Babel Task Reference
Every attribute of the Babel MSBuild task, grouped by feature, with the command line option each attribute maps to.
The Babel task exposes one attribute for each option of the command line tool and forwards the attribute values to it unchanged. A Boolean attribute accepts true or false. Where the command line option takes an argument, the same argument can be passed as the attribute value, so an attribute marked Boolean / String accepts either form. List attributes take several values separated by ;. Attributes that are not set keep the defaults listed in the tables.
When the Babel Obfuscator NuGet package is used, each attribute is set through an MSBuild property or item; see the Property Mapping table of the package reference.
Version 12.0 adds the SingleFile, TrustedSigner, TrustedBundle and TrustedTeam attributes, which drive the mobile package-integrity checks of Tampering Detection, and the stream value of StringEncryption. They are marked 12.0 in the tables below.
Miscellaneous
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
BabelDirectory | String | Legacy override of the folder that contains babel.exe. The task fails when the executable is not found there. Prefer ToolPath. | ||
DbgHelpDllDir | String | --dbghelpdlldir | Path of the folder that contains dbghelp.dll. | |
DetectIfObfuscated | Boolean / String | false | --isobfuscated | Whether to detect if the target assembly is already obfuscated. The value warn raises a warning and continues, exit stops without processing the assembly. |
EnableObfuscationAgent | Boolean | true | --agent | Whether to run the obfuscation agent, which analyzes the assembly and excludes from obfuscation the symbols that would break it. |
License | String | --license | Full path of the license file, or a list of directories to search for license files. | |
NoConfiguration | Boolean | false | --noconfig | Whether to ignore the default values stored in the Babel configuration file. |
NoWarnings | String | --nowarn | List of warning codes to ignore. | |
ProvideCommandLineArgs | Boolean | false | Whether to log the command line passed to Babel and return it in the CommandLineArgs output item. | |
QuickRules | String | --quickrule | Quick rule definitions. | |
RandomSeed | String | --randomseed | Seed of the random number generator used during obfuscation. | |
RemoveKey | Boolean | false | --removekey | Whether to remove the strong name from the obfuscated assembly. |
SatelliteAssemblies | String | --satellite | List of satellite assembly files to process. | |
SearchDirectories | String | --addsearch | List of directories where the referenced assemblies are searched. References is accepted as an alias. | |
SearchSatelliteAssemblies | Boolean | true | --satellite | Whether to search and process the satellite assemblies of the target. |
ShowLogo | Boolean | true | --logo | Whether to output the Babel version and copyright information. |
ShowStatistics | Boolean | true | --statistics | Whether to display the obfuscation statistics at the end of the process. Boolean only: use StatisticsFile to save the statistics to a file. |
StatisticsFile | String | --statistics | Path of the file where the obfuscation statistics are saved. Ignored when ShowStatistics is false. | |
TargetAssemblyName | String | nochange | --assemblyname | Origin of the target assembly name: nochange, inputfilename, outputfilename or name=<assembly name>. |
ToolExe | String | Name of the Babel executable, babel.exe or babel.dll. | ||
ToolPath | String | Directory of the Babel executable. | ||
Trace | String | --trace | List of regular expressions that select the symbols to trace. The trace shows why a symbol is or is not obfuscated and helps debugging the obfuscation rules. | |
Use | Key=Value | --use | Usage options as key-value pairs. | |
VerboseLevel | Int | 1 | --verbose | Verbosity of the console output. 0 disables the messages, values above 10 show debug information. |
WarningsAsErrors | String | --warnaserror | List of warning codes reported as errors. An error stops the obfuscation process. | |
WarningsAsInfos | String | --warnasinfo | List of warning codes reported as informational messages. | |
XmlRules | String | Inline XML rule elements, see XML Rules. |
Input Files
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
InputFile | String | Path of the assembly to obfuscate. | ||
KeyContainer | String | --keyname | Name of the strong name key container (Windows only). | |
KeyFile | String | --keyfile | Path of the strong name key file used to sign the obfuscated assembly. | |
KeyPwd | String | --keypwd | Password of the strong name key file or certificate. | |
MapInFiles | String | --mapin | List of XML map files of already obfuscated assemblies, used to rename the references to their symbols. | |
Project | String | --project | Path of a Babel obfuscation project file. | |
RulesFiles | String | --rules | List of XML rules files to process. |
Output Files
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
GenerateLogFile | Boolean | false | --logfile | Whether to generate an obfuscation log. The default log file name is <target assembly>.log. |
GenerateMapOutFile | Boolean | false | --mapout | Whether to generate an obfuscation map file. The default map file name is <target assembly>.xml.map. |
