Babel Obfuscator
Babel Obfuscator protects .NET assemblies against reverse engineering, from .NET Framework 2.0 to .NET 10, on desktop, mobile, web and server targets. It renames, encrypts and restructures compiled code so that what a decompiler recovers is no longer worth reading.
Why Obfuscate .NET Code
Software written in .NET languages such as C#, VB.NET and F# compiles to MSIL (Microsoft Intermediate Language), a CPU-independent instruction set stored in the assembly alongside rich metadata: type names, member signatures, string literals and attributes. Together they let freely available decompilers rebuild source code that is close to the original, in seconds and without any special skill.
Obfuscation transforms the compiled assembly so that this reconstruction stops being useful. Babel Obfuscator renames symbols, encrypts strings, constants and resources, rewrites the control flow of methods, and can encrypt whole method bodies for execution inside a managed virtual machine. The application behaves exactly as before; the code an attacker recovers no longer does.
What’s New in 12.0
Version 12.0 hardens Babel against automated deobfuscation, extends tampering detection to mobile, and opens the product to AI assistants.
New cross-platform app for Windows, macOS and Linux that edits and runs obfuscation projects, decodes stack traces, manages Babel Licensing and hosts an MCP server.
A control flow flattening algorithm engineered to resist automated deobfuscators. Verifiable IL, NativeAOT and MAUI compatible, within a few percent of ordinary flattening at run time.
Authenticated, lazy per-string encryption with a fully managed decryptor: safe under trimming, NativeAOT and FIPS, verified on Android and iOS.
Tampering detection for .NET MAUI on Android: the app checks the APK signing certificate against signer fingerprints pinned at obfuscation time, so a repackaged app is rejected, even when trimmed or AOT-compiled.
Tampering detection for .NET MAUI on iOS: the app verifies its bundle identifier and Apple Team identifier against pinned values, under full AOT.
Decoded stack traces now name the method behind every Dynamic Proxy bridge, and can hide the Babel-generated frames entirely.
The releases leading up to 12.0 brought more: version 11.8 added a managed AES decryptor so protected assemblies start on FIPS-mode hosts, much faster obfuscation of very large assemblies, and the Hardware Dongle Binding sample; version 11.7 introduced the AI-friendly command line.
The Ultimate Badge
Some headings in this manual carry this marker: Ultimate. It means the feature is available from the Babel Obfuscator Ultimate edition or higher; hovering over the badge shows the same information.
Babel Obfuscator comes in two editions. Enterprise is a single-user license for Windows with the command line tool and the MSBuild task of the .NET Framework (babel_net472) zip package. Ultimate is a site license that runs on Windows, Linux and macOS on any number of machines and adds Babel Desktop, the NuGet packages, build server integration, the Babel Encrypt plugin, and the protections introduced in 12.0 for the Ultimate tier: Chained State, STREAM string encryption and Android and iOS package-integrity tampering detection. The Babel Licensing editions, Server and Data Center, include Babel Obfuscator Ultimate, so every badged feature is available on them too; a few licensing-related capabilities, such as the licensing tools of the MCP server, are specific to those two editions and say so on their page.
A heading without a badge describes a feature of both editions. The complete matrix, with pricing, is on the Compare Editions page.
Protection Features
Each feature can be enabled on its own and tuned per symbol with obfuscation rules, so you can apply the strongest transforms only where the intellectual property is.
Rename namespaces, types, members and parameters to meaningless names, in ASCII or Unicode, with XAML/BAML awareness and cross-assembly map files.
Encrypt string literals with the XOR, HASH or STREAM algorithms, or plug in an algorithm of your own.
Insert opaque branches, rewrite conditionals and flatten methods around dispatchers, up to the Ultimate Chained State algorithm.
Encrypt method bodies and run them in the managed Babel Virtual Machine. Keep them in external files or behind passwords for feature-based licensing.
Route calls to external and internal methods through generated proxies, so the real call targets disappear from the IL.
Compress and encrypt embedded resources, decrypted on demand at run time.
Hide inline numeric constants and array initializers, such as keys and lookup tables.
Detect an attached debugger and terminate the process, or run a handler of your own.
