Skip to Content
New release 12 available 🎉
ObfuscatorIntroductionGeneral Features

General Features

What Babel Obfuscator does, where it runs, and what it protects. Each section links to the page that shows how to configure the feature.

Protects Your Code and Intellectual Property Against Reverse Engineering

Babel Obfuscator applies several independent layers of protection to a compiled assembly: it renames symbols to meaningless identifiers, encrypts strings, constants and arrays and resources, rewrites the control flow of methods, hides call targets behind dynamic proxies, and can encrypt whole method bodies for execution in a managed virtual machine. The application keeps its behaviour and its public interface; what a decompiler recovers is no longer the source you wrote.

The layers combine. Renaming removes the vocabulary a reader relies on, string and value encryption remove the clues that survive renaming, control flow obfuscation removes the structure, and code encryption removes the code itself. Applied together, and selectively where the intellectual property is, they raise the cost of understanding and modifying the assembly far above the value an attacker can extract from it.

Compatible With the Whole .NET Ecosystem

Babel Obfuscator works at the IL and metadata level, so it supports every runtime and application model that produces standard .NET assemblies:

  • .NET 10 and every .NET and .NET Core release before it
  • .NET Framework 2.0 to 4.8
  • Desktop applications built with WPF, Windows Forms or Avalonia
  • .NET MAUI on Android and iOS, and Xamarin
  • Blazor and ASP.NET Core
  • .NET Standard, UWP, Mono and nanoFramework

It handles code written in C#, up to C# 14, VB.NET and F#, and it follows the publish modes of the modern SDK: framework-dependent, self-contained, single-file, trimmed and NativeAOT. Symbol renaming, STREAM string encryption and control flow obfuscation, including Chained State, survive trimming and ahead-of-time compilation unchanged. Features that rely on a memory-mapped image or on dynamic IL, such as Code Encryption, Dynamic Proxy and the desktop tampering check, have documented limits on MAUI, Blazor and AOT targets; each feature page states them, and the Obfuscate .NET MAUI and Blazor WebApp examples show working configurations.

Runs on Windows, macOS and Linux Ultimate

Every edition includes the command line tool and MSBuild task for Windows (zip packages). Running Babel Desktop, running Babel on macOS and Linux, and inside Azure DevOps, GitHub Actions and similar CI build pipelines, requires the Ultimate edition, or the Server and Data Center licensing editions that include it: only these ship the Babel Obfuscator NuGet packages, which run Babel as a dotnet tool on any operating system and integrate it into dotnet build and dotnet publish. The Enterprise edition is limited to the Windows command line tool and MSBuild task of the .NET Framework zip package.

Because obfuscation works on IL, the operating system of the build host does not constrain the target: a Windows build agent can protect assemblies published for linux-x64, linux-arm64 or osx-arm64, and a Linux container can protect a Windows desktop application. Teams can therefore keep the build environment they already have.

Fully Managed Code Encryption and Virtualization

Code Encryption rewrites the IL of a method into a custom instruction set, encrypts it, and leaves in its place a stub that hands control to the Babel Virtual Machine (BVM), a lightweight managed runtime embedded in the obfuscated assembly. The BVM decrypts and executes the method when it is called. The method body no longer exists in the assembly in a form a decompiler can read, and the instructions cannot be patched.

The solution is entirely managed: encrypted methods are not replaced by native code for a specific platform, so the cross-platform nature of .NET is preserved and the JIT compiler still optimizes for the target CPU. Encrypted code can be kept in external code files deployed alongside a license, or protected with a password supplied at run time, which is the basis for feature-based licensing. The Hardware Dongle Binding article shows how to tie encrypted code to a physical device. Because it costs performance, Code Encryption is meant for the sensitive parts of the code base, with the other protections covering the rest.

Hardened Against Automated Deobfuscation Ultimate

Classic obfuscation defeats a human reader; a class of automated tools can undo some of it in a single pass, by statically recovering the order of a flattened method or reading the key that sits next to an encrypted string. Version 12.0 adds two transforms designed for that adversary:

  • Chained State flattens a method around a dispatcher whose original order cannot be recovered by static analysis alone. In internal testing against a standard automated deobfuscator, methods flattened with the ordinary switch algorithm were rebuilt, while the same methods flattened with chain were left intact. It emits verifiable IL, adds no runtime dependencies, and runs within a few percent of ordinary flattening.
  • STREAM string encryption encrypts each string individually with an authenticated cipher, decrypts it lazily on first use, and never stores the key inline. Identical strings encrypt to different bytes, no point in time holds the whole string set in clear text, and the fully managed decryptor publishes unchanged under trimming, NativeAOT and FIPS mode.

Detects Debugging and Tampering, on Desktop and Mobile

Anti-debugging code injected into the assembly detects an attached debugger and terminates the process or invokes a method of yours. Tampering detection verifies at start-up that the assembly is the one Babel produced: on desktop targets it hashes the loaded image in memory and compares it with a hash stamped at obfuscation time.

