The talk about DEFCON CTF this year on Twitter seems to imply having LLMs allowed in CTF (or, at least, allowing autoslopping without significant restrictions) kinda kills the game. There’s a ton of sentiment about CTF being effectively dead.
back.engineering folks seem to imply that Denuvo is another case of virtualization based obfuscator being vulnerable to a symbolic execution/optimization approach.
> As AI assisted static deobfuscation continues to improve we will see more virtual machine based obfuscators fold away. In an upcoming article we will publish details on how we fully statically devirtualized Denuvo anti(tamper/cheat). One of the most attacked pieces of software second only to anticheats.
…or you can not bother with analyzing at all and just feed correct CPUID/shared data/whatever values to Denuvo, like the hypervisor thing does.
It's not terribly surprising to me that a third-party mod that requires the use of a special kernelspace program only works on Windows.
FWIW, Valve doesn't require use of that system for tournament play and is of the opinion that VAC is sufficient to run a Counterstrike tournament. [0][1]
reply