Tigress

B
B tier on Code Obfuscation SoftwareScore 7.3 · #2 of 33
Android app
Yes
Free plan
Yes
Runs on
Android, Linux, Mac, Windows
tigress.wtf
The Tigress homepage

Summary

Tigress is a command-line obfuscator for C that transforms source code to make static and dynamic reverse engineering harder. Users apply sequences of transformations and options to generate new C source, and the same input can produce different outputs. Documented transformation groups include control flow, data, functions, integrity, and anti-analysis. Listed targets include Linux, Darwin, Android, Windows, Intel, ARM, and WebAssembly, with 32- and 64-bit output; cross-compilation is set through Compiler and Environment options. Tigress accepts one C file as input, so a program made from multiple files needs to be merged before transformation. The maker lists support for C99 source and GCC, Clang, Emscripten, and cl. Nonprofit organizations can use it for 0.00 USD per free. Commercial deployment by a for-profit organization requires a license from the University of Arizona; no price is listed for that license, and users may try Tigress for any length of time before deployment. The source is not generally open source, though it may be shared with university or research-lab researchers on request. Tigress is also presented for student learning and reverse-engineering research. The maker notes that generated code can be slow, particularly for huge programs, and performance depends on the transformations and options selected.

Who it is for

It suits software-protection developers, students learning obfuscation, and researchers studying reverse engineering. Nonprofit organizations can use it without a listed charge.

What is good

  • One input can produce multiple obfuscated outputs
  • Includes control-flow and anti-analysis transformations
  • Supports listed Linux, Darwin, Android, and Windows targets
  • Cross-compilation uses target compiler and environment options
  • Nonprofit use is free

What to know first

  • Accepts only one C file as input
  • Generated code can be slow, especially for huge programs
  • For-profit deployment requires a University of Arizona license
  • Source is not generally open source

Everything Xiaomi review

Tigress: the full review

Tigress offers varied C transformations and target options for research and software protection, but its single-file input and performance caveats matter. For-profit use requires arranging a license before deployment.

Tigress is a command-line C obfuscator for researchers, students and teams that build software from C source. Its transformation range and output diversity offer useful control, though fitting it into a build means handling single-file input and weighing performance costs.

Overview

Tigress transforms C source through sequences of command-line transformations and options. One input can produce multiple distinct outputs, a practical advantage for creating varied builds rather than distributing the same transformed program each time. Its documented transformation families span control flow, data, functions, integrity and anti-analysis; supported capabilities also include anti-tamper controls and string encryption.

This is not a drop-in fit for every C project. Tigress takes one C file, so a program split across multiple files must be merged before transformation. Output can run slowly, especially for huge programs, and the impact depends on the transformations and options chosen. Protection decisions should account for protected assets, performance budgets and the capabilities of the adversary being considered.

Key features

  • Diversified output: Multiple outputs from the same source can make builds less uniform, which suits software-protection work that values variation.
  • Transformation choice: Control-flow, data, function, integrity and anti-analysis transformations let users select among different ways to complicate analysis. String encryption and anti-tamper controls broaden the available protection techniques.
  • Targets and cross-compilation: Tigress supports Linux, Darwin, Android and Windows, Intel and ARM, and WebAssembly. Cross-compilation uses its Compiler and Environment options, making target selection explicit in the command-line workflow.
  • Research use: The developer encourages researchers to attack Tigress-generated code and compare protection techniques, and presents it as a way for students to study obfuscation and build reverse-engineering challenges.

Pricing

The Research use plan costs 0.00 USD per free for nonprofit organizations. It is a strong fit for academic research and student learning, but does not cover commercial deployment by a for-profit organization.

The Commercial license has custom pricing and is required for use in a for-profit organization. Contact the University of Arizona licensing department to arrange it. Users may try Tigress for any length of time before deployment, but that trial flexibility does not remove the licensing requirement for commercial use.

Tigress is self-hosted and driven through a command-line interface. Its source is not generally open source, though the maker may share it with researchers at universities or research labs on request.

Platforms

Tigress transforms C99 source and supports Linux, Darwin, Android and Windows targets, with Intel and ARM architectures and WebAssembly output. Supported compiler options include GCC, Clang, Emscripten and cl. Its cross-compilation settings make it relevant when the build target differs from the environment used to run the transformation.

Who it's for

Tigress is best suited to nonprofit researchers, students and software-protection practitioners comfortable with command-line workflows and C build processes. The range of transformations and ability to produce varied outputs are especially relevant to studying reverse engineering or evaluating protection strategies. Developers with multi-file codebases should be prepared to merge inputs, and teams with tight runtime budgets should consider whether the generated code's potential slowdown is acceptable.

For-profit teams need to arrange a license before deployment. The developer, Christian Collberg, is a professor in the University of Arizona Department of Computer Science and offers consulting, including for unsupported features or target platforms.

