mirror of
https://github.com/AdvDebug/Brovan
synced 2026-08-09 11:57:17 +00:00
Improved README and added new sections
Updated README with improved formatting, added new sections, and enhanced descriptions of features and documentation.
This commit is contained in:
@@ -1,127 +1,171 @@
|
||||
<div align="center">
|
||||
<img src="./brovan_banner.png" alt="Brovan banner" />
|
||||
|
||||
# Brovan
|
||||
|
||||
*"Emulate like a bro"* - *for your emulation services.*
|
||||
|
||||
[](https://dotnet.microsoft.com/)
|
||||
[](https://learn.microsoft.com/dotnet/csharp/)
|
||||
|
||||
<img src="./brovan_banner.png" alt="Brovan banner" width="100%" style="border-radius: 10px;" />
|
||||
|
||||
<br/><br/>
|
||||
|
||||
[](https://dotnet.microsoft.com/)
|
||||
[](https://learn.microsoft.com/dotnet/csharp/)
|
||||
[](https://www.gnu.org/licenses/gpl-2.0.html)
|
||||
|
||||
<p align="center">
|
||||
<b>A user-mode x86_64 binary emulator for inspecting programs, tracing syscalls, and safely running untrusted software.</b>
|
||||
</p>
|
||||
|
||||
</div>
|
||||
|
||||
Brovan is a powerful user-mode binary emulator for inspecting and running x86_64 programs in a controlled emulated environment. It supports PE, ELF, memory dumps, and even raw files with no recognized file format.
|
||||
## What is Brovan?
|
||||
|
||||
It is a tool used to analyze binaries in an interactive way and discovering what functions they are trying to access, what they are doing, and fully controlling the program inside the emulator.
|
||||
Brovan is an interactive x86_64 emulator that gives you full control over how programs execute. It can be used to reverse engineer binaries, trace API and system calls, capture network traffic, or run software in an isolated environment without executing it directly on your host CPU.
|
||||
|
||||
it is useful for malware analysis, reverse engineering, debugging binaries, or generally understanding what a program is doing, without executing their instructions directly on the host CPU.
|
||||
It is designed to support as much software as possible while remaining a safe, efficient, and high-performance option for running software across Windows and Linux. Brovan is still in early development, so it is not yet fully mature or reliable.
|
||||
|
||||
Supported backends:
|
||||
* **Unicorn Engine** for cross-platform emulation
|
||||
* **WHP** (Windows Hypervisor Platform) for hardware acceleration on Windows
|
||||
* **KVM** (Kernel-based Virtual Machine) for hardware acceleration on Linux
|
||||
|
||||
## Core Features
|
||||
|
||||
Brovan supports multiple backends you can choose from depending on your needs. for example, Unicorn for analysis-oriented emulation and KVM for speed, with room for additional backends over time.
