enhancementhelp wantedmacossecuritywindows
Repository metrics
- Stars
- (137 stars)
- PR merge metrics
- (PR metrics pending)
Description
Currently, the anti-debugging logic is implemented only for Linux. It includes checks such as:
- Disabling core dumps via
prctl(PR_SET_DUMPABLE, 0), - Checking
/proc/self/statusforTracerPid, - Detecting presence of GDB or LLDB via
/proc/self/cmdline.
However, this logic does not apply to other platforms like macOS and Windows, leaving those builds unprotected against runtime inspection, debugging, or tampering.
So the goal is to Implement cross-platform anti-debugging support for:
- macOS:
- Detect
ptrace()withPT_DENY_ATTACH, - Check for known debuggers (
lldb,gdb) via process list (sysctl), - Block core dumps if applicable.
- Windows:
- Use
IsDebuggerPresent()andCheckRemoteDebuggerPresent()from WinAPI, - Use
NtQueryInformationProcessfor advanced checks, - Optionally: detect debugger windows or tools like x64dbg.
Please Note!
- Some methods may require elevated permissions (macOS
PT_DENY_ATTACHmust be called early), - Anti-debugging is never bulletproof but raises the bar,
- All features must be behind platform checks to maintain compatibility.
Looking for contributors with experience in low-level macOS or Windows system programming.