Skip to main content
Sogen provides extensive configuration options to customize the emulation environment. Settings can be configured through command-line arguments or programmatically when using Sogen as a library.

Emulator Settings

The emulator_settings structure controls core emulator behavior:

Basic Settings

disable_logging

Disables all logging output from the emulator.
Command-line equivalent: -s or --silent

use_relative_time

Uses instruction count instead of wall-clock time for deterministic execution.
Command-line equivalent: -rep or --reproducible
Relative time mode is essential for reproducible malware analysis and debugging race conditions.

emulation_root

Base directory for the virtual Windows filesystem:
Command-line equivalent: -e /path/to/windows/root The emulation root should contain a typical Windows directory structure:

registry_directory

Path to the registry hive directory:
Command-line equivalent: -r ./my-registry

Application Settings

The application_settings structure defines the target program and its execution environment:

application

Path to the executable to run (Windows-style path):

working_directory

Working directory for the process. If not specified, defaults to the executable’s directory:

arguments

Command-line arguments passed to the program:

Path Mappings

Path mappings allow you to redirect Windows paths to specific host filesystem locations. This is useful for:
  • Analyzing samples without copying them into the emulation root
  • Providing custom configuration files
  • Isolating specific directories

Programmatic Configuration

Command-Line Configuration

The syntax is: -p <windows-path> <host-path> [program]

Path Mapping Example

Port Mappings

Port mappings redirect network connections from emulator ports to different host ports. This allows:
  • Multiple emulator instances on one host
  • Routing traffic to specific network services
  • Testing network isolation

Programmatic Configuration

Runtime Port Mapping

You can also map ports at runtime:

Port Mapping Use Cases

Complete Configuration Example

Registry Configuration

Sogen requires a Windows registry dump to function properly. The registry provides:
  • System configuration
  • Installed software information
  • User profiles
  • Windows version details

Creating a Registry Dump

Registry Path Substitution

Sogen automatically performs registry path substitution:
  • CurrentControlSet → ControlSet001
  • ActiveComputerName → ComputerName
This ensures compatibility with exported registry hives.