|
||||
|
||||
<div align="center">
|
||||
|
||||
<table>
|
||||
<table width="100%">
|
||||
<tr>
|
||||
<td width="50%" valign="top">
|
||||
<h3>🖥️ Multi-format loading</h3>
|
||||
<p>Run <b>PE</b>, <b>ELF</b>, memory dumps, and even raw binaries with no recognized file format.</p>
|
||||
<td width="50%" valign="top" align="left">
|
||||
<p><b>MULTI-FORMAT LOADING</b></p>
|
||||
<p>Load and execute binaries directly inside the emulator without host installation.</p>
|
||||
<sub><code>PE</code> <code>ELF</code> <code>Memory Dumps</code> <code>Raw Shellcode</code></sub>
|
||||
</td>
|
||||
<td width="50%" valign="top">
|
||||
<h3>🧠 Interactive analysis</h3>
|
||||
<p>Inspect execution live, follow control flow, and understand what a program is doing as it runs.</p>
|
||||
<td width="50%" valign="top" align="left">
|
||||
<p><b>BROVVULK GRAPHICS LAYER</b></p>
|
||||
<p>Custom Vulkan translation subsystem handling DXVK calls and game rendering.</p>
|
||||
<sub><code>DXVK</code> <code>DirectX</code> <code>Vulkan Surface</code></sub>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width="50%" valign="top">
|
||||
<h3>🔎 Syscall & function tracing</h3>
|
||||
<p>See which APIs, syscalls, and functions the target resolves and accesses inside the emulator.</p>
|
||||
<td width="50%" valign="top" align="left">
|
||||
<p><b>SYSCALL & API TRACING</b></p>
|
||||
<p>Inspect execution live to see what functions, DLLs, and kernel calls the program accesses.</p>
|
||||
<sub><code>Kernel Syscalls</code> <code>Symbol Resolving</code> <code>Loaded DLLs</code></sub>
|
||||
</td>
|
||||
<td width="50%" valign="top">
|
||||
<h3>🛡️ Controlled execution</h3>
|
||||
<p>Emulate binaries in a safe sandbox environment without executing them directly on the host CPU.</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width="50%" valign="top">
|
||||
<h3>🌐 Network traffic dumping</h3>
|
||||
<p>Capture and inspect emulated network activity to better understand program behavior.</p>
|
||||
</td>
|
||||
<td width="50%" valign="top">
|
||||
<h3>⚙️ Reverse-engineering friendly</h3>
|
||||
<p>Useful for malware analysis, debugging, and general binary inspection workflows.</p>
|
||||
<td width="50%" valign="top" align="left">
|
||||
<p><b>NETWORK DUMPING</b></p>
|
||||
<p>Intercept guest socket traffic and export network activity for payload analysis.</p>
|
||||
<sub><code>Socket Intercept</code> <code>PCAP Capture</code> <code>Traffic Analysis</code></sub>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
</div>
|
||||
|
||||
<div align="center">
|
||||
<p><strong>And much more ✨</strong></p>
|
||||
</div>
|
||||
## Previews & Demos
|
||||
|
||||
## Preview
|
||||
### Gaming & Graphics (Brovvulk)
|
||||
|
||||
Brovan can render guest graphical applications through its Brovvulk translation subsystem. Here is a sample game i had (Deltarune), but it can work on many other games:
|
||||
|
||||
<div align="center">
|
||||
<table style="border-collapse: separate; border-spacing: 12px 10px;">
|
||||
<tr>
|
||||
<td align="center">
|
||||
<a href="https://github.com/user-attachments/assets/d77b4d0a-6715-4e97-ac0b-f37ef23e37bd">
|
||||
<img src="https://github.com/user-attachments/assets/d77b4d0a-6715-4e97-ac0b-f37ef23e37bd"
|
||||
alt="Brovan preview 1" width="270"
|
||||
style="border-radius: 8px; box-shadow: 0 2px 12px rgba(0,0,0,0.18);" />
|
||||
</a>
|
||||
<br /><sub><i>Emulating linux binary (fastfetch) on Windows</i></sub>
|
||||
</td>
|
||||
<td align="center">
|
||||
<a href="https://github.com/user-attachments/assets/4c264450-e7bd-48ab-85e0-4220ae416c88">
|
||||
<img src="https://github.com/user-attachments/assets/4c264450-e7bd-48ab-85e0-4220ae416c88"
|
||||
alt="Brovan preview 2" width="270"
|
||||
style="border-radius: 8px; box-shadow: 0 2px 12px rgba(0,0,0,0.18);" />
|
||||
</a>
|
||||
<br /><sub><i>Showing syscalls and functions the binary accesses</i></sub>
|
||||
</td>
|
||||
<td align="center">
|
||||
