Skip to Content
New release 12 available 🎉

Control Flow Algorithms

Babel Obfuscator provides several control flow algorithms that you enable individually. Most produce verifiable IL and run on every supported runtime; two (token and underflow) do not and are covered at the end of this page.

Verifiable Algorithms

AlgorithmWhat it does
gotoInserts irrelevant branches, making the control flow longer and less linear.
ifRewrites if statements into more complex forms by introducing additional conditions.
switchRebuilds a method around one or more switch dispatchers, so its blocks no longer run in source order (this is known as flattening).
caseHides the constant values that drive the switch dispatcher, so they are no longer plain numbers in the code.
callAdds variables that determine the next jump inside the switch body and are produced by calls to other methods.
valueFurther protects the switch selectors using the Value Encryption feature.
chainChained State — an advanced flattening algorithm hardened against automated deobfuscation. Available from the Ultimate edition. See Chained State.

goto and if are inexpensive and can be applied broadly. The switch family (switch, case, call, value) and chain flatten a method and are the strongest transforms, at a higher runtime cost — see Performance & Tuning.

Chained State Ultimate

chain is a flattening algorithm, like switch, but it is specifically engineered to resist the automated tools that can rebuild an ordinary flattened method. It produces verifiable IL and runs on every supported runtime. Enable it with --controlflow chain=on. It has its own page: Chained State.

Non-Verifiable Options

The token algorithm inserts invalid metadata tokens into the control flow, and the underflow algorithm adds points to the method body where the managed stack can underflow. Both make the IL non-verifiable.

The token and underflow algorithms are not compatible with the verifiable nature of .NET and .NET Core assemblies and can cause runtime errors. Babel Obfuscator automatically disables them when targeting .NET or .NET Core assemblies.

Invalid Opcodes

The Emit Invalid Opcodes option adds invalid MSIL instructions alongside the instructions inserted by each algorithm, which can make it harder for decompilers to reconstruct the original code. Enabling it makes the assembly non-verifiable and forces the CLR to run the application as a 32-bit process.

Do not enable Emit Invalid Opcodes if the application must run as a 64-bit process, or if it targets .NET Core or .NET Framework where the assembly needs to be IL-verifiable to execute. In those cases, leave this option off.

Last updated on