Warp-net/warpnet

Add Anti-Debugging Support for macOS and Windows

Open

#9 opened on May 20, 2025

View on GitHub
 (0 comments) (0 reactions) (0 assignees)Go (12 forks)auto 404
enhancementhelp wantedmacossecuritywindows

Repository metrics

Stars
 (137 stars)
PR merge metrics
 (PR metrics pending)

Description

Currently, the anti-debugging logic is implemented only for Linux. It includes checks such as:

  • Disabling core dumps via prctl(PR_SET_DUMPABLE, 0),
  • Checking /proc/self/status for TracerPid,
  • Detecting presence of GDB or LLDB via /proc/self/cmdline.

However, this logic does not apply to other platforms like macOS and Windows, leaving those builds unprotected against runtime inspection, debugging, or tampering.

So the goal is to Implement cross-platform anti-debugging support for:

  1. macOS:
  • Detect ptrace() with PT_DENY_ATTACH,
  • Check for known debuggers (lldb, gdb) via process list (sysctl),
  • Block core dumps if applicable.
  1. Windows:
  • Use IsDebuggerPresent() and CheckRemoteDebuggerPresent() from WinAPI,
  • Use NtQueryInformationProcess for advanced checks,
  • Optionally: detect debugger windows or tools like x64dbg.

Please Note!

  • Some methods may require elevated permissions (macOS PT_DENY_ATTACH must be called early),
  • Anti-debugging is never bulletproof but raises the bar,
  • All features must be behind platform checks to maintain compatibility.

Looking for contributors with experience in low-level macOS or Windows system programming.

Contributor guide