<a href="https://github.com/user-attachments/assets/a3f41dda-fe36-48a9-9ea2-f02b24235d7d">
|
||||
<img src="https://github.com/user-attachments/assets/a3f41dda-fe36-48a9-9ea2-f02b24235d7d"
|
||||
alt="Brovan preview 3" width="270"
|
||||
style="border-radius: 8px; box-shadow: 0 2px 12px rgba(0,0,0,0.18);" />
|
||||
</a>
|
||||
<br /><sub><i>Running raw/unrecognized binaries directly</i></sub>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td colspan="3" align="center">
|
||||
<a href="https://github.com/user-attachments/assets/d0932ff6-08cf-49e5-a48d-70c577352152">
|
||||
<img src="https://github.com/user-attachments/assets/d0932ff6-08cf-49e5-a48d-70c577352152"
|
||||
alt="Brovan preview 4" width="270"
|
||||
style="border-radius: 8px; box-shadow: 0 2px 12px rgba(0,0,0,0.18);" />
|
||||
</a>
|
||||
|
||||
<a href="https://github.com/user-attachments/assets/8bea785c-8f29-4261-8450-97e6b9dd7622">
|
||||
<img src="https://github.com/user-attachments/assets/8bea785c-8f29-4261-8450-97e6b9dd7622"
|
||||
alt="Brovan preview 5" width="270"
|
||||
style="border-radius: 8px; box-shadow: 0 2px 12px rgba(0,0,0,0.18);" />
|
||||
</a>
|
||||
<br /><sub><i>Dumping emulated network traffic & viewing them</i></sub>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
<table width="100%">
|
||||
<tr>
|
||||
<td align="center" width="60%">
|
||||
<a href="https://github.com/user-attachments/assets/d77b4d0a-6715-4e97-ac0b-f37ef23e37bd">
|
||||
<img src="https://github.com/user-attachments/assets/15f11fe6-4f6b-4df1-a568-8be26d1e00d7"
|
||||
alt="Deltarune running in Brovan" width="100%"
|
||||
style="border-radius: 8px; border: 1px solid #30363d;" />
|
||||
</a>
|
||||
</td>
|
||||
<td valign="top" width="40%" align="left">
|
||||
<h4>Deltarune Bring-up</h4>
|
||||
<ul>
|
||||
<li>Vulkan surface rendering via Brovvulk</li>
|
||||
<li>DPI-aware host window integration</li>
|
||||
<li>WHP acceleration for a smoother gaming experience</li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
</div>
|
||||
|
||||
## Documentation
|
||||
### Binary Execution & Tracing
|
||||
|
||||
The wiki is the main source for:
|
||||
<div align="center">
|
||||
|
||||
- Build instructions
|
||||
- Architecture overview
|
||||
- Usage guide (recommended, as Brovan have a lot than it advertises and some other useful functionalities)
|
||||
- Command reference
|
||||
<table width="100%">
|
||||
<tr>
|
||||
<td width="33%" align="center" valign="top">
|
||||
<a href="https://github.com/user-attachments/assets/d77b4d0a-6715-4e97-ac0b-f37ef23e37bd">
|
||||
<img src="https://github.com/user-attachments/assets/d77b4d0a-6715-4e97-ac0b-f37ef23e37bd"
|
||||
alt="Cross-platform Linux execution" width="100%" style="border-radius: 6px;" />
|
||||
</a>
|
||||
<br />
|
||||
<b>Linux ELF on Windows</b>
|
||||
<br />
|
||||
<sub>Running <code>fastfetch</code> cross-platform</sub>
|
||||
</td>
|
||||
<td width="33%" align="center" valign="top">
|
||||
<a href="https://github.com/user-attachments/assets/4c264450-e7bd-48ab-85e0-4220ae416c88">
|
||||
<img src="https://github.com/user-attachments/assets/4c264450-e7bd-48ab-85e0-4220ae416c88"
|
||||
alt="Syscall tracing log" width="100%" style="border-radius: 6px;" />
|
||||
</a>
|
||||
<br />
|
||||
<b>Syscall Tracing</b>
|
||||
<br />
|
||||
<sub>Live logs of API calls and dynamic symbols</sub>
|
||||
</td>
|
||||
<td width="33%" align="center" valign="top">
|
||||
<a href="https://github.com/user-attachments/assets/a3f41dda-fe36-48a9-9ea2-f02b24235d7d">
|
||||
<img src="https://github.com/user-attachments/assets/a3f41dda-fe36-48a9-9ea2-f02b24235d7d"
|
||||
alt="Raw binary execution" width="100%" style="border-radius: 6px;" />
|
||||
</a>
|
||||
<br />
|
||||
<b>Raw Binaries</b>
|
||||
<br />
|
||||
<sub>Executing shellcode and memory dumps</sub>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
See the wiki here: https://github.com/AdvDebug/Brovan/wiki
|
||||
</div>
|
||||
|
||||
You can also view the FAQ <a href="https://github.com/AdvDebug/Brovan/blob/main/FAQ.md">here</a>.
