Nothing is beyond our reach

Aftermath Labs

We build advanced binary tooling, deobfuscate complex software, and help security teams understand and protect the systems that matter.

  • Binary analysis
  • Custom tooling
  • Software protection
Aftermath Labs octopus and computer mark

Products & services

Research translated into working systems.

Our internal compiler technology powers focused products, custom tooling, and hands-on engagements.

Binary control-flow graph visualization

Software protection

CodeDefender

CodeDefender protects native software against tampering, exploitation, and reverse engineering without treating compatibility, performance, or debugging as afterthoughts.

  • Safe function-level transformations that preserve program behavior.
  • Exception-safe rewrites and comprehensive debug information for protected binaries.
  • Support for modern Windows defenses including ACG, CFG, CET, and HVCI.
Explore CodeDefender
SigBreaker product artwork

Binary diversification

SigBreaker

SigBreaker diversifies executable code so traditional static signatures fail while preserving semantics, near-original performance, compatibility, and debuggability.

  • Production-scale binary rewriting with no source code or annotations required.
  • Full PDB, structured exception handling, and exception-safe rewrite support.
  • Compatible with modern Windows binary-hardening features.
Explore SigBreaker
BLARE2 binary analysis graph

Core technology

BLARE2

BLARE2 is our in-house binary manipulation platform: a custom disassembler, SSA intermediate representation, optimization pipeline, compiler backend, and linker.

  • Custom IR for deep code analysis and transformation.
  • High-performance compiler backend for AMD64 and ARM64.
  • Advanced linking, instrumentation, recompilation, and deobfuscation workflows.
Discuss a BLARE2 project
Reverse engineering symbol analysis interface

Consulting

Reverse Engineering Services

From protected applications to high-value game cheats, we investigate complex software and turn opaque behavior into evidence your team can act on.

  • In-depth binary analysis of obfuscation, anti-debugging, injection, and evasion techniques.
  • Custom disassembly and deobfuscation tooling powered by BLARE2.
  • Clear technical reports, countermeasure guidance, and reproducible findings.
View a case study

Latest research

We publish the work.

Technical deep dives into devirtualization, software protection, kernel security, and the systems we build along the way.

View all research
Windows

Static Devirtualization of Tencent VM

Over the course of several months we have noticed an increased interest in Tencent VM obfuscation. We have had complete static devirtualization of this VM obfuscation for quite some time now and have noticed others have achieved similar deobfuscation results.

Read article
Windows

Static Devirtualization of Themida

This article demonstrates devirtualization of CodeVirtualizer/Themida protected code, however the techniques described here apply to pretty much every virtual machine based obfuscator. Only requiring some minor modifications to support each of them.

Read article
Windows

Deobfuscation and Analysis of Ring-1.io

As part of this research, we partially deobfuscated multiple Themida-protected binaries used by ring-1.io, including its UEFI bootloader implant. Several critical functions were recovered to enable static analysis of the implant’s behavior. This work provides visibility into mechanisms that are intentionally designed to resist inspection, including virtualization-assisted hooks, execution redirection, and kernel manipulation techniques.

Read article

Have a difficult binary?

Bring us the problem without an obvious answer.

Whether you need a difficult target understood, custom binary tooling built, or software protection reviewed, we can help define the shortest path forward.