Skip to main content
The Sogen emulator runs Windows executables through the analyzer.exe tool, which provides comprehensive control and monitoring capabilities during program execution.

Basic Usage

To run a Windows program in Sogen, use the following syntax:

Running with Arguments

Pass command-line arguments to the target program:

Command-Line Options

Emulation Configuration

Logging and Analysis Options

Verbosity Levels

Module Tracking

Track specific modules during execution:

Advanced Analysis

State Management

Creating Snapshots

Snapshots capture the complete emulator state and can be restored later:
  1. Run the program with CTRL+C interrupt
  2. When prompted, type y to create a snapshot
  3. The snapshot is saved for later use

Loading Snapshots

Restore a previously saved snapshot:

Loading Minidumps

Analyze Windows minidump files:
Minidumps are loaded into the emulator without starting execution, allowing inspection of crash state.

Advanced Features

Tenet Tracer Integration

Enable execution tracing for Tenet (IDA Pro plugin):
This generates tenet_trace.log containing the execution trace.

Reproducible Execution

Stub clocks and randomness sources for deterministic execution:
Useful for analyzing anti-debugging techniques and ensuring consistent behavior across runs.

Ignore Functions

Skip logging for specific functions:

Complete Example

Here’s a comprehensive example combining multiple options:
This command:
  • Sets the emulation root to ./emulation-root
  • Uses registry from ./registry
  • Enables verbose logging
  • Tracks the malware.exe module
  • Logs executable memory access
  • Logs foreign module access
  • Maps a configuration file from the host system
  • Runs the malware with a command-line argument

Exit Status

The analyzer exits with:
  • 0 - Program terminated with STATUS_SUCCESS
  • 1 - Program terminated with an error status or emulation failed
The final exit status is displayed in green (success) or red (failure).