A Debugging Check is a type of Check that detects whether a debugger is attached to the application.
For example, an attacker might launch the application in a debugger to reverse engineer it, extract sensitive data, or manipulate the application's behavior. A Debugging Check can detect the debugger and react by notifying the application or hindering the attacker.
In other words, Debugging Checks help detect and react to unauthorized debugging of your application.
Configure Debugging Checks
You can configure Debugging Checks in two ways:
- In the source code, add and configure the Check attributes directly in your application.
- In the Config Editor, add the Check and configure its properties and locations.
Both methods allow you to specify the properties that determine how the Check operates.
To configure a Debugging Check in the Config Editor:
- Go to the Checks tab in Dotfuscator’s Config Editor.
- Select Add Debugging Check….
- Configure the Check properties.
- Configure the Check locations.
For the full list of available properties, see the DebuggingCheckAttribute section in Check Attributes.
If you are adding a Tamper Check to a Xamarin Android application, see the Debugging Check for Xamarin Android section in the Enhance Protection article.
Unsupported Application Types
Dotfuscator can inject Debugging Checks into all .NET assemblies except the following:
- .NET Core 3.0 and earlier assemblies
- Xamarin assemblies
- MAUI assemblies
Test Debugging Checks
To test how Debugging Checks react when a debugger is present:
- Run the protected application.
- Attach a debugger to the running application, such as Visual Studio, MDbg, or WinDbg.
- Exercise the locations of your Debugging Checks.
- Observe how the application reacts when the debugger is detected.
A Debugging Check only runs when one of its configured locations is called. If the debugger is attached after that location has already run, the Check does not detect the debugger until the location is called again.