We had an open source CPU emulator (of many CPU arch) called “Unicorn” that was a heavy test instrumentation points inserted widely throughout and into QEMU 4.0. I spent 2 solid years on these dynamic API bindings of Unicorn into QEMU.
It was an awesome piece of SW that allowed us to recreate the behavior of malware.
Asking the QEMU team to insert some 50-odd test points into the QEMU code was proved to be a maintenance nightmare.
Even if it just an #ifdef of C language, it was too “cluttery”, it was still an awesome automated detection of code generation of just the affected malware portion.
I still believe this approach to be a significant tangential vector of prime investing for a startup.