Java Obfuscation Technique Detector
Scan Java source or decompiled output to identify which obfuscation tool was used. Detects ProGuard, DashO, Zelix KlassMaster, Allatori, and yGuard based on naming conventions, string encryption patterns, annotations, and control flow signatures. Each detection includes confidence scoring, detailed indicator analysis, and code snippet context. Free, private, and no signup required.
Scan Java source or decompiled output to identify the obfuscation tool used. Detects ProGuard, DashO, Zelix KlassMaster, Allatori, and yGuard based on naming conventions, string encryption patterns, annotations, and control flow signatures with confidence scoring.
Paste Java source code (or decompiled output) above and click Detect Obfuscation to identify which obfuscation tool was used. The detector analyzes naming conventions, string encryption patterns, annotations, and control flow signatures to identify ProGuard, DashO, Zelix KlassMaster, Allatori, and yGuard. Try loading an example to see how it works!
Features
5 Major Java Obfuscator Detectors
Automatically scans for ProGuard (single-letter naming, a$b inner classes), DashO (com.preemptive.* imports, integer array encryption), Zelix KlassMaster (char array XOR, hashed identifiers), Allatori (Roman numeral naming, repeated-letter classes), and yGuard (underscore-obfuscated names, map references). Each detector uses specialized pattern matching tuned to the obfuscator's unique signatures.
Confidence Scoring & Detailed Indicators
Every detection includes a confidence rating from 1-5 (Low to Very High) based on indicator strength and quantity. Strong evidence like explicit obfuscator annotations or matching renaming schemes scores higher. The tool lists every individual indicator with type, description, strength score, and the matching code snippet.
Multiple Detection Categories per Obfuscator
Each obfuscator detector checks multiple categories: class/method renaming patterns, string encryption techniques (char arrays, integer arrays, XOR), annotation markers, import references, control flow patterns, and metadata artifacts. This multi-faceted approach ensures accurate identification even when only partial obfuscation evidence is present.
100% Browser-Local & Private
All Java obfuscation detection runs entirely in your browser. Your Java code, all detected indicators, and analysis results never leave your device. No server uploads, no API calls, no data storage, and no tracking. Completely safe for analyzing proprietary Java applications or decompiled third-party code.
Use Cases
Security Analysis of Obfuscated Java Applications
Identify which obfuscation tool was used on a Java application to inform your deobfuscation strategy. Knowing whether ProGuard, DashO, Zelix KlassMaster, Allatori, or yGuard was applied helps security researchers choose the right tools and techniques for further analysis.
Malware & Backdoor Analysis
Analyze decompiled Java malware samples to determine the obfuscation technique used. Many Java-based trojans and backdoors use specific obfuscators to evade detection. Identifying the obfuscator helps incident responders understand the complexity of deobfuscation needed.
Reverse Engineering & Deobfuscation Planning
Before attempting to deobfuscate a Java application, use this detector to understand what you are dealing with. Each obfuscator requires a different approach - ProGuard output is easily decompilable, while Zelix KlassMaster and DashO require more advanced techniques.
Code Auditing & Intellectual Property Analysis
During security audits of Java vendors and third-party libraries, detect whether commercial obfuscators like DashO or Zelix KlassMaster have been applied. This helps assess the level of effort required for a thorough code review and identifies potential licensing compliance issues.
Educational Tool for Java Obfuscation Techniques
Learn to recognize the distinctive signatures of different Java obfuscation tools. Understand how ProGuard renames classes to single letters, how DashO encrypts strings as integer arrays, and how Allatori uses Roman numeral-style class names. Each example demonstrates real obfuscated code patterns.
Third-Party Library Risk Assessment
When evaluating third-party Java libraries in your supply chain, scan decompiled JAR contents for obfuscation signatures. Heavy obfuscation can be a red flag indicating malware, stolen code, or attempts to hide malicious behavior in Java dependencies.
About Java Obfuscation Detection
What is Java Obfuscation Detection?
Java obfuscation detection is the process of analyzing Java bytecode or decompiled source code to identify which obfuscation tool was used to protect it. Different Java obfuscators leave distinctive signatures in the code they process - unique naming conventions, specific string encryption patterns, custom annotations, and characteristic control flow structures. By recognizing these signatures, security researchers, developers, and reverse engineers can determine the obfuscator in use and plan their deobfuscation approach accordingly. This tool analyzes decompiled Java code for patterns from five major Java obfuscators: ProGuard, DashO, Zelix KlassMaster, Allatori, and yGuard.
How Our Detection Works
The detector runs five specialized scanners, one for each supported obfuscator, against the provided Java code. Each scanner uses multiple detection strategies: class and method naming pattern analysis (e.g., single-letter names for ProGuard, Roman numeral names for Allatori), string encryption technique identification (e.g., integer arrays for DashO, char array XOR for Zelix KlassMaster), annotation detection (e.g., @Obfuscate for DashO, @Keep for ProGuard), import reference scanning (e.g., com.preemptive.* for DashO), and control flow pattern analysis. Each indicator is scored by strength, and the overall confidence for each obfuscator is calculated from the number and quality of matching indicators.