Pros and cons

  • Pro — varied transformed builds: The same input can yield multiple outputs, useful when one fixed transformed version is not enough.
  • Pro — broad target range: Linux, Darwin, Android, Windows and WebAssembly targets cover varied deployment environments.
  • Pro — research-friendly positioning: The developer encourages attacks and comparisons of Tigress-generated code, making it pertinent to obfuscation research and education.
  • Con — single-file input: Multi-file programs must be merged first, adding preparation work to the build process.
  • Con — performance uncertainty: Generated code can be slow, and huge programs are a known concern; teams need to assess the cost for their selected transformations.
  • Con — commercial license required: For-profit deployment requires a separately arranged license, so commercial teams cannot assume the free nonprofit plan applies.

Alternatives

For a broader platform mix and a free individual-developer option, consider ByteHide Shield, whose free plan is described as core obfuscation for individual developers and small projects; its paid plans cover advanced techniques at custom pricing.

If open-source JavaScript obfuscation is the priority, JS-Confuser is a free option described by its maker as open source. JavaScript Obfuscator is another free JavaScript choice, with unlimited standard obfuscation but a 25 MB lifetime VM quota and 4 MB VM file-size limit on its free plan.

Obfuscator.io is an alternative. Allatori is an alternative. DashO is an alternative. Redgate SQL Provision is an alternative. .NET Reactor is an alternative.

Verdict

Choose Tigress if you need configurable C obfuscation, varied outputs and a target range suited to research or software protection. Its nonprofit access and transformation breadth are compelling for academic and experimental work; multi-file preparation, potential slowdown and the required commercial license make it less suitable for teams seeking effortless integration or straightforward commercial deployment.

Tigress plans and pricing

All plans
Research use Free Free for non-profit organizations tigress.wtf · 4 Oct 2026
Commercial license Not published Contact the University of Arizona licensing department for a license Required for use in a for-profit organization tigress.wtf · 4 Oct 2026

Compared on code obfuscation software

Free plan
Notigress.wtf
Supported targets
C99 source; Linux, Darwin, Android, Windows; Intel and ARM; WebAssembly; GCC, Clang, Emscripten, and cltigress.wtf
Anti-tamper controls
Yestigress.wtf
Control-flow obfuscation
Yestigress.wtf
String encryption
Yestigress.wtf
Deployment model
self_hostedtigress.wtf
Build integration
clitigress.wtf

Facts

Purpose
Tigress is a diversifying obfuscator for C designed to defend against static and dynamic reverse engineering.tigress.wtf · 4 Oct 2026
How it works
It transforms C source code into new C source code according to sequences of command-line transformations and options.tigress.wtf · 4 Oct 2026
Output variety
A single input program can produce multiple different output programs.tigress.wtf · 4 Oct 2026
Targeting
The site lists Linux, Darwin, Android, and Windows, plus Intel, Arm, and WebAssembly targets and 32- and 64-bit output.tigress.wtf · 4 Oct 2026
Nonprofit use
Tigress is free to use for non-profit organizations.tigress.wtf · 4 Oct 2026
Commercial licensing
Commercial use in a for-profit organization requires a license from the University of Arizona; users can try Tigress for any length of time before deployment.tigress.wtf · 4 Oct 2026
Source availability
The source is not generally open source; the maker says it may be shared with researchers at universities or research labs on request.tigress.wtf · 4 Oct 2026
Research audience
The maker encourages reverse-engineering researchers to attack Tigress-generated code and software-protection researchers to compare techniques against its transformations.tigress.wtf · 4 Oct 2026
Student use
The maker presents Tigress as a tool for students to learn code obfuscation and create reverse-engineering challenges.tigress.wtf · 4 Oct 2026
Commercial support
The maker offers consulting and invites users to contact them about unsupported features or target platforms.tigress.wtf · 4 Oct 2026
Known limitation
The issues page lists Tigress as slow on huge programs.tigress.wtf · 4 Oct 2026
Security guidance
The maker says users should conduct a detailed security analysis before using software-protection techniques, including assessing protected assets, performance budget, and adversary capabilities.tigress.wtf · 4 Oct 2026
Diversification
The same input program can be transformed into multiple different output programs.tigress.wtf · 4 Oct 2026
Transformation families
Its documented transformations include control flow, data, functions, integrity, and anti-analysis transformations.tigress.wtf · 4 Oct 2026
Target platforms
The site lists Linux, Darwin, Android, and Windows targets, with Intel, ARM, and WebAssembly architectures.tigress.wtf · 4 Oct 2026
Cross-compilation
Tigress supports cross-compilation by setting the target with its Compiler and Environment options.tigress.wtf · 4 Oct 2026
Whole-program input
Tigress accepts one C file as input, so programs made of multiple files must be merged before transformations.tigress.wtf · 4 Oct 2026
Performance
The maker notes that generated code can be slow and that performance depends on the chosen transformations and options.tigress.wtf · 4 Oct 2026
Commercial use
There is no restriction on how long users can try Tigress, but commercial deployment requires contacting the maker about a license.tigress.wtf · 4 Oct 2026
Consulting and support
The maker offers consulting and invites users to get in touch about unsupported features or target platforms.tigress.wtf · 4 Oct 2026
Maker
Christian Collberg identifies himself as Tigress's primary developer and a professor in the University of Arizona Department of Computer Science.tigress.wtf · 4 Oct 2026

Best Tigress alternatives

See all 20

Where it ranks on Everything Xiaomi

Is Tigress yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources