HyperDbg: Reinventing Hardware-Assisted Debugging
Mohammad Sina Karvandi, MohammadHosein Gholamrezaei, Saleh Khalaj Monfared, Soroush Meghdadi Zanjani, Behrooz Abbassi, Ali Amini, Reza Mortazavi, Saeid Gorgin, Dara Rahmati, Michael Schwarz
Abstract
Software analysis, debugging, and reverse engineering have a crucial impact in today's software industry. Efficient and stealthy debuggers are especially relevant for malware analysis. However, existing debugging platforms fail to address a transparent, effective, and high-performance low-level debugger due to their detectable fingerprints, complexity, and implementation restrictions. In this paper, we present HyperDbg, * a new hypervisor-assisted debugger for high-performance and stealthy debugging of user and kernel applications. To accomplish this, HyperDbg relies on state-of-the-art hardware features available in today's CPUs, such as VT-x and Extended Page Table (EPT). In contrast to other widely used existing debuggers, we design HyperDbg using a custom hypervisor, making it independent of OS functionality or API. We propose hardware-based instruction-level emulation and OS-level API hooking via extended page tables to increase the stealthiness. Our results of the dynamic analysis of 10,853 malware samples show that HyperDbg's stealthiness allows debugging on average 22% and 26% more samples than WinDbg and x64dbg, respectively. Moreover, in contrast to existing debuggers, HyperDbg is not detected by any of the 13 tested packers and protectors. We improve the performance over other debuggers by deploying a VMX-compatible script engine, eliminating unnecessary context switches. Our experiment on three concrete debugging scenarios shows that compared to WinDbg as the only kernel debugger, HyperDbg performs step-in, conditional breaks, and syscall recording, 2.98x, 1319x, and 2018x faster, respectively. We finally show real-world applications, such as a 0-day analysis, structure reconstruction for reverse engineering, software performance analysis, and code-coverage analysis. CCS CONCEPTS • Security and privacy → Virtualization and security; Software security engineering; • Software and its engineering → Compilers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 726eb053-fb31-4619-ae3b-20ff7812c0e6Cited by top-tier papers2
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu et al.CCS 2025
- (M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side ChannelsRuiyi Zhang, Taehyun Kim, Daniel Weber, Michael SchwarzUSENIX Security 2023
Builds on6
- Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine TypesSergej Schumilo, Cornelius Aschermann, Ali Abbasi, Simon Wörner et al.USENIX Security 2021 · 102 citations
- Ninja: Towards Transparent Tracing and Debugging on ARMZhenyu Ning, Fengwei ZhangUSENIX Security 2017 · 62 citations
- Understanding the Security of ARM Debugging FeaturesZhenyu Ning, Fengwei ZhangS&P 2019 · 41 citations
- Happer: Unpacking Android Apps via a Hardware-Assisted ApproachLei Xue, Hao Zhou, Xiapu Luo, Yajin Zhou et al.S&P 2021 · 29 citations
- Reverse Debugging of Kernel Failures in Deployed SystemsXinyang Ge, Ben Niu, Weidong CuiUSENIX ATC 2020 · 29 citations
Related papers
- Obfuscation-Resilient Executable Payload Extraction From Packed MalwareBinlin Cheng, Jiang Ming, Erika A. Leal, Haotian Zhang et al.USENIX Security 2021 · 29 citations
- HyperFuzzer: An Efficient Hybrid Fuzzer for Virtual CPUsXinyang Ge, Ben Niu, Robert Brotzman, Yaohui Chen et al.CCS 2021 · 9 citations
- HyperMirage: Direct State Manipulation in Hybrid Virtual CPU FuzzingManuel Andreas, Fabian Specht, Marius MomeuNDSS 2026
- KRover: A Symbolic Execution Engine for Dynamic Kernel AnalysisPansilu Pitigalaarachchi, Xuhua Ding, Haiqing Qiu, Haoxin Tu et al.CCS 2023 · 4 citations
- Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code PagesSeunghun Han, Seong-Joong Kim, Wook Shin, Byung Joon Kim et al.USENIX Security 2024 · 9 citations
