TukeWIN
Request a call

Tiger: bin2bin obfuscator. Compiled binaries in, harder-to-read binaries out.

Feed Tiger a compiled binary; get back one that's functionally identical and dramatically harder to read. No source access. No SDK to integrate. One extra step in your build pipeline.

What Tiger is

Tiger is a standalone tool that takes a compiled binary and produces a functionally identical binary that's much harder to analyze. No source required, no SDK to link. Point it at the output of your build pipeline and it runs.

Under the hood it applies a stack of well-known-but-composed transforms: control-flow flattening, opaque predicates, string and constant encryption, junk insertion, and instruction-level substitution. The composition and the tuning are what make it useful.

Tiger is what we ship when you don't want a DRM relationship. Just a raw obfuscation layer on top of whatever you already build.

How you use it

It's a CLI. Your build pipeline runs the linker, then runs Tiger on the output. Nothing else in your source or build scripts needs to change.

You choose the aggressiveness. A conservative profile costs almost nothing at run time and still buys weeks of extra work for a reverser. A heavy profile trades a small performance overhead for a much larger analysis cost.

Sensible defaults, with per-binary or per-function config for the edge cases. Symbols and hot paths you want left alone stay alone.

What Tiger does and doesn't do

Tiger is obfuscation, not DRM. It slows down static and dynamic analysis of your binary. It does not check licenses, phone home, or bind the binary to a machine. If that's what you need, DRM is our other product for exactly that.

It won't stop a lab with unlimited time. It will make a casual reverse-engineer spend days on what would have been minutes, and it will invalidate most published tooling on your specific binary.

You keep the source. Tiger only ever sees the compiled artifact and it doesn't send anything anywhere. It runs on your build machine.

UNDER THE HOOD

One function in.A private machine out.

Tiger lifts selected functions out of native code, rewrites them into a custom bytecode, and pairs that bytecode with a virtual machine that exists nowhere else. Every build ships a different instruction set.

NATIVE CODE

A compiled function in your binary, marked for protection.

IR / ANALYSIS

Lifted into an internal representation and rewritten via semantic identities.

CUSTOM BYTECODE + PRIVATE VM

Emitted as opcodes for a virtual machine generated for this build only.

PROTECTED BINARY

Reinserted in place; behavior identical, static shape unrecognizable.

NATIVE X86-64 (BEFORE)
mov eax, [rdi]
add eax, ebx
xor eax, 0x2a
ret
TIGER VM BYTECODE (AFTER)
vm_load r0, [ctx+0x28]
vm_super r0, r1, {ADD, XOR, POST_INC}
vm_bailout r0, 0x77b3
vm_dispatch @next

Every build emits different opcodes and a different dispatch table.

Semantic obfuscation via MBA identities

Arithmetic is replaced with mixed boolean-arithmetic equivalents that SMT solvers can't cheaply cancel. Pattern databases match the shape, not the meaning.

Per-build handler diversification

Opcode numbering, dispatch layout, and handler shapes are re-seeded on every build. Tooling calibrated against last week's release does not carry over.

Merged superhandlers

Related operations collapse into single dispatches that touch multiple state fields at once. Handler-by-handler analysis returns overlapping, ambiguous behavior.

No shared runtime

Nothing is linked from a shared library. Each protected binary carries its own private VM, so there is no baseline dispatch table to lift and reuse.

Anti-analysis primitives baked in

Debugger detection, timing checks, VM-in-VM detection, and integrity probes are woven into the bytecode itself rather than bolted on as a runtime layer.

Selective per-function protection

You choose which functions enter the VM. Hot paths stay native at full speed; the handful of functions worth protecting pay the cost.

100+handler variants per build
min→wkseconds of build time, weeks of analysis

Compiles to a machine that only exists in your binary.