This change removes many x64-only syscall paths and makes Windows emulation pointer-size aware so x86/WOW64 flows work end-to-end. It introduces shared argument/pointer/IO_STATUS helpers, adds x86 thread/context and TEB/PEB initialization, wires WOW64 gate/system data setup, and implements missing WOW64-related syscalls. It also adds Unicorn GDTR writing support for x86 segment setup and updates runtime messaging to mark WOW64 as experimental. But not all syscalls are fixed and not all backends supports it yet. Only unicorn for now.
Brovan is a powerful user-mode binary emulator for inspecting and running x86_64 programs in a controlled emulated environment. It supports PE, ELF, memory dumps, and even raw files with no recognized file format.
It is a tool used to analyze binaries in an interactive way and discovering what functions they are trying to access, what they are doing, and fully controlling the program inside the emulator.
it is useful for malware analysis, reverse engineering, debugging binaries, or generally understanding what a program is doing, without executing their instructions directly on the host CPU.
Core Features
Brovan supports multiple backends you can choose from depending on your needs. for example, Unicorn for analysis-oriented emulation and KVM for speed, with room for additional backends over time.
🖥️ Multi-format loadingRun PE, ELF, memory dumps, and even raw binaries with no recognized file format. |
🧠 Interactive analysisInspect execution live, follow control flow, and understand what a program is doing as it runs. |
🔎 Syscall & function tracingSee which APIs, syscalls, and functions the target resolves and accesses inside the emulator. |
🛡️ Controlled executionEmulate binaries in a safe sandbox environment without executing them directly on the host CPU. |
🌐 Network traffic dumpingCapture and inspect emulated network activity to better understand program behavior. |
⚙️ Reverse-engineering friendlyUseful for malware analysis, debugging, and general binary inspection workflows. |
And much more ✨
Preview
|
Emulating linux binary (fastfetch) on Windows |
Showing syscalls and functions the binary accesses |
Running raw/unrecognized binaries directly |
|
Dumping emulated network traffic & viewing them |
||
Documentation
The wiki is the main source for:
- Build instructions
- Architecture overview
- Usage guide (recommended, as Brovan have a lot than it advertises and some other useful functionalities)
- Command reference
See the wiki here: https://github.com/AdvDebug/Brovan/wiki
You can also view the FAQ here.
Warning
The Releases page may not always have the latest changes.
For the most up-to-date version, build from source instead or use the latest build from GitHub Actions
Credits
Thanks to Iced library for x86_64 disassembly and assembly.
Thanks to Unicorn Engine for the core emulator.
Thanks to my friend GittingHubbers for help with the MLFQ Scheduler.
License
This software is licensed under GPL-2.0.