Starting with version 12.0, tampering detection covers .NET MAUI, where the desktop technique cannot apply. On Android the obfuscated app compares the certificate the running APK was signed with against trusted signer fingerprints you pin at obfuscation time, so a repackaged or re-signed app is rejected. On iOS it verifies its own bundle identifier and Apple Team identifier. Both checks inspect the operating-system package rather than the managed image, so they keep working with trimming and full AOT. In every case the reaction is yours to choose: terminate, or run a custom handler that can log, degrade features or phone home.

Simplifies Deployment by Merging and Embedding Dependencies

Merge and Embed turns an application and its dependencies into a single file. Merging folds the code of referenced assemblies into the target and renames it together with your own, so the merged types can be internalized and obfuscated as one unit, which both simplifies deployment and shrinks the surface of readable code. Embedding stores an assembly whole, as an encrypted resource that is loaded at run time, for third-party or strong-named assemblies that must not be altered. The two can be combined in the same project.

Optimizes Code and Metadata

Beyond protection, Babel optimizes the assembly it produces. Dead code removal strips methods, fields, properties and types that are never used. Metadata optimizations seal classes automatically, remove unneeded custom attributes, System.Enum types and property and event constructs. Code optimizations inline small methods and properties and remove const fields. The result is an assembly that is smaller on disk, faster to load, and harder to read, because the metadata a reverse engineer relies on has been reduced to what the runtime needs.

Integrated With Visual Studio, MSBuild, NuGet and Build Servers

Babel runs inside the build rather than after it. The Babel MSBuild task obfuscates from Visual Studio and from any build server that runs MSBuild, and every task property is documented with IntelliSense in the project file. The Babel.Obfuscator NuGet package Ultimate goes further for SDK-style projects: a single package reference places the task at the right point of the dotnet build and dotnet publish pipeline, before trimming and ahead-of-time compilation rewrite the assembly, which is the only order in which those publish modes can be protected. The build server examples cover Azure DevOps, GitHub Actions, AppVeyor and App Center, and show how to run unit tests against the obfuscated output; like the NuGet package, they require the Ultimate edition.

Available as a Command Line Tool, With an AI-Friendly Mode

Everything Babel can do is available from the command line, on Windows, Linux and macOS. Since version 11.7 the tool also offers an AI-friendly mode for pipelines and agents: --format=json or --format=ndjson emit a structured, versioned event stream on stdout while diagnostics go to stderr, --quiet suppresses the banner and fails fast instead of prompting, and --strict-exit enables semantic exit codes that distinguish invalid arguments, missing input, obfuscation, licensing and signing failures. The same flag turns --help into a machine-readable description of every option.

Operated by AI Assistants Through MCP

Babel Desktop can host a Model Context Protocol server, so an assistant such as Claude Code connects to the running application and drives it: create a project, add assemblies, write rules, choose what to merge or embed, obfuscate, read warnings and statistics, decode a stack trace, author a theme, and take a screenshot to check the result. Tools cover the operations you perform most often, plus tools for settings, Babel Licensing and application updates. On the Server and Data Center editions the same server manages the licensing database: customers, products, orders, licenses, signing keys, and license generation and export.

The server is off by default, binds to the loopback address only, and can require an access token on every request. Babel Licensing offers a separate MCP server for the hosted Licensing Service.

Decodes Obfuscated Stack Traces

Renaming changes the names that appear in exception stack traces, so Babel produces an XML map file for every obfuscated assembly and provides the tools to translate a trace back. The Stack Decoder in Babel Desktop, and the --stacktrace command line option, restore the original names, with optional PDB support for line numbers. When Dynamic Proxy is enabled, the decoder names the method behind every proxy bridge frame and can hide the Babel-generated frames altogether, leaving a trace identical to the one the unobfuscated application would produce. Map files also drive cross-assembly renaming, so an application and its libraries can be obfuscated in separate builds and still agree on the renamed symbols.

FIPS-Ready

Assemblies protected with Babel run on hosts in FIPS mode. The features that decrypt content at run time, Code Encryption, String Encryption, Resource Encryption and Value and Array Encryption, can be configured to use a self-contained managed AES decryptor, so the injected runtime never depends on the platform cryptographic provider and the application starts even in a container whose OpenSSL FIPS provider is missing. The FIPS Compliance page explains the environment condition, the obfuscation-time fix and the environment-level fix.

Extensible With Rules, Attributes and Plugins

Every feature can be tuned per symbol. XML rules select types and members by pattern, attribute, visibility or inheritance and enable, disable or configure a feature for them; custom attributes do the same from the source code. The obfuscation Agent analyses the assembly before obfuscation and generates the rules that keep reflection, serialization, data binding and dynamic code working. For anything beyond that, plugins written in .NET can add string and value encryption algorithms, custom renaming schemes, generated rules and code transformations, with open-source samples on GitHub as a starting point.

Last updated on