The Five Supported Java Obfuscators
ProGuard is the most widely used free Java obfuscator, known for renaming classes to single letters (a, b, c) and methods to a(), b(). DashO by PreEmptive Solutions uses integer array string encryption and imports from com.preemptive.*. Zelix KlassMaster employs char array XOR decryption patterns and hashed hex identifiers like _0001. Allatori uses distinctive Roman numeral-style class names (I, II, III, IV) and repeated-letter methods (a, aa, aaa). yGuard uses underscore-prefixed obfuscated names and preserves line number tables by default. Each leaves unique traces in decompiled output.
Privacy & Security
This tool runs entirely in your browser using client-side JavaScript. The Java code you paste, all detected obfuscation indicators, and analysis results are never uploaded to any server, stored in any database, or transmitted over the network. All pattern matching, signature analysis, and scoring execute locally on your device. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it safe for analyzing proprietary Java applications, commercial software, or potentially malicious code samples.
Related Deobfuscation Tools
Go Deobfuscator / Symbol Restorer
Detect and reverse Go obfuscation: short identifiers, hex escapes, Base64 strings, XOR cipher patterns, and obfuscated numeric literals.
Binary Data Unpacker
Detect and unpack obfuscated binary data. Supports Base64, hex, XOR, GZIP, and more with confidence scoring.
Obfuscated Text Diff & Comparison
Compare two text versions to detect invisible differences: zero-width characters, homoglyph substitutions, and Unicode tricks.
Integer Obfuscator
Obfuscate integers using base conversion, arithmetic expressions, and bitwise operations. Perfect for protecting magic numbers.
Frequently Asked Questions About Java Obfuscation Detection
The tool can detect five major Java obfuscators: ProGuard (the most popular free obfuscator), DashO (by PreEmptive Solutions), Zelix KlassMaster, Allatori, and yGuard. Each obfuscator has unique signatures in the decompiled code. ProGuard uses single-letter names, DashO uses com.preemptive.* annotations and integer array encryption, Zelix KlassMaster uses char array XOR patterns, Allatori uses Roman numeral names, and yGuard uses underscore prefix naming.
Accuracy depends on how much obfuscated code is available to analyze. Strong indicators like explicit obfuscator annotations (@Keep, @Obfuscate), imports (com.preemptive.*), or extremely distinctive naming patterns (single-letter classes for ProGuard, Roman numeral classes for Allatori) give Very High confidence. Weaker indicators like missing package declarations or preserved line number tables give lower confidence scores. The tool ranks each obfuscator with a confidence rating from 1 (Low) to 5 (Very High).
Paste decompiled Java source code from tools like CFR, Procyon, or JD-GUI. The tool analyzes the decompiled output for naming patterns, string encryption methods, annotations, import statements, and control flow structures. Original source code that has not been obfuscated will typically not trigger any detections. For best results, paste at least one class with methods and fields.
No. This tool only recognizes the five supported obfuscators (ProGuard, DashO, Zelix KlassMaster, Allatori, yGuard). Custom obfuscators or lesser-known tools will not be detected. If no obfuscation is detected, the code may be unobfuscated, or it may use a different obfuscation tool not covered by this detector.
Each obfuscator has unique characteristics that differentiate it. For example, both ProGuard and yGuard use short naming, but ProGuard uses a$b inner class patterns while yGuard uses underscore prefixes. DashO leaves distinctive com.preemptive.* imports. Allatori uses Roman numeral names that no other obfuscator produces. Zelix KlassMaster uses hex-style hashed identifiers alongside char array XOR patterns. The tool checks multiple indicator types for each obfuscator, reducing false positives.
No - the tool analyzes decompiled Java source code, not raw bytecode. To use it, first decompile your JAR or APK file using a Java decompiler like CFR, Procyon, JD-GUI, or JADX, then paste the resulting Java source code into this tool. The naming patterns and string encryption signatures are preserved in decompiled output.
ProGuard has extensive configuration options. If ProGuard was configured with -dontobfuscate, -dontshrink, or custom -keep rules that preserve original names, the obfuscated output may retain meaningful class and method names. Additionally, ProGuard with -useuniqueclassmembernames or -overloadaggressively uses different naming patterns. The default single-letter naming is what the tool primarily detects.
Yes, absolutely. The Java obfuscation detector runs entirely in your browser. Your Java code, all detected indicators, and analysis results are never uploaded to any server or transmitted over the network. All processing happens locally on your device with no API calls or data collection. You can safely analyze proprietary Java applications, commercial software, or any other Java code.
Yes - 100% free with no signup, no account, and no usage limits. Analyze as much Java code as you need, as many times as you want. There are no premium tiers, hidden charges, or rate limits. The tool runs entirely in your browser - your code never leaves your device.