LogFile | String | --logfile | Path of the obfuscation log file. | |
MakeProject | String | --makeproject | Path of the MSBuild project file created from the task settings. | |
MapOutFile | String | --mapout | Path of the obfuscation map file. | |
OutputFile | String | --output | Path of the obfuscated assembly. | |
PdbFile | String | --pdb | Path of the debug symbols file. | |
PdbPwd | String | --pdbpwd | Password of the debug symbols file. |
Plugins
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
Plugins | String | --plugin | List of plugin assembly files. | |
PluginsArguments | Key=Value | --argument | Plugin arguments as key-value pairs. |
Merge and Embed
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
CopyAttributes | Boolean / String | false | --copyattrs | Whether the assembly level attributes of the merged assemblies are copied into the target assembly. A regular expression selects the duplicate attributes that can be merged. |
DependenciesManifest | Boolean | true | --jsonmanifest | Whether to update the .deps.json dependencies manifest of the target assembly when assemblies are merged or embedded. |
EmbedAssemblies | String | --embed | List of assembly files to embed into the target assembly. | |
Internalize | Boolean | false | --internalize | Whether the merged types have their visibility restricted to the target assembly. |
MergeAssemblies | String | List of assembly files to merge into the target assembly. |
Renaming
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
FlattenNamespaces | Boolean / String | true | --flatns | Whether to move the renamed types into the global namespace. A string sets a common namespace name for the renamed types instead. |
NameLength | Int / Key=Value | --namelength | Minimum length of the obfuscated names. Key-value pairs assign the length to a given symbol kind. | |
NamePrefix | String / Key=Value | --nameprefix | Prefix of the obfuscated names, $name or any string. Key-value pairs assign the prefix to a given symbol kind. | |
ObfuscateEvents | Boolean | true | --events | Whether to rename events. |
ObfuscateFields | Boolean | true | --fields | Whether to rename fields. |
ObfuscateMethods | Boolean | true | --methods | Whether to rename methods. |
ObfuscateParameters | Boolean | true | --parameters | Whether to rename method parameters. |
ObfuscateProperties | Boolean | true | --properties | Whether to rename properties. |
ObfuscateTypes | Boolean | true | --types | Whether to rename types. |
ObfuscateXaml | Boolean / Key=Value | false | --xaml | Whether to rename the symbols referenced by XAML and BAML resources. Key-value pairs configure the renaming. |
OverloadedRenaming | Boolean / Key=Value | false | --overloaded | Whether to reuse the same name for members with different signatures. Key-value pairs select which members are overloaded. |
UnicodeNormalization | Boolean / String | false | --unicode | Whether to generate names using Unicode characters. When disabled, ASCII characters are used. A comma-separated list of characters or ranges restricts the character set. |
VirtualFunctions | Boolean / Key=Value | true | --virtual | Whether to rename virtual members. Key-value pairs configure the renaming of external overrides. |
XmlDocFiles | String | --xmldoc | List of XML documentation files to process together with the assembly. XmlDoc is accepted as a legacy alias. |
Control Flow Obfuscation
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
ControlFlowObfuscation | Boolean / Key=Value | false | --controlflow | Whether to obfuscate the control flow of the methods. Key-value pairs select the algorithms, including chain=on for Chained State Ultimate. |
ControlFlowIterations | Int | 3 | --iterations | Number of iterations of the control flow obfuscation algorithms. 0 disables control flow obfuscation. ILIterations and Iterations are accepted as aliases. |
EmitInvalidOpcodes | Boolean / String | false | --invalidopcodes | Whether to emit invalid MSIL op-codes, which makes the assembly not verifiable. The value enhanced inserts additional invalid op-codes. |
Encryption and Protection
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
DebuggingProtection | Boolean | false | --antidebugging | Whether to enable anti-debugging protection. |
DynamicProxy | Boolean / String | false | --proxy | Whether to wrap method calls in dynamically generated proxies. The value selects the calls to proxy: internal, external or all. |
DynamicProxyCallFilters | String | --proxy | List of regular expressions that select the method calls to proxy. | |
MsilEncryption | Boolean / String | false | --msilencryption | Whether to encrypt the MSIL code of the methods. Regular expressions select the methods to encrypt by signature. |
ResourceEncryption | Boolean / Key=Value | false | --resourceencryption | Whether to encrypt the managed resources. Key-value pairs enable encryption and compression separately. |
SingleFile 12.0 | Boolean | false | --singlefile | Signals that the target is published as a single-file, trimmed or NativeAOT application. On desktop targets the tampering detection check is inert for such a publish, and Babel emits a warning when it is requested. |
StringEncryption | Boolean / String | false | --stringencryption | Whether to encrypt the user strings. The value selects the algorithm: xor, hash, or stream 12.0 Ultimate. |
