Control Flow Algorithms
Babel Obfuscator provides several control flow algorithms that you enable individually. Most produce verifiable IL and run on every supported runtime; two (token and underflow) do not and are covered at the end of this page.
Verifiable Algorithms
| Algorithm | What it does |
|---|---|
goto | Inserts irrelevant branches, making the control flow longer and less linear. |
if | Rewrites if statements into more complex forms by introducing additional conditions. |
switch | Rebuilds a method around one or more switch dispatchers, so its blocks no longer run in source order (this is known as flattening). |
case | Hides the constant values that drive the switch dispatcher, so they are no longer plain numbers in the code. |
call | Adds variables that determine the next jump inside the switch body and are produced by calls to other methods. |
value | Further protects the switch selectors using the Value Encryption feature. |
chain | Chained State — an advanced flattening algorithm hardened against automated deobfuscation. Available from the Ultimate edition. See Chained State. |
goto and if are inexpensive and can be applied broadly. The switch family (switch, case, call, value) and chain flatten a method and are the strongest transforms, at a higher runtime cost — see Performance & Tuning.
Chained State Ultimate
chain is a flattening algorithm, like switch, but it is specifically engineered to resist the automated tools that can rebuild an ordinary flattened method. It produces verifiable IL and runs on every supported runtime. Enable it with --controlflow chain=on. It has its own page: Chained State.
Non-Verifiable Options
The token algorithm inserts invalid metadata tokens into the control flow, and the underflow algorithm adds points to the method body where the managed stack can underflow. Both make the IL non-verifiable.
The token and underflow algorithms are not compatible with the verifiable nature of .NET and .NET Core assemblies and can cause runtime errors. Babel Obfuscator automatically disables them when targeting .NET or .NET Core assemblies.
Invalid Opcodes
The Emit Invalid Opcodes option adds invalid MSIL instructions alongside the instructions inserted by each algorithm, which can make it harder for decompilers to reconstruct the original code. Enabling it makes the assembly non-verifiable and forces the CLR to run the application as a 32-bit process.
Do not enable Emit Invalid Opcodes if the application must run as a 64-bit process, or if it targets .NET Core or .NET Framework where the assembly needs to be IL-verifiable to execute. In those cases, leave this option off.