Hack.lu 2026

GoaTracer: A Hybrid Dynamic Analysis Platform

Modern malware increasingly relies on packing, process injection, self-modifying code, and anti-analysis techniques that challenge traditional dynamic analysis platforms. Existing approaches often force analysts to choose between fine-grained execution visibility and stealth, while many advanced solutions remain proprietary, difficult to reproduce, or poorly suited for extracting reusable low-level execution traces for research and reverse purposes.

In this paper, we present GoaTracer, an open-source dynamic binary analysis platform for Windows that combines in-guest binary instrumentation with hypervisor-level virtual machine introspection. This hybrid architecture provides instruction-level visibility while limiting the observable footprint exposed to the analyzed program, improving resistance against common anti-analysis and anti-debugging mechanisms.

Beyond execution tracing, GoaTracer is designed as a low-level analysis foundation from which higher-level semantic information can be reconstructed automatically. The platform introduces a wave-based execution model that isolates dynamically generated execution stages and enables the reconstruction of unpacked binaries, shellcodes, control-flow graphs, call graphs, and behavioral artifacts associated with malware activity. GoaTracer also captures system interactions with parameters and maps observed behaviors to MITRE ATT&CK and Malware Behavior Catalog (MBC) techniques.

We describe the architecture and implementation of GoaTracer and demonstrate its practical capabilities through the analysis of the ClaimLoader malware, showing how the platform reconstructs multi-stage execution flows, extracts intermediate payloads, and reveals behaviors that remain difficult to observe with conventional dynamic analysis systems.


Modern malware increasingly relies on packing, process injection, self-modifying code, and anti-analysis techniques to evade conventional dynamic analysis platforms. Existing systems generally force analysts to choose between fine-grained execution visibility and stealth: in-guest instrumentation frameworks expose rich execution details but introduce detectable artifacts, while hypervisor-based approaches provide stronger transparency at the cost of reduced semantic visibility. In addition, many advanced analysis platforms remain proprietary or difficult to extend, limiting reproducibility and experimentation for the research community.

This presentation introduces GoaTracer, an open-source hybrid dynamic analysis platform for Windows designed to bridge this gap. GoaTracer combines in-guest binary instrumentation with hypervisor-level virtual machine introspection to achieve instruction-level visibility while significantly reducing the analysis footprint observable by the monitored program.

A key design objective of GoaTracer is not only to trace execution, but also to provide reusable low-level execution data from which higher-level semantic information can be reconstructed automatically. To this end, the platform introduces a wave-based execution model that identifies and isolates successive layers of dynamically generated code. This mechanism enables the extraction and reconstruction of unpacked binaries, injected shellcodes, and other write-then-execute artifacts commonly used by modern malware.

Beyond code reconstruction, GoaTracer rebuilds control-flow and call graphs, captures system interactions together with their parameters, detects anti-analysis and anti-debugging mechanisms, and maps observed behaviors to MITRE ATT&CK techniques and Malware Behavior Catalog (MBC) categories. The resulting traces and reconstructed artifacts can be reused for reverse engineering, behavioral analysis, malware clustering, or downstream research tasks.

The presentation will detail the architecture and design choices behind GoaTracer, discuss how its hybrid instrumentation/introspection model addresses limitations of existing dynamic analysis systems, and demonstrate its practical capabilities through the analysis of the ClaimLoader malware. The case study illustrates how GoaTracer reconstructs multi-stage execution flows, uncovers persistence and command-and-control mechanisms, and extracts intermediate payloads that would otherwise remain difficult to analyze.

The talk will be of interest to malware analysts, reverse engineers, threat researchers, and practitioners interested in advanced dynamic analysis, malware unpacking, and low-level behavioral reconstruction. GoaTracer is publicly available to the community at:

https://goatracer.lhs.loria.fr/

Pierre MARTY

I am Pierre MARTY, a research engineer working for the LORIA in France.
My topics of interest are static and dynamic malware analysis, and cybersecurity in
general.

Fabrice Sabatier
ROYER