|
||||
### Network Inspection
|
||||
|
||||
<div align="center">
|
||||
|
||||
<table width="100%">
|
||||
<tr>
|
||||
<td width="50%" align="center" valign="top">
|
||||
<a href="https://github.com/user-attachments/assets/d0932ff6-08cf-49e5-a48d-70c577352152">
|
||||
<img src="https://github.com/user-attachments/assets/d0932ff6-08cf-49e5-a48d-70c577352152"
|
||||
alt="Network dumping" width="100%" style="border-radius: 6px;" />
|
||||
</a>
|
||||
<br />
|
||||
<b>Network Capture</b>
|
||||
<br />
|
||||
<sub>Intercepting guest socket reads and writes</sub>
|
||||
</td>
|
||||
<td width="50%" align="center" valign="top">
|
||||
<a href="https://github.com/user-attachments/assets/8bea785c-8f29-4261-8450-97e6b9dd7622">
|
||||
<img src="https://github.com/user-attachments/assets/8bea785c-8f29-4261-8450-97e6b9dd7622"
|
||||
alt="Traffic viewer" width="100%" style="border-radius: 6px;" />
|
||||
</a>
|
||||
<br />
|
||||
<b>Traffic Analyzer</b>
|
||||
<br />
|
||||
<sub>Viewing dumped PCAPs and payloads</sub>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
|
||||
</div>
|
||||
|
||||
## Documentation & Wiki
|
||||
|
||||
Check out the [GitHub Wiki](https://github.com/AdvDebug/Brovan/wiki) for:
|
||||
- [Building from source](https://github.com/AdvDebug/Brovan/wiki/Building-Brovan)
|
||||
- Architecture details
|
||||
- Command reference and usage guides
|
||||
- [FAQ](https://github.com/AdvDebug/Brovan/blob/main/FAQ.md)
|
||||
|
||||
> [!WARNING]
|
||||
> The [Releases](https://github.com/AdvDebug/Brovan/releases) page may not always have the latest changes.
|
||||
@@ -135,5 +179,12 @@ Thanks to <a href="https://github.com/unicorn-engine/unicorn">Unicorn Engine</a>
|
||||
|
||||
Thanks to my friend <a href="https://github.com/GittingHubbers">GittingHubbers</a> for help with the MLFQ Scheduler.
|
||||
|
||||
# License
|
||||
This software is licensed under GPL-2.0.
|
||||
## Credits
|
||||
|
||||
- [Iced](https://github.com/icedland/iced) for x86_64 disassembly/assembly.
|
||||
- [Unicorn Engine](https://github.com/unicorn-engine/unicorn) for core CPU emulation.
|
||||
- Thanks to [GittingHubbers](https://github.com/GittingHubbers) for help with the MLFQ scheduler.
|
||||
|
||||
## License
|
||||
|
||||
GPL-2.0
|
||||
|
||||
Reference in New Issue
Block a user