PRJ-001 / ENGINEERING BRIEF

loupe

emulation-based malware deobfuscator and unpacker

RECORD PRJ-001 STATUS ACTIVE INITIATED 2026 CLASS SOFTWARE
INDEX TERMS gounicornmalware-analysis
PROJECT DOSSIER / LOUPE PRJ-001
MISSION

Loupe is an emulation-based malware deobfuscator and unpacker. It is designed to let suspicious code reveal itself inside an instrumented environment without granting it control of a complete operating system.

The project is also a practical study of Portable Executable internals, low-level execution, and the boundary between static and dynamic malware analysis.

SYSTEM ARCHITECTURE FLOW / PRIMARY
01 PE INPUT
02 PARSER
03 IAT PATCHER
04 EMULATION HARNESS
05 UNPACKED OUTPUT
CAPABILITIES 3 MODULES
CAP-01

inspect

Parse PE headers, sections, imports, and execution context before emulation.

CAP-02

instrument

Patch imports and intercept behavior inside a controlled Unicorn Engine harness.

CAP-03

recover

Observe execution and extract a cleaner artifact for further analysis.

DEVELOPMENT STATUS ACTIVE
CURRENT PHASE

Building the emulator scaffold and establishing reliable import-address-table patching.

NEXT DIRECTIVE

Run the first complete sample through the parse, patch, emulate, and recover pipeline.