Cupelix is the security tooling line of Novus Technology.
A cupel is the vessel used in fire assay: you put an impure sample in it, drive off
everything that is not the metal you are looking for, and what remains is what was really
there. That is what this toolchain does to a hostile binary — separate the behaviour from
the obfuscation wrapped around it.
The line is five programs. They are deliberately separate products rather than one
suite, so you can take the part you need and leave the rest. Each page below says plainly
what state its program is in, including the ones that are not finished.
The line
Cupelix Sentinel — In use
Security introspection for Windows: platform identity, firmware and boot introspection,
and kernel-level capture and tracing. Inspect hostile code without the code being able to
fingerprint the machine inspecting it. Public, Apache-2.0.
Cupelix Forge — In use, not publicly released
A CPU emulator for analysis work: a QEMU 11 core behind a Unicorn-compatible API, so a
binary can be re-executed instruction by instruction, deterministically, as many times as
needed. GPL-2.0.
Cupelix Assay — Early, usable
An auditor for one question: what does this machine actually disclose? Snapshot, change
something, snapshot again, diff. Deliberately independent of the suite it audits — including
ours.
Cupelix Manifold — Internal
The communication layer. It exposes reverse-engineering capability — decompilers,
debuggers, crash-dump triage, the emulator — to clients over one protocol, so a tool is
driven directly instead of through hand-built command lines and pasted output.
Cupelix Refinery — Planned, not yet implemented
Staged refinement of a protected binary into readable pseudocode. The name and the scope
are settled; none of it is written yet. It is listed here because it is part of the line,
not because there is anything to download.
How these pages are written
Every figure on this site is measured rather than estimated, and anything not tested is
marked as not tested. A record that only contains successes is not a record. Where a tool
reports an honest refusal instead of a reassuring absence, these pages say so, because that
is a deliberate design choice and not a gap.