Verify the image hash on desktop and the package signature or identity on Android and iOS, then terminate or react with custom code.
Fold dependencies into one assembly, or embed them as encrypted resources, for a single-file deployment with a smaller exposed surface.
Remove dead code, seal classes, strip attributes and inline small members to shrink metadata and speed up loading.
Fine-tune every feature with XML rules and custom attributes, backed by the analysis Agent that keeps reflection and serialization working.
Built for AI-Assisted Workflows
Babel treats AI assistants as first-class operators of the product, at two levels.
Babel MCP Server. Babel Desktop can expose an MCP endpoint on the local machine. Claude Code, or any client that speaks the Model Context Protocol, then operates the application the way you would: it creates projects, adds assemblies, writes rules, chooses what to merge or embed, starts the obfuscation, reads warnings and statistics, decodes stack traces, authors themes and takes screenshots to check its own work. On the Server and Data Center editions the same server manages the licensing database. The server is off by default. Turn it on with Enable the automation server in Settings > MCP. It listens on loopback only and can require an access token. Copy Claude Code command, on the same page, gives you the registration command. See Babel MCP Server.
claude mcp add --transport http babel-obfuscator http://127.0.0.1:8765/mcp \
--header "X-Babel-Token: paste-the-token-from-settings-mcp"AI-friendly command line. Since version 11.7 the command line tool can emit a structured, versioned output stream for CI pipelines and agents: --format=json or --format=ndjson switch stdout to the babel.cli.v1 schema, --quiet makes unattended runs fail fast instead of prompting, and --strict-exit turns on semantic exit codes. The same flag makes --help and --version machine-readable, so an agent can discover every option on its own. See AI-Friendly Mode.
Babel Licensing has its own MCP server for the hosted Licensing Service, so an assistant can manage customers, licenses and activations over the REST API. See AI Integration in the Babel Licensing manual.
Platforms and Frameworks
| Area | Support |
|---|---|
| Build host | Windows, with the command line tool and MSBuild task from the zip packages; Linux, macOS and CI build servers through the Babel NuGet packages and dotnet tool (Ultimate edition); Babel Desktop on Windows, macOS and Linux (Ultimate edition) |
| Target runtimes | .NET 10 and every .NET and .NET Core release before it, .NET Framework 2.0 to 4.8, .NET Standard, Mono |
| Application models | Desktop (WPF, Windows Forms, Avalonia), .NET MAUI on Android and iOS, Xamarin, Blazor, ASP.NET Core, UWP, nanoFramework |
| Languages | C#, including C# 14, VB.NET and F# |
| Publish modes | Framework-dependent, self-contained, single-file, trimmed and NativeAOT |
Obfuscation works on IL, so a build host on one operating system can protect assemblies published for any runtime identifier. Symbol renaming, STREAM string encryption and control flow obfuscation, including Chained State, survive trimming and NativeAOT unchanged. Features that need a memory-mapped image or dynamic IL, such as Code Encryption, Dynamic Proxy and the desktop tampering check, have documented limits on MAUI, Blazor and AOT targets; each feature page states them.
How You Run It
Application for Windows, macOS and Linux to build and run obfuscation projects, decode stack traces, manage Babel Licensing and host the MCP server.
Every feature from a shell or script, with an AI-friendly output mode. On
Linux and macOS it runs as the Ultimate dotnet tool.
Obfuscate as part of the build from Visual Studio and build servers, with IntelliSense for every task property.
Add a package reference and dotnet build or dotnet publish obfuscates at
the right point of the SDK pipeline, before trimming and AOT. The way to run
Babel on Linux, macOS and CI build servers.
The Ultimate edition and the Babel Licensing editions include the NuGet packages, so Babel runs as a dotnet tool on Windows, Linux and macOS and inside SDK-style builds. Babel Desktop runs the engine on .NET 10, so obfuscating in Babel Desktop also requires one of these editions. The Enterprise edition provides the Windows command line tool and the MSBuild task of the .NET Framework zip package.
Next Steps
- Getting Started to install Babel and activate your license
- General Features for a feature-by-feature tour
- Enhancing Code Security for the settings that give the best protection with the least effort
- Examples for MAUI, Blazor, ClickOnce, build servers and feature-based licensing