SuppressIldasm | Boolean | false | --ildasm | Whether to prevent ILDASM from disassembling the obfuscated assembly. |
SuppressReflection | Boolean / Int | false | --reflection | Whether to emit invalid metadata that stops reflection-based tools. An integer sets the level: the higher the level, the more invalid metadata is generated. |
TamperingDetection | Boolean | false | --tamperingdetection | Whether to enable tampering detection. |
TrustedBundle 12.0 Ultimate | String | --trustedbundle | Trusted iOS bundle identifier (CFBundleIdentifier) pinned by the iOS package-integrity check. | |
TrustedSigner 12.0 Ultimate | String | --trustedsigner | List of SHA-256 fingerprints, 64 hexadecimal characters each, of the trusted Android APK signing certificates pinned by the Android package-integrity check. | |
TrustedTeam 12.0 Ultimate | String | --trustedteam | Trusted Apple Developer Team ID pinned by the iOS package-integrity check. | |
ValueEncryption | Boolean / Key=Value | false | --valueencryption | Whether to encrypt the constant values and arrays. Key-value pairs select the kinds of value to encrypt. |
Optimizations
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
CleanAttributes | Boolean / String | false | --cleanattrs | Whether to remove unwanted attributes. Regular expressions select the full names of the attribute types to remove. |
ConstRemoval | Boolean | false | --constremoval | Whether to remove the constant fields. |
DeadCodeElimination | Boolean / String | false | --deadcode | Whether to remove the methods, properties and events not used by the application. Regular expressions set the entry points where the search starts. |
DisgregateRemoval | Boolean | false | --disgregateremoval | Whether to remove the property and event metadata. |
EnumRemoval | Boolean | false | --enumremoval | Whether to remove the System.Enum types. |
InlineExpansion | Boolean | false | --inlineexpansion | Whether to replace the calls to the methods marked for inline expansion with the method body. |
SealClasses | Boolean | false | --seal | Whether to seal the classes that are not used in any inheritance chain. |
Code Generation
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
AddReferences | String | --addreference | List of assemblies to add as references of the target assembly. | |
Framework | String | Target framework name forced for the processed assembly. | ||
GenerateDebug | Boolean / String | false | --debug | Whether to generate the debug symbols of the obfuscated assembly. A symbol store path can be specified as the value. |
Instrument | Boolean / String | false | --instrument | Whether to instrument the code. Regular expressions select the full names of the methods to instrument. |
InstrumentEmptyMethods | Boolean | false | --emptymethods | Whether to instrument the methods with an empty body. |
ModuleInitializer | Boolean / String | false | --moduleinitializer | Whether to add module initializer code to the target assembly. |
ModuleInitializerTarget | String | --moduleinitializer | Signature of the static method, without parameters, called after the module loads. | |
ModuleVersionId | Boolean / String | false | --moduleversionid | Whether to set the module version identifier (MVID) of the obfuscated assembly. A GUID string sets the value, otherwise a random one is generated. |
Packages
| Attribute | Type | Default | Command line | Description |
|---|---|---|---|---|
AndroidSigningKeyAlias | String | --keyalias | Alias of the key in the Android key store (APK packages). | |
AndroidSigningKeyPass | String | --keypass | Password of the key in the Android key store (APK packages). | |
AndroidSigningKeyStore | String | --keystore | Android key store file (APK packages). | |
AndroidSigningStorePass | String | --storepass | Password of the Android key store (APK packages). | |
RemoveFiles | String | --remove | List of deployed assemblies to remove from the package. | |
SkipFiles | String | --skip | List of deployed assemblies that are not obfuscated. | |
TakeFiles | String | --take | List of deployed assemblies to obfuscate. | |
XapCompressionLevel | Int | 6 | --compress | Compression level of the package, from 0 (no compression) to 9 (XAP packages). |
Task Outputs
| Output | Description |
|---|---|
CommandLineArgs | The command line passed to Babel, available when ProvideCommandLineArgs is true. |
ExitCode | The exit code returned by Babel. |
Example
The task below obfuscates the intermediate assembly of a .NET MAUI Android project with STREAM string encryption and tampering detection pinned to the APK signing certificate, and captures the command line passed to Babel:
<Target Name="Obfuscate" AfterTargets="Compile" Condition="'$(DesignTimeBuild)' != 'true'">
<Babel InputFile="$(ProjectDir)$(IntermediateOutputPath)$(TargetFileName)"
OutputFile="$(ProjectDir)$(IntermediateOutputPath)$(TargetFileName)"
StringEncryption="stream"
ControlFlowObfuscation="true"
ControlFlowIterations="3"
TamperingDetection="true"
TrustedSigner="2924C53EE9C511E9F26E0720FD8151064F7621681667D7AB1899E551CDB25104"
ProvideCommandLineArgs="true">
<Output TaskParameter="CommandLineArgs" ItemName="BabelCommandLineArgs" />
</Babel>
<Message Importance="high" Text="@(BabelCommandLineArgs, ' ')" />
</Target>