Status: In use. Public. Apache-2.0. Current release v2.0.0-beta.1, published 18 September 2026.
A framework for inspecting hostile code safely — and for making sure it
cannot tell where it is running.
What it is
Cupelix Sentinel is a security introspection framework for Windows. It exists to inspect
obfuscated, protected and dangerous code — up to and including malware — in an environment
the code cannot fingerprint. Those are two halves of one job: malware routinely profiles the
machine it lands on, and alters or suppresses its behaviour when it decides it is being
watched. An analysis rig that presents a consistent synthetic hardware identity sees the
behaviour the sample would show anywhere else, and keeps the analyst’s real machine identity
out of whatever the sample reports home.
The framework works across four privilege tiers, because the identity a program reads is
assembled at every one of them, and a value corrected in only one place disagrees with
itself. Today’s shipping stack is three components: a UEFI driver that runs before Windows, a
kernel driver it maps in, and one command-line utility that drives both.
What it actually does
Firmware and boot
A UEFI DXE driver that runs before Windows starts, publishes a TCG2 event log, and maps
the kernel driver in without going through Windows’ driver-load path — so code integrity
never gates it and driver signature enforcement is left alone. Secure Boot signing is
bring-your-own-key: without a key the build still produces an image, and firmware refuses it
silently, which is a failure mode the documentation names rather than letting you
discover.
A software TPM 2.0, implemented against the specification rather than against one machine
A RAM-backed CRB transport published through the ACPI namespace, which the Windows TPM
driver binds against — a synthetic TPM for an analysis environment with no physical one.
131 of the 134 TPM 2.0 commands in the TCG Library specification are implemented,
and every one of the 131 is verified against a specific known answer. The three that
are not are the field upgrade and firmware read commands, deliberately omitted: their
authorisation half is buildable and would answer success to a caller whose firmware had not
been replaced, which this codebase counts as a stub. The PC Client specification marks all
three optional, so omitting them is conformant.
The coverage figure is measured, not estimated. The denominator is extracted from the
published TCG specification and the numerator from the source; neither is hand-maintained,
and a disagreement between them fails the build. Every command code in range is additionally
swept for correct refusal and response-header sanity.
Platform identity
Identity presentation across the surfaces a program actually reads: SMBIOS tables before
Windows boots; network adapter addresses through the NDIS and TCP/IP paths; storage serial
numbers through the storage dispatch path; TPM identity; Bluetooth addresses; USB and HID
container identifiers; the registry identifiers Windows publishes; and GPT disk and partition
identifiers.
Deploying it spoofs nothing. The kernel tier stays off until it is armed,
and arming it first proves the pre-OS tier really loaded, then records a baseline from the
still-genuine machine, and only then turns the filter on for every subsequent boot. That
ordering exists because the first clean boot is the only moment a genuine baseline can be
captured, and a tool that waits for the user to think of it has already missed it. Individual
identifiers can be declined one at a time, with the trade stated in the output every time: a
declined row is presented genuine.
It reports what is presented, per surface, as distinct from what is
armed — and it states the limit of that report rather than overselling it. A single
run cannot prove a value is synthetic, because a consistent machine has no second view to
disagree with. Proving it takes a snapshot from before, which is why the tool makes one.
Capture and tracing
Kernel-side enumeration of processes, threads, modules and memory regions, including the
objects that are deliberately not in the lists: processes resolvable by ID but unlinked from
the kernel’s own, and memory regions no loaded module claims — which is what a manually
mapped image looks like. A module can be captured at the instant it loads, before it has
run.
For code that decrypts itself, runs, and re-encrypts, a single read never holds the
plaintext. So a region can be read repeatedly and reassembled page by page by lowest entropy,
which produces the decrypted form a single dump cannot.
Hardware tracing: Intel Processor Trace, with executed basic blocks reconstructed by
walking the target’s own live code in lockstep with the trace packets — so it works on
manually mapped and decrypted code that no file on disk backs. Last Branch Records for
resolving indirect control flow that static analysis cannot see. Branch sampling, per logical
processor, because a hybrid CPU’s cores do not have identical capabilities.
Physical memory reads, page-table walks that name the level a failed walk stopped at, and
parsing of the measured-boot event log. Reads outside system RAM are refused, because reading
device memory can change device state.
The posture
Several of these tools report an honest refusal where another tool would report a
reassuring absence. A surface that cannot be read says so, and says why. A capability that
needs a component that is not loaded says that, rather than reporting nothing found. An empty
result where an empty result is not proof says that too. This is a deliberate trade: a tool
that emits plausible guesses teaches you to ignore it.
Runs offline
No network dependency, no account, no third-party service. Nothing leaves the machine.
The privilege tiers
| Tier | Component | What it provides | State |
|---|---|---|---|
| Pre-OS (UEFI) | PlatformRuntimeDxe.efi |
Runs before Windows. SMBIOS presentation, boot-time hooks, maps the kernel driver, publishes the measured-boot log | Shipping |
| Ring 0 (kernel) | NexusCore.sys |
Capture, tracing, runtime identity presentation. Manually mapped by the UEFI driver | Shipping |
| Ring 3 (usermode) | PlatformCtl.exe |
The control utility: survey, self-test, capture, trace, identity control | Shipping |
| Ring 3 (GUI) | engine.dll + WinForms shell |
The v1 toolset — memory scanner, debugger, disassembler, structure dissector, monitors, C# scripting | Present, unmaintained |
| Ring −1 (hypervisor) | SentinelHV |
VMX, EPT page remapping, hardware-level identity control | v1 work, archived. Planned for a later phase |
Two optional extras ship alongside: a demand-start storage class filter, and a
boot-channel diagnostic.
On the validation target
Sentinel is developed and validated against a commercial anti-cheat: a professionally
built, safe-to-run system that uses the same techniques as real malware — virtual-machine-based
packing, encrypted import tables, anti-debug, hardware fingerprinting and kernel self-defence.
The reasoning is that a tool which cannot fully account for a target of that calibre is not
ready to be pointed at a dangerous one.
The target is deliberately not named, and no measurement of it is published. What is
published is the capability. What the capability finds belongs to whoever runs it.
Support
| Host OS | Target binaries | Architecture | |
|---|---|---|---|
| Supported, measured | Windows 11 x64 [measured] |
Windows PE [measured] |
x86-64 [measured] |
| Not supported | Windows 10 and earlier; Linux; macOS | — | ARM, AArch64 |
[measured] — tested on real hardware. Anything absent from this table is not
supported, and absence is not a roadmap. Windows 10 has not been tested and is therefore not
claimed.
Licence and source
Apache-2.0 throughout, including the UEFI tree, since 17 September 2026. Releases up to
v2.0.0-alpha.4 carried GPL-3.0 for that tree, and nothing withdraws the rights
granted with them.
Third-party code is permissive throughout: HDE64 and MinHook (BSD-2-Clause), Zydis (MIT),
EDK2 (BSD-2-Clause-Patent).
Source: github.com/NovusTechnologyCo/Nexus-Sentinel
Cupelix Sentinel was developed as Nexus Sentinel. The repository and the current build
artifacts still carry the original names.