Skip to Content
New release 12 available 🎉

Chained State Ultimate

Chained State (chain) is the strongest control flow transform in Babel Obfuscator. Like the switch algorithm it flattens a method — it rebuilds the method around a dispatcher so its blocks no longer run in source order — but it is specifically engineered to resist the automated tools that can undo ordinary flattening.

Why Chained State

Ordinary switch flattening is effective against a human reader, but a well-known class of automated deobfuscators can often reconstruct the original method: they statically analyze the dispatcher, recover the order in which the blocks were meant to run, and rewrite the method back to something close to the source. Against these tools, plain flattening can be undone in a single automated pass.

Chained State closes that gap. The dispatcher is built so that the original order cannot be recovered by static analysis alone — an attacker has to actually run the method to follow its flow. In internal testing against a standard automated control-flow deobfuscator, code flattened with switch was rebuilt back to the original method, while the same code flattened with chain was left intact. The result is a flattened method that resists both manual reading and automated recovery.

Chained State is a hardening of flattening, not a replacement for it. You can enable it on its own, or alongside the other control flow algorithms.

Compatibility

Chained State emits only ordinary, verifiable IL and adds no helper types, no reflection, and no runtime dependencies. As a result it runs unchanged across the whole .NET range:

  • .NET Framework 4.x through .NET 10, .NET Core, and Mono / Xamarin.
  • Trimmed (ILLink) and NativeAOT applications — there is no dynamic code to break under ahead-of-time compilation.
  • .NET MAUI, including Android and iOS.

Because the transform stays within verifiable IL, it does not force the assembly into a 32-bit process and is safe to combine with the rest of your obfuscation configuration.

Performance

Chained State carries the same kind of runtime cost as switch flattening — a flattened method runs a dispatcher on every call — and in practice its per-call overhead is within a few percent of ordinary switch. As with any flattening, reserve it for the methods that actually protect your intellectual property, and keep it off hot, performance-critical paths. See Performance & Tuning for the full comparison and how to limit it with rules.

Enabling Chained State

Command Line

babel myapp.exe --controlflow chain=on

You can combine it with the other algorithms, for example:

babel myapp.exe --controlflow switch=on --controlflow case=on --controlflow chain=on

MSBuild Babel Task

<PropertyGroup> <ControlFlowObfuscation>chain=true;true</ControlFlowObfuscation> </PropertyGroup> <Babel ControlFlowObfuscation="$(ControlFlowObfuscation)" />

Babel Desktop

In the Control flow group of the properties panel, enable control flow obfuscation (ControlFlowObfuscation) and select chain among the algorithms.

Chained State is available from the Ultimate edition (and Server / Data Center). With the Enterprise edition the engine does not apply the chain algorithm.

Last updated on