Emulator Settings
Theemulator_settings structure controls core emulator behavior:
Basic Settings
disable_logging
Disables all logging output from the emulator.-s or --silent
use_relative_time
Uses instruction count instead of wall-clock time for deterministic execution.-rep or --reproducible
Relative time mode is essential for reproducible malware analysis and debugging race conditions.
emulation_root
Base directory for the virtual Windows filesystem:-e /path/to/windows/root
The emulation root should contain a typical Windows directory structure:
registry_directory
Path to the registry hive directory:-r ./my-registry
Application Settings
Theapplication_settings structure defines the target program and its execution environment:
application
Path to the executable to run (Windows-style path):working_directory
Working directory for the process. If not specified, defaults to the executable’s directory:arguments
Command-line arguments passed to the program:Path Mappings
Path mappings allow you to redirect Windows paths to specific host filesystem locations. This is useful for:- Analyzing samples without copying them into the emulation root
- Providing custom configuration files
- Isolating specific directories
Programmatic Configuration
Command-Line Configuration
-p <windows-path> <host-path> [program]
Path Mapping Example
Port Mappings
Port mappings redirect network connections from emulator ports to different host ports. This allows:- Multiple emulator instances on one host
- Routing traffic to specific network services
- Testing network isolation
Programmatic Configuration
Runtime Port Mapping
You can also map ports at runtime:Port Mapping Use Cases
Complete Configuration Example
Registry Configuration
Sogen requires a Windows registry dump to function properly. The registry provides:- System configuration
- Installed software information
- User profiles
- Windows version details
Creating a Registry Dump
Registry Path Substitution
Sogen automatically performs registry path substitution:CurrentControlSet→ControlSet001ActiveComputerName→ComputerName