Files
Senbei/README.md
T
Momoko-Ayase d3dd1a8ff8 Merge Android (AArch64) shared-library restoration, bump to 1.2.0
Adds the Android protection-scheme pipeline: hollowed ELF64/AArch64
libraries are restored statically (stage-1/stage-2 module extraction,
container decode, dynamic-linker table rebuild), with app-package
(.apk/.apks/.xapk) container handling, cross-source content dedup, and
il2cpp metadata support for the Android variants (seeded RID permutation;
embedded XOR-wrapped blob extraction).

The single senbei CLI now routes single .so files, packages, and folders
by content; outputs follow the existing .unpack-infix naming under
<root>/unpack or --out. PE behavior is unchanged (35/35 goldens).
2026-09-02 03:09:21 +08:00

4.2 KiB

Senbei

A static unpacker for Crackproof-protected 64-bit and 32-bit PE files and protected Android (AArch64) shared libraries. Point it at a file, an app package, or a folder and it writes decrypted copies — no launch of the protected program, no kernel driver, no code runs out of the protected binary.

"Crackproof"? It's senbei (煎餅 — rice cracker). Cracks itself.

Senbei reads a protected .exe or .dll, replays the unpacking algorithm entirely in memory, and writes the recovered image to a new file. The core is a pure, panic-free library with no file I/O; the CLI wraps it with scanning, a progress bar, and a run log. A browser version (WebAssembly, fully client-side) lives in web/.

Read this before using Senbei.

  • Senbei is a research and interoperability tool. It exists to enable lawful reverse engineering, security research, preservation, and interoperability with software you already legitimately possess.
  • Only process binaries you own or are explicitly authorized to analyze. Depending on your jurisdiction and license agreements, circumventing technological protection measures may be restricted (for example under DMCA §1201 in the United States, which contains exemptions for security research and interoperability). It is your responsibility to ensure your use is lawful.
  • Senbei does not bypass any access control for you: it performs a purely static transformation of a file already on your disk. It derives everything it needs from the input file itself, contains no vendor code, and distributes no cracks or copyrighted content. (One Android packaging variant's embedded metadata layer is unwrapped with an XOR keystream recovered from a ciphertext/plaintext pair during analysis of a single build; that keystream is research output shipped with the unpacker, not a vendor-distributed key, and builds it doesn't match are left alone.)
  • Senbei does not enable online play, license fraud, or cheating, and must not be used to redistribute decrypted binaries. Do not upload outputs anywhere.
  • The authors provide this software "as is", without warranty of any kind, and accept no liability for misuse. See LICENSE (AGPL-3.0).
  • "Crackproof" is a trademark of its respective owner; this project is not affiliated with or endorsed by the protection vendor or any software publisher. Names are used for identification only.

What it handles

Kind Description
NativeExe Crackproof-protected native executable (PE32+ and PE32).
ManagedExe Protected .NET executable (has a CLR data directory).
NativeDll Protected native (unmanaged) DLL.
ManagedDll Protected .NET assembly (has a CLR data directory).
._ companion Stub + external encrypted payload layout, spliced automatically.
global-metadata.dat il2cpp metadata with obfuscated method tokens, de-obfuscated in place.
Android .so Protected AArch64 shared library, statically restored (hollowed sections + stripped dynamic tables rebuilt).
.apk / .apks / .xapk App packages; protected entries inside are restored, preserving the package's internal layout.

Detection is content-based (header key-table at offset 4096, magic KONN), not extension-based — app packages are the one exception, recognised by extension plus the zip magic because they are containers. Anything unrecognized is left untouched.

Quick start

cargo build --release

senbei protected.exe
:: -> unpack\protected.unpack.exe

senbei game.apk
:: -> unpack\game.apk\lib\arm64-v8a\libil2cpp.unpack.so

senbei "C:\Games\MyGame"
:: -> C:\Games\MyGame\unpack\...  (recursive, skips non-targets)

Every output is sanity-checked statically; structurally broken results are flagged as suspect rather than silently trusted.

Documentation

License

GNU Affero General Public License v3.0 (AGPL-3.0-only).