About this project

obfus.h is a macro-only library for compile-time obfuscating C applications, designed specifically for the Tiny C Compiler (tcc) on Windows x86 and x64. It is distributed as a single header that you include in your source; obfuscation is applied automatically during compilation. The author notes it supports almost all versions of tcc, recommends tcc 0.9.27, and states that Visual C, GCC and Clang are not supported. Documented features: - Function call obfuscation to make calls less readable. - Anti-debugging mechanisms intended to hinder runtime analysis; protection is triggered by calls to many basic MSVCRT functions, and an ANTI_DEBUG; construct can be placed at critical points. - Control-flow code mutation that restructures conditions and loops; a CFLOW_V2 option provides a stronger (and slower) variant. - String hiding via HIDE_STRING(str), which assembles strings on the stack through mov instructions at runtime rather than declaring them statically. The README cautions that some decompilers may still reveal them due to static optimizations. - Anti-decompilation techniques intended to visually break decompiler output. - Fake signatures of various packers and protectors to confuse reverse engineers. - A math virtual machine (enabled with VIRT) exposing VM_ADD, VM_SUB, VM_MUL, VM_DIV, VM_MOD, comparison macros such as VM_EQU/VM_NEQ/VM_LSS/VM_GTR/VM_LEQ/VM_GEQ, double variants, and VM_IF/VM_ELSE_IF/VM_ELSE logical constructs. The README warns that virtualization can impact optimization and should be used only where needed, and that some double comparison operations are unsupported. Configuration is done through defines such as VIRT, CFLOW_V2, ANTIDEBUG_V2, FAKE_SIGNS, and disabling flags NO_OBF, NO_CFLOW, NO_ANTIDEBUG, or via compiler arguments (for example tcc app.c -w -D NO_CFLOW -D ANTIDEBUG_V2 -D FAKE_SIGNS -D VIRT). The README advises compiling with -w to suppress the many warnings produced during obfuscation. Usage is a single #include "obfus.h" line. A Windows batch script (include-updater/obfh-update.cmd) can fetch the latest header from the repository without git, useful for automated security updates before builds. The README links community security analyses, including a black-box analysis of the protection mechanisms (whose findings the author says have been patched), a CTF write-up using an earlier generation, and ObfusHunter, a utility for scanning files protected by obfus.h. The author states that protected program logic is nearly impossible to recover, but stresses that obfuscation alone does not guarantee complete protection and that internal security systems should still be developed and maintained.