on your real GPU, while the Hyper-V backend runs the code natively on your CPU. Fast enough for games.
Direct3D 8/9/10/11 titles run through DXVK, which translates Direct3D to Vulkan on top of the GPU bridge.

A game running inside the Sogen emulator  

Project Overview

YouTube Video

Click here for the slides.
 

Python Bindings

Install with:

root@kitploit:~
pip install sogen

Python bindings require an emulation root. You can download a ready-made root here, or create your own by following the instructions in the wiki.

Example:

root@kitploit:~
import sogen

emu = sogen.windows.create_application("c:/test-sample.exe", emulation_root="./root")


def on_module_load(module):
    if module.name.lower() == "test-sample.exe":
        emu.hooks.memory_execution_at(module.entry_point, lambda address: print(f"hit entry point: 0x{address:x}"))

emu.callbacks.on_module_load = on_module_load
emu.start()
print(emu.process.exit_status)

See examples/python/README.md for setup details and a larger example.
 

Unofficial Bindings

Dart bindings are available in a separate repository.
 

Quick Start (Windows + Visual Studio)

[!TIP]
Checkout the Wiki for more details on how to build & run the emulator on Windows, Linux, macOS, ...

1. Checkout the code:

root@kitploit:~
git clone --recurse-submodules https://github.com/momo5502/sogen.git

2. Run the following command in an x64 Development Command Prompt in the cloned directory:

root@kitploit:~
cmake --preset=vs2022

3. Build the solution that was generated at build/vs2022/sogen.sln

4. Create a registry dump by running the grab-registry.bat as administrator and place it in the artifacts folder next to the analyzer.exe

5. Run the program of your choice:

root@kitploit:~
analyzer.exe C:\example.exe
下载工具