AdvDebug 2dd672f4bd Add DPI awareness and guest process launch
# DPI awareness

The emulator gave every program a screen of 96 DPI. It also made the host
window with no DPI awareness. A program that asks for a different DPI got
the wrong screen size and a window that is not sharp.

The emulator now reads the DPI awareness of the program. It reads it from
the application manifest in the image, from an external manifest file, or
from the NtUserSetProcessDpiAwarenessContext system call.

user32 does not ask the kernel for most DPI values. It calculates them
from a packed value in the CLIENTINFO block of the thread and in the
window structure. The emulator writes this value into the two locations.
If it does not, the program reads one DPI from user32 and a different DPI
from the system calls.

The emulator gives the same awareness to the host window. An aware program
gets a window in true pixels. An unaware program keeps the window that the
desktop manager makes larger for it.

The emulator also sets the composited flag in the desktop data. Without
this flag, user32 uses a different code path. That path gives 96 DPI to a
program that is aware.

# Guest process launch

A guest process could not start a different program. The emulator did not
have the NtCreateUserProcess system call. DELTARUNE stopped at its menu
for this reason. The game starts a new process when you select a chapter.

The emulator now starts a second Brovan for each new guest process. One
guest process is one host process. The window manager, the Vulkan device,
the scheduler and the caches are global to a process. Two guests in one
emulator need a process identity in all of them. The host operating system
gives this isolation at no cost.

The parent sends the image path, the command line and the directory to the
child. It encodes these values with base64. Without base64, the host
command line divides the values and joins them again. A value with a
quotation mark or a space does not stay correct.

# Session registry

The Brovan instances of one session share a table in a memory-mapped file.
Each instance writes one row. An instance that must stop a different guest
process writes a request into the row of that process. The owner of the row
reads the request and stops itself. This is the only correct method. The
memory of that process is in a different host process.

The emulator counts the rows before it starts a child. It permits a maximum
of six guest processes in one session.

# New options

--cwd <dir> sets the directory in which the program starts.
--guest-cmdline <s> sets the command line of the program.
The two options also accept a value in the form "base64:<value>".
2026-07-27 23:25:06 +03:00
2026-06-15 23:46:12 +03:00
2026-05-15 05:13:31 +03:00
2026-06-07 15:24:15 +03:00
2026-07-24 13:56:01 +03:00
2026-06-07 15:30:19 +03:00
…
2026-06-29 15:21:32 +03:00

Brovan banner

Brovan

"Emulate like a bro" - for your emulation services.

.NET Language

Brovan is a powerful user-mode binary emulator for inspecting and running x86_64 programs in a controlled emulated environment. It supports PE, ELF, memory dumps, and even raw files with no recognized file format.

It is a tool used to analyze binaries in an interactive way and discovering what functions they are trying to access, what they are doing, and fully controlling the program inside the emulator.

it is useful for malware analysis, reverse engineering, debugging binaries, or generally understanding what a program is doing, without executing their instructions directly on the host CPU.

Core Features

Brovan supports multiple backends you can choose from depending on your needs. for example, Unicorn for analysis-oriented emulation and KVM for speed, with room for additional backends over time.

🖥️ Multi-format loading

Run PE, ELF, memory dumps, and even raw binaries with no recognized file format.

🧠 Interactive analysis

Inspect execution live, follow control flow, and understand what a program is doing as it runs.

🔎 Syscall & function tracing

See which APIs, syscalls, and functions the target resolves and accesses inside the emulator.

🛡️ Controlled execution

Emulate binaries in a safe sandbox environment without executing them directly on the host CPU.

🌐 Network traffic dumping

Capture and inspect emulated network activity to better understand program behavior.

⚙️ Reverse-engineering friendly

Useful for malware analysis, debugging, and general binary inspection workflows.

And much more ✨

Preview

Brovan preview 1
Emulating linux binary (fastfetch) on Windows
Brovan preview 2
Showing syscalls and functions the binary accesses
Brovan preview 3
Running raw/unrecognized binaries directly
Brovan preview 4     Brovan preview 5
Dumping emulated network traffic & viewing them

Documentation

The wiki is the main source for:

  • Build instructions
  • Architecture overview
  • Usage guide (recommended, as Brovan have a lot than it advertises and some other useful functionalities)
  • Command reference

See the wiki here: https://github.com/AdvDebug/Brovan/wiki

You can also view the FAQ here.

Warning

The Releases page may not always have the latest changes.
For the most up-to-date version, build from source instead or use the latest build from GitHub Actions

Credits

Thanks to Iced library for x86_64 disassembly and assembly.

Thanks to Unicorn Engine for the core emulator.

Thanks to my friend GittingHubbers for help with the MLFQ Scheduler.

License

This software is licensed under GPL-2.0.

S
Description
Automated archival mirror of github.com/AdvDebug/Brovan
Readme GPL-2.0
15 MiB
Languages
C# 93.7%
C 4.3%
Java 1.6%
Shell 0.3%
Batchfile 0.1%