Modern malware increasingly relies on packing, process injection, self-modifying code, and anti-analysis techniques that challenge traditional dynamic analysis platforms. Existing approaches often force analysts to choose between fine-grained execution visibility and stealth, while many advanced solutions remain proprietary, difficult to reproduce, or poorly suited for extracting reusable low-level execution traces for research and reverse purposes.
In this paper, we present GoaTracer, an open-source dynamic binary analysis platform for Windows that combines in-guest binary instrumentation with hypervisor-level virtual machine introspection. This hybrid architecture provides instruction-level visibility while limiting the observable footprint exposed to the analyzed program, improving resistance against common anti-analysis and anti-debugging mechanisms.
Beyond execution tracing, GoaTracer is designed as a low-level analysis foundation from which higher-level semantic information can be reconstructed automatically. The platform introduces a wave-based execution model that isolates dynamically generated execution stages and enables the reconstruction of unpacked binaries, shellcodes, control-flow graphs, call graphs, and behavioral artifacts associated with malware activity. GoaTracer also captures system interactions with parameters and maps observed behaviors to MITRE ATT&CK and Malware Behavior Catalog (MBC) techniques.
We describe the architecture and implementation of GoaTracer and demonstrate its practical capabilities through the analysis of the ClaimLoader malware, showing how the platform reconstructs multi-stage execution flows, extracts intermediate payloads, and reveals behaviors that remain difficult to observe with conventional dynamic analysis systems.