AdvDebug 184107dd99 Refactor guest session IPC for remote processes
Replaced the old `GuestSessionRegistry` request path with a split session model (`GuestSession`, `GuestSessionMailbox`, `RemoteGuestProcess`) and moved remote process operations behind explicit APIs for memory read/write, allocation, thread creation, and termination. This also updates process/thread handle types to use remote-backed objects and wires startup publishing/consumption so spawned guests are only used after their PEB and process parameters are ready.

Process creation and query flows were improved to populate `PS_CREATE_INFO` and `SECTION_IMAGE_INFORMATION` consistently (including PE header parsing in the launcher), and `NtAllocateVirtualMemory` now exposes shared allocation logic used for remote requests.

These changes fixed lots of bugs related to process creation.

Also replaced directory mask regex matching with `FileSystemName.MatchesSimpleExpression` for simpler, culture-invariant wildcard handling.
2026-07-31 20:34:17 +03:00
2026-06-15 23:46:12 +03:00
2026-05-15 05:13:31 +03:00
2026-07-24 13:56:01 +03:00
2026-05-15 05:12:24 +03:00
2026-07-28 20:01:47 +03:00

Brovan banner



.NET Language License

A user-mode x86_64 binary emulator for inspecting programs, tracing syscalls, and safely running untrusted software.

What is Brovan?

Brovan is an interactive x86_64 emulator that gives you full control over how programs execute. It can be used to reverse engineer binaries, trace API and system calls, capture network traffic, or run software in an isolated environment without executing it directly on your host CPU.

It is designed to support as much software as possible while remaining a safe, efficient, and high-performance option for running software across Windows and Linux. Brovan is still in early development, so it is not yet fully mature or reliable.

Supported backends:

  • Unicorn Engine for cross-platform emulation
  • WHP (Windows Hypervisor Platform) for hardware acceleration on Windows
  • KVM (Kernel-based Virtual Machine) for hardware acceleration on Linux

Core Features

MULTI-FORMAT LOADING

Load and execute binaries directly inside the emulator without host installation.

PE   ELF   Memory Dumps   Raw Shellcode

BROVVULK GRAPHICS LAYER

Custom Vulkan translation subsystem handling DXVK calls and game rendering.

DXVK   DirectX   Vulkan Surface

SYSCALL & API TRACING

Inspect execution live to see what functions, DLLs, and kernel calls the program accesses.

Kernel Syscalls   Symbol Resolving   Loaded DLLs

NETWORK DUMPING

Intercept guest socket traffic and export network activity for payload analysis.

Socket Intercept   PCAP Capture   Traffic Analysis

Previews & Demos

Gaming & Graphics (Brovvulk)

Brovan can render guest graphical applications through its Brovvulk translation subsystem. Here is a sample game i had (Deltarune), but it can work on many other games:

Deltarune running in Brovan

Deltarune Bring-up

  • Vulkan surface rendering via Brovvulk
  • DPI-aware host window integration
  • WHP acceleration for a smoother gaming experience

Binary Execution & Tracing

Cross-platform Linux execution
Linux ELF on Windows
Running fastfetch cross-platform
Syscall tracing log
Syscall Tracing
Live logs of API calls and dynamic symbols
Raw binary execution
Raw Binaries
Executing shellcode and memory dumps

Network Inspection

Network dumping
Network Capture
Intercepting guest socket reads and writes
Traffic viewer
Traffic Analyzer
Viewing dumped PCAPs and payloads

Documentation & Wiki

Check out the GitHub Wiki for:

Warning

The Releases page may not always have the latest changes.
For the most up-to-date version, build from source instead or use the latest build from GitHub Actions

Credits

Thanks to Iced library for x86_64 disassembly and assembly.

Thanks to Unicorn Engine for the core emulator.

Thanks to my friend GittingHubbers for help with the MLFQ Scheduler.

License

GPL-2.0

S
Description
Automated archival mirror of github.com/AdvDebug/Brovan
Readme GPL-2.0
15 MiB
Languages
C# 93.7%
C 4.3%
Java 1.6%
Shell 0.3%
Batchfile 0.1%