Skip to content

feat(reactor): Add support for Brotli compressed resources - #44

Merged
meck-gd merged 1 commit into
GDATAAdvancedAnalytics:masterfrom
YagUber:feat/add-reactor-brotli-rc-decompression
Oct 5, 2026
Merged

meck-gd merged 1 commit into
GDATAAdvancedAnalytics:masterfrom
YagUber:feat/add-reactor-brotli-rc-decompression

Conversation

@YagUber

@YagUber YagUber commented Sep 28, 2026

Copy link
Copy Markdown

Adds Brotli support for encrypted .NET Reactor resources.

The resolver previously treated the decrypted payload as either a raw PE, QuickLZ data, or deflate data. My sample’s resource initializer uses BrotliStream(..., Decompress), so none of those paths produced the embedded managed resource.

The resolver now yields raw, QuickLZ, deflate, and Brotli candidates, then accepts the first one dnlib can load as a managed module. Decoder failures are now treated as failed candidates, allowing the remaining formats to be tested. This also removes the old 64 byte/raw header heuristic. The final candidate is now validated by dnlib rather than by header check alone.

.NET Framework 4.8 does not provide System.IO.Compression.BrotliStream, so the change adds a conditional BrotliSharpLib dependency for .NET Framework builds.

@meck-gd

meck-gd commented Oct 5, 2026

Copy link
Copy Markdown

Thanks!

@meck-gd
meck-gd merged commit 02bf591 into GDATAAdvancedAnalytics:master Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants