> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/sogen.md).

# Sogen

Sogen is an open source emulator that "runs Windows and Linux programs without a real operating system, and lets you see and control everything they do." Sogen does not reimplement the Windows API. It emulates the program at the CPU and syscall level and runs the real system DLLs, such as ntdll, kernel32, and user32, so the behavior is close to a real Windows system. It supports PE loading with relocations and TLS, SEH, threads, the registry, the file system, and networking.

Sogen is a good sandbox for interactive analysis. The sample runs in the emulator and cannot access your host. Its files come from an emulation root, a directory that contains a virtual `C:` drive and a registry. Runs are deterministic, so when you restart a session the sample does the same things again. Sogen can also hook each instruction, memory access, and API call.

Sogen is licensed under the [GPL-2.0](https://github.com/momo5502/sogen/blob/main/LICENSE). The source is at [github.com/momo5502/sogen](https://github.com/momo5502/sogen), and you can try it in a browser at [sogen.dev](https://sogen.dev).

## How the add-on uses Sogen

The add-on includes a prebuilt Sogen analyzer and an emulation root in the `ida-sogen-runtime` dependency. The analyzer is available for Windows x86-64, Linux x86-64, Linux AArch64, and macOS on Apple silicon. The add-on runs the analyzer as a separate process and does not load it into IDA.

For [isolated system emulation](/ida-9.5/add-ons/malware/concepts/isolated-system-emulation.md), set the `backend` setting to `sogen`. The add-on copies the sample into the emulation root as `C:\<file name>`, starts the analyzer with a GDB server on `127.0.0.1`, and connects IDA's remote GDB debugger to it. Sogen runs 64-bit PE files, and 32-bit PE files through WOW64. The `sogen_root` and `sogen_analyzer` settings select a different emulation root or analyzer.

For [automated unpacking](/ida-9.5/add-ons/malware/concepts/automated-unpacking.md), set `default_debugger` to `sogen`. The unpacker then starts Sogen through the isolated system emulator and runs its heuristics on the emulated process.

Sogen is not a backend for [sandbox integration](/ida-9.5/add-ons/malware/concepts/sandbox-integration.md). To import a trace from an emulator, use [Speakeasy](/ida-9.5/add-ons/malware/concepts/speakeasy.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/sogen.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
