--- title: Anti-Cheat kind: overview topics: [anti-cheat] sources: - wiki/sources/skills/anti-cheat.md - wiki/sources/README-categories.md - wiki/sources/descriptions/modcommunity__dot-server-security.md - wiki/sources/descriptions/Driw0x__CS2Guard.md - wiki/sources/descriptions/zelect0r__zamr.md - wiki/sources/descriptions/Lixense__ff-ace-anticheat-analysis.md - wiki/sources/descriptions/LordeTyrael__PokeAllianceAntiCheatAnalysis.md - wiki/sources/descriptions/0dayatday0__BattleFN-cheat-analysis.md - wiki/sources/descriptions/zyhp__vac3_inhibitor.md - wiki/sources/descriptions/x1tan__vac3-dumper.md - wiki/sources/descriptions/shuruk421__VACKeyRetrieval.md - wiki/sources/descriptions/nevioo1337__VAC-ModuleDumper.md - wiki/sources/descriptions/ioncodes__vacation3-emu.md - wiki/sources/descriptions/gmh5225__Vac-Emulator.md - wiki/sources/descriptions/gmh5225__VACDumper.md - wiki/sources/descriptions/RenardDev__DumpVAC.md - wiki/sources/descriptions/gmh5225__PreventVAC.md - wiki/sources/descriptions/shefben__VALVeAntiCheat1.md - wiki/sources/descriptions/ianveig29__como-funciona-vac.md - wiki/sources/descriptions/iamsopotatoe-coder__TinyLoad.md - wiki/sources/descriptions/iArtorias__debug_remover.md - wiki/sources/descriptions/atrexus__vulkan.md - wiki/sources/descriptions/artmih24__TeleParser.md - wiki/sources/descriptions/arisada__midgetpack.md - wiki/sources/descriptions/armvirus__SinMapper.md - wiki/sources/descriptions/armvirus__DriverDllFInder.md - wiki/sources/descriptions/armvirus__VanguardTrace.md - wiki/sources/descriptions/krispybyte__Vook.md - wiki/sources/descriptions/danielkrupinski__Osiris.md - wiki/sources/descriptions/danielkrupinski__cs2-anticheat.md - wiki/sources/descriptions/c3rb3ru5d3d53c__binlex.md - wiki/sources/descriptions/c4kef__UAC.md - wiki/sources/descriptions/cocomelonc__tabby.md - wiki/sources/descriptions/akuafif__hXOR-Packer.md - wiki/sources/descriptions/akawashiro__sloader.md - wiki/sources/descriptions/DavidBuchanan314__stelf-loader.md - wiki/sources/descriptions/AsuNa-jp__HotkeybasedKeyloggerDetector.md - wiki/sources/descriptions/AvivShabtay__Stresser.md - wiki/sources/descriptions/ait-aecid__rootkit-detection-ebpf-time-trace.md - wiki/sources/descriptions/aahmad097__AlternativeShellcodeExec.md - wiki/sources/descriptions/Wra7h__FlavorTown.md - wiki/sources/descriptions/a0rtega__pafish.md - wiki/sources/descriptions/SaadAhla__Anti-Sandbox.md - wiki/sources/descriptions/LukeGoule__compact_vm_detector.md - wiki/sources/descriptions/Letomaniy__Speed-Hack.md - wiki/sources/descriptions/LilPidgey__BEClient.md - wiki/sources/descriptions/Lima-X__Win32.Nebula.md - wiki/sources/descriptions/LeoChen-CoreMind__VMPacker.md - wiki/sources/descriptions/Leeksov__rustsecure-re.md - wiki/sources/descriptions/LloydLabs__wsb-detect.md - wiki/sources/descriptions/LloydLabs__shellcode-plain-sight.md - wiki/sources/descriptions/LloydLabs__ntqueueapcthreadex-ntdll-gadget-injection.md - wiki/sources/descriptions/LloydLabs__delete-self-poc.md - wiki/sources/descriptions/LordNoteworthy__al-khaser.md - wiki/sources/descriptions/LordAbbot__Rust-External-Cheat.md - wiki/sources/descriptions/Longno242__Encryptic-Roblox-Anti-Cheat.md - wiki/sources/descriptions/LongWayHomie__PolyEngine.md - wiki/sources/descriptions/LooperSalty__cs2-tracker.md - wiki/sources/descriptions/Luchinkin__device-control-hooks-scanner.md - wiki/sources/descriptions/adem-hosni__AtomicShieldClient.md - wiki/sources/descriptions/adde88__SkyEngine.md - wiki/sources/descriptions/afulsamet__integrity.md - wiki/sources/descriptions/alal4465__KernelMon.md - wiki/sources/descriptions/alekzandren__in-memory-mutation-demo.md - wiki/sources/descriptions/alfarom256__rs-ldr.md - wiki/sources/descriptions/cocomelonc__peekaboo.md - wiki/sources/descriptions/codetronik__AndroidAntiCheat.md - wiki/sources/descriptions/codedevdev__irontrace.md - wiki/sources/descriptions/hawkeye-Leo__hawkeye.md - wiki/sources/descriptions/chztbby__RebirthGuard.md - wiki/sources/descriptions/chrisgdt__DELBOT-Mouse.md - wiki/sources/descriptions/crazythecoder__IW4MAdmin-SebzAntiCheat.md - wiki/sources/descriptions/cs2-server-plugins__cs2-calladmin.md - wiki/sources/descriptions/cognis-digital__packpeek.md - wiki/sources/descriptions/clementine44613__seiun-ac.md - wiki/sources/descriptions/XuJun05__FairCount.md - wiki/sources/descriptions/EpicLizard05013__UltimateMeteorAntiCheat.md - wiki/sources/descriptions/cklsit__AdvancedAntiCheat.md - wiki/sources/descriptions/connormcgarr__EATGuard.md - wiki/sources/descriptions/connorjaydunn__BinaryShield.md - wiki/sources/descriptions/cpz__trinity.md - wiki/sources/descriptions/crvvdev__vac-bypass-kernel.md - wiki/sources/descriptions/ccsimplyspolit__CS2-P2C-TEMPLATES.md - wiki/sources/descriptions/danielkrupinski__vac-hooks.md - wiki/sources/descriptions/danielkrupinski__VAC.md - wiki/sources/descriptions/danielkrupinski__VAC-Bypass.md - wiki/sources/descriptions/danielkrupinski__VAC-Bypass-Loader.md - wiki/sources/descriptions/Jackbail4__VAC-Bypass.md - wiki/sources/descriptions/J-Tanzanite__Little-Anti-Cheat.md - wiki/sources/descriptions/JackBro__BetaShield.md - wiki/sources/descriptions/JUS7205__cheatguard.md - wiki/sources/descriptions/danielkrupinski__MemJect.md - wiki/sources/descriptions/danielkrupinski__GOESP.md - wiki/sources/descriptions/kkent030315__Van1338.md - wiki/sources/descriptions/kkent030315__EQU8-PoC.md - wiki/sources/descriptions/hotline1337__equ8_bypass.md - wiki/sources/descriptions/kitty8904__blanket.md - wiki/sources/descriptions/gmh5225__Rootkit-2.md - wiki/sources/descriptions/jackullrich__syscall-detect.md - wiki/sources/descriptions/gmh5225__KasperskyHook.md - wiki/sources/descriptions/gmh5225__Hook-HvlSwitchVirtualAddressSpace.md - wiki/sources/descriptions/jfmaes__LazySign.md - wiki/sources/descriptions/jimbeveridge__readdirectorychanges.md - wiki/sources/descriptions/jnz__q3vm.md - wiki/sources/descriptions/jonomango__nohv.md - wiki/sources/descriptions/jonny-jhnson__EtwWatcher.md - wiki/sources/descriptions/jdu2600__CFG-FindHiddenShellcode.md - wiki/sources/descriptions/jdu2600__EtwTi-FluctuationMonitor.md - wiki/sources/descriptions/jthuraisamy__TelemetrySourcerer.md - wiki/sources/descriptions/jseclab__obj2shellcode.md - wiki/sources/descriptions/jxy-s__herpaderping.md - wiki/sources/descriptions/zxd1994__vt-debuuger.md - wiki/sources/descriptions/zx0CF1__shredder-rs.md - wiki/sources/descriptions/zouxianyu__BlindEye.md - wiki/sources/descriptions/zorftw__revert-mapper.md - wiki/sources/descriptions/zorftw__lsass-extend-mapper.md - wiki/sources/descriptions/gmh5225__KExecDD.md - wiki/sources/descriptions/gmh5225__KexecDDPlus.md - wiki/sources/descriptions/gmh5225__Kernel_Anti-Cheat.md - wiki/sources/descriptions/Vasieco__Kernel-Anticheat.md - wiki/sources/descriptions/zompi2__Static-Variables-Obfuscator-UE4.md - wiki/sources/descriptions/gmh5225__UnrealEngine-Protection.md - wiki/sources/descriptions/gmh5225__UE5MultiplayerProject.md - wiki/sources/descriptions/LeroyTechnologies__ProjectM.md - wiki/sources/descriptions/zodiacon__EtwExplorer.md - wiki/sources/descriptions/zoand__Injectors.md - wiki/sources/descriptions/nettitude__Tartarus-TpAllocInject.md - wiki/sources/descriptions/SafeBreach-Labs__PoolParty.md - wiki/sources/descriptions/zhaodice__proxmox-ve-anti-detection.md - wiki/sources/descriptions/zhaodice__qemu-anti-detection.md - wiki/sources/descriptions/killvxk__awesome-obfuscations.md - wiki/sources/descriptions/kila58__qemu-patched.md - wiki/sources/descriptions/batusan__Hardened-qemu.md - wiki/sources/descriptions/Schnocker__NoEye.md - wiki/sources/descriptions/Schnocker__EAC_dbp.md - wiki/sources/descriptions/R7flex__dll-ollvm.md - wiki/sources/descriptions/Rat431__EAC_Emu.md - wiki/sources/descriptions/CamxxCore__EasyAntiCheat-Emulator.md - wiki/sources/descriptions/S12cybersecurity__FrankensteinAPCInjection.md - wiki/sources/descriptions/S12cybersecurity__RWXFinder.md - wiki/sources/descriptions/Oliver-1-1__MouseDetection.md - wiki/sources/descriptions/Oliver-1-1__EtwKeyboardDetection.md - wiki/sources/descriptions/Oliver-1-1__RwxScanner.md - wiki/sources/descriptions/Schich__Lucky-Spark.md - wiki/sources/descriptions/KANKOSHEV__Detect-HiddenThread-via-KPRCB.md - wiki/sources/descriptions/KANKOSHEV__Detect-KeAttachProcess.md - wiki/sources/descriptions/KANKOSHEV__Detect-MouseClassServiceCallback.md - wiki/sources/descriptions/Karwmam__Vanguard-Service-Manager-vGK-Control.md - wiki/sources/descriptions/KelvinMsft__NoTruth.md - wiki/sources/descriptions/KaelusAI__Shard.md - wiki/sources/descriptions/KDIo3__PCIBan.md - wiki/sources/descriptions/Ke4ton__hardware_bypass.md - wiki/sources/descriptions/Keyzp1337__Fortnite.md - wiki/sources/descriptions/KeyzpOnTheFluxxx__Fortnite-External.md - wiki/sources/descriptions/Saxmason__Interic-Fortnite-External-Cheat.md - wiki/sources/descriptions/Saxmason__Subzero-Fortnite-Cheat.md - wiki/sources/descriptions/CheaterRehab__GodFather-Fortnite-Cheat-Cracked.md - wiki/sources/descriptions/SLAUC91__AntiCheat.md - wiki/sources/descriptions/Scrut1ny__Hypervisor-Phantom.md - wiki/sources/descriptions/SilentisVox__DoomSyscalls.md - wiki/sources/descriptions/SilentVoid13__Silent_Packer.md - wiki/sources/descriptions/Sinclairq__hiearchy-eac.md - wiki/sources/descriptions/SingularityCloud__KVM.Performance.md - wiki/sources/descriptions/bad-antics__rce-shield.md - wiki/sources/descriptions/baldspots440__R6Intel.md - wiki/sources/descriptions/brandenbailey23__r6-siege-battleye-launch-bug.md - wiki/sources/descriptions/zer0condition__hv.md - wiki/sources/descriptions/zer0condition__Ophion.md - wiki/sources/descriptions/zer0condition__ZeroThreadKernel.md - wiki/sources/descriptions/zer0condition__checkhv_um.md - wiki/sources/descriptions/zer0condition__gexec.md - wiki/sources/descriptions/ytk2128__pe32-password.md - wiki/sources/descriptions/ykus4__kagura.md - wiki/sources/descriptions/Neo23x0__Raccine.md - wiki/sources/descriptions/NeverSight__NeverC.md - wiki/sources/descriptions/romainthomas__the-poor-mans-obfuscator.md - wiki/sources/descriptions/open-obfuscator__dProtect.md - wiki/sources/descriptions/nkhmelni__Obscura.md - wiki/sources/descriptions/obfuscar__obfuscar.md - wiki/sources/descriptions/mishka-sit2002__CS2-Hybrid-AntiCheat-Proposal.md - wiki/sources/descriptions/mkaring__ConfuserEx.md - wiki/sources/descriptions/govcert-ch__ConfuserEx_IDAPython.md - wiki/sources/descriptions/nak0823__ObfuscationMethods.md - wiki/sources/descriptions/yardenshafir__cet-research.md - wiki/sources/descriptions/gmh5225__QueryShadowStack.md - wiki/sources/descriptions/gabriellandau__ShadowStackWalk.md - wiki/sources/descriptions/0xjbb__cet-spoofing-detection.md - wiki/sources/descriptions/gmh5225__CET-win10.md - wiki/sources/descriptions/xxFURYWOLFxx__veh-dumper.md - wiki/sources/descriptions/t3ssellate__unmapper.md - wiki/sources/descriptions/pr701__fix-arxan.md - wiki/sources/descriptions/BadPlayer555__TraceCleaner.md - wiki/sources/descriptions/Barracudach__Swap-control-ioctl.md - wiki/sources/descriptions/BarakAharoni__LADD.md - wiki/sources/descriptions/BeneficialCode__WinArk.md - wiki/sources/descriptions/BaumFX__cpp-anti-debug.md - wiki/sources/descriptions/Black0ffR__omega-sast.md - wiki/sources/descriptions/BlackSnufkin__AxHunter.md - wiki/sources/descriptions/Brentdevent__S2x.md - wiki/sources/descriptions/xuanxuan0__TiEtwAgent.md - wiki/sources/descriptions/preludeorg__ThreatIntelligenceConsumer.md - wiki/sources/descriptions/xsj3n__x64-EXE-Packer.md - wiki/sources/descriptions/xM0kht4r__2Pack.md - wiki/sources/descriptions/frank2__oxide.md - wiki/sources/descriptions/fuqiuluo__amice.md - wiki/sources/descriptions/Systemcluster__wrappe.md - wiki/sources/descriptions/xiaoweime__WProtect.md - wiki/sources/descriptions/D7EAD__mkPIVM.md - wiki/sources/descriptions/DeDf__WProtect.md - wiki/sources/descriptions/jokerNi__WProtectSDK.md - wiki/sources/descriptions/johnsonjason__MapleStoryBuildFramework.md - wiki/sources/descriptions/gmh5225__MapleStoryDetectionSampleGenerator.md - wiki/sources/descriptions/xan105__Mini-Launcher.md - wiki/sources/descriptions/xakepru__x14.08-coverstory-blizzard.md - wiki/sources/descriptions/xihedun-2026__Ponytail-Risk-.md - wiki/sources/descriptions/x86matthew__InstrumentationCallbackSyscallLogger.md - wiki/sources/descriptions/x86byte__sbox.md - wiki/sources/descriptions/x86byte__Obfusk8.md - wiki/sources/descriptions/xhscfq__anti-cheat-research-index.md - wiki/sources/descriptions/wufhex__Mystic-xorstr.md - wiki/sources/descriptions/JustasMasiulis__xorstr.md - wiki/sources/descriptions/JustasMasiulis__lazy_importer.md - wiki/sources/descriptions/JoshKappler__laneguard.md - wiki/sources/descriptions/JonathanBerkeley__Quack.md - wiki/sources/descriptions/JonDoNym__peinjector.md - wiki/sources/descriptions/nevergiveup-c__obfuscxx.md - wiki/sources/descriptions/Nou4r__Polymorphic-Engine.md - wiki/sources/descriptions/skadro-official__skCrypter.md - wiki/sources/descriptions/ac3ss0r__obfusheader.h.md - wiki/sources/descriptions/DosX-dev__obfus.h.md - wiki/sources/descriptions/adamyaxley__Obfuscate.md - wiki/sources/descriptions/android1337__crystr.md - wiki/sources/descriptions/android1337__crycall.md - wiki/sources/descriptions/android1337__brkida.md - wiki/sources/descriptions/igozdev__xorlit.md - wiki/sources/descriptions/llxiaoyuan__oxorany.md - wiki/sources/descriptions/llsgllsg__Minecraft_AntiCheatAI.md - wiki/sources/descriptions/blaquee__dllnotif.md - wiki/sources/descriptions/blackhades00__PareidoliaTriggerbot.md - wiki/sources/descriptions/brew02__KiUserExceptionDispatcherHook.md - wiki/sources/descriptions/brew02__CovertThread.md - wiki/sources/descriptions/bluecapesecurity__PWF.md - wiki/sources/descriptions/PaulNorman01__Forensia.md - wiki/sources/descriptions/PartialVolume__shredos.x86_64.md - wiki/sources/descriptions/PickAngE__AntiCheat-Scanner.md - wiki/sources/descriptions/Psmths__windows-forensic-artifacts.md - wiki/sources/descriptions/burrowers__garble.md - wiki/sources/descriptions/redskal__obfuscatxor.md - wiki/sources/descriptions/pykaso__Swift-String-Obfuscator.md - wiki/sources/descriptions/serge-14__encrypted_value.md - wiki/sources/descriptions/obama-gaming__xor-float.md - wiki/sources/descriptions/emlinhax__blitz.md - wiki/sources/descriptions/emlinhax__xv.md - wiki/sources/descriptions/eksses__EAFE.md - wiki/sources/descriptions/ekknod__nv_v2.md - wiki/sources/descriptions/ekknod__Nmi.md - wiki/sources/descriptions/ekknod__EC_PRO-LAN.md - wiki/sources/descriptions/ekknod__CSGO-AC.md - wiki/sources/descriptions/ekknod__Anti-Cheat-TestBench.md - wiki/sources/descriptions/dslee2022__SignatureKid.md - wiki/sources/descriptions/dsasmblr__hacking-online-games.md - wiki/sources/descriptions/dungnotnull__game-cheating-exploit-detection-agent-skill.md - wiki/sources/descriptions/emilyinure__solace-csgo.md - wiki/sources/descriptions/seifreed__r2morph.md - wiki/sources/descriptions/secrary__makin.md - wiki/sources/descriptions/revsic__AntiDebugging.md - wiki/sources/descriptions/cBournhonesque__lightyear.md - wiki/sources/descriptions/Krilliac__SparkEngine.md - wiki/sources/descriptions/XX-Batsu__bevy-personal-test.md - wiki/sources/descriptions/XRadius__project-tanya.md - wiki/sources/descriptions/XuanXuan-ZhengGui__Minecraft-Anti-Cheat.md - wiki/sources/descriptions/YcbrYL1__YCBR-AntiCheat.md - wiki/sources/descriptions/YouNeverKnow00__Anti-Debugger-Protector-Loader.md - wiki/sources/descriptions/hiatus__adbg.md - wiki/sources/descriptions/hfiref0x__WubbabooMark.md - wiki/sources/descriptions/hasherezade__mal_unpack_drv.md - wiki/sources/descriptions/liors619__TtdAntiDebugging.md - wiki/sources/descriptions/lainswork__shellcode-factory.md - wiki/sources/descriptions/lauralex__OAC.md - wiki/sources/descriptions/focus-creative-games__obfuz.md - wiki/sources/descriptions/bmjoy__Unity3D_Obfuscator.md - wiki/sources/descriptions/endgameinc__ClrGuard.md - wiki/sources/descriptions/friedkiwi__netcrypt.md - wiki/sources/descriptions/freezato__LocalAnticheat-1.8.9.md - wiki/sources/descriptions/winzysss__JarAnalyzer.md - wiki/sources/descriptions/Sutaigne__alibi.md - wiki/sources/descriptions/Skotschia__hwid_spoofer.md - wiki/sources/descriptions/Scrut1ny__Windows-Spoofer.md - wiki/sources/descriptions/StelGR__ArrowAntiCheat.md - wiki/sources/descriptions/SurgeGotTappedAgain__Window-Hijack.md - wiki/sources/descriptions/SurgeGotTappedAgain__Pink-Eye.md - wiki/sources/descriptions/enis1enis2__Windfall-AntiCheat.md - wiki/sources/descriptions/frkngksl__Huan.md - wiki/sources/descriptions/frkngksl__Shoggoth.md - wiki/sources/descriptions/frkngksl__HintInject.md - wiki/sources/descriptions/dmaivel__covirt.md - wiki/sources/descriptions/divodeuxsevres__gvmp-anticheat.md - wiki/sources/descriptions/layerfsd__phantasm-x86-virtualizer.md - wiki/sources/descriptions/lannden1245__Void-Engine.md - wiki/sources/descriptions/lguilhermee__EAC-Extractor-Utility.md - wiki/sources/descriptions/ksoju__Eac-Bypass.md - wiki/sources/descriptions/lguilhermee__Battleye-Shellcode-Dumper.md - wiki/sources/descriptions/libriscv__godot-sandbox.md - wiki/sources/descriptions/secrary__Hooking-via-InstrumentationCallback.md - wiki/sources/descriptions/pandaadir05__ghost.md - wiki/sources/descriptions/paranoidninja__EtwTi-Syscall-Hook.md - wiki/sources/descriptions/ssyuqixe__obfCoder.md - wiki/sources/descriptions/javascript-obfuscator__javascript-obfuscator.md - wiki/sources/descriptions/levifrsn63__krunker-loader.md - wiki/sources/descriptions/sfr-development__Lua-Obfuscator-Clyde-Protection.md - wiki/sources/descriptions/ssnob__hidden_syscall_monitoring.md - wiki/sources/descriptions/wpdk__wdutf.md - wiki/sources/descriptions/kernullist__kernforge.md - wiki/sources/descriptions/kernullist__KnWin32ApiMonitor.md - wiki/sources/descriptions/kernelwernel__VMAware.md - wiki/sources/descriptions/redecorate__Holodori-Kernel-Bypass.md - wiki/sources/descriptions/d35ha__CallObfuscator.md - wiki/sources/descriptions/AreWeAntiCheatYet__AreWeAntiCheatYet.md - wiki/sources/descriptions/aclist__aclist.github.io.md - wiki/sources/descriptions/dazi2011__crossover-patcher.md - wiki/sources/descriptions/ValveSoftware__Proton.md - wiki/sources/descriptions/TuncorReUnion__TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED.md - wiki/sources/descriptions/TOSTcRa__vigil.md - wiki/sources/descriptions/mikio815__linux-anticheat.md - wiki/sources/descriptions/daswareinfach__Battleye-VAC-EAC-Kernel-Bypass.md - wiki/sources/descriptions/dashingsoft__pyarmor.md - wiki/sources/descriptions/wietze__windows-dll-hijacking.md - wiki/sources/descriptions/wietze__HijackLibs.md - wiki/sources/descriptions/redteamsocietegenerale__DLLirant.md - wiki/sources/descriptions/Sh0ckFR__DLLirant.md - wiki/sources/descriptions/knight0x07__ImpulsiveDLLHijack.md - wiki/sources/descriptions/anhkgg__SuperDllHijack.md - wiki/sources/descriptions/andrew9382__exe_packer.md - wiki/sources/descriptions/ctxis__DLLHSC.md - wiki/sources/descriptions/whokilleddb__function-collections.md - wiki/sources/descriptions/whereisr0da__Lumina-Cheat.md - wiki/sources/descriptions/spirthack__CSGOSimple.md - wiki/sources/descriptions/gmh5225__CSGO-aw-v5.1.13.md - wiki/sources/descriptions/gmh5225__CSGO-Alphen.md - wiki/sources/descriptions/gmh5225__CSGO-Loader.md - wiki/sources/descriptions/flowxrc__csgo-xenforo-loader.md - wiki/sources/descriptions/b1scoito__cozinha_loader.md - wiki/sources/descriptions/gmh5225__CSGO-NIXWARE-CSGO.md - wiki/sources/descriptions/seksea__gamesneeze.md - wiki/sources/descriptions/gigbh__d-process.md - wiki/sources/descriptions/otvv__csgo-linux-cheat-sdk.md - wiki/sources/descriptions/danielkrupinski__Anubis.md - wiki/sources/descriptions/s3pt3mb3r__Dainsleif.md - wiki/sources/descriptions/gmh5225__anti-cheat.md - wiki/sources/descriptions/gmh5225__AntiDbg-AmogusPlugin.md - wiki/sources/descriptions/gmh5225__antidbg-Baka.md - wiki/sources/descriptions/NotRequiem__antidbg.md - wiki/sources/descriptions/gmh5225__augur-riot.md - wiki/sources/descriptions/gmh5225__VanguardImportResolver.md - wiki/sources/descriptions/gmh5225__TFT-OCR-BOT.md - wiki/sources/descriptions/gmh5225__StarRailCopilot.md - wiki/sources/descriptions/gmh5225__StarRail-S-GC.md - wiki/sources/descriptions/gmh5225__StarRail-ACE-B.md - wiki/sources/descriptions/gmh5225__HI3-ACE-B.md - wiki/sources/descriptions/Gitex68__Katapult-AntiCheat.md - wiki/sources/descriptions/GuidoBartoli__sherloq.md - wiki/sources/descriptions/GunshipPenguin__kiteshield.md - wiki/sources/descriptions/H1d3r__GPU_ShellCode.md - wiki/sources/descriptions/H3d9__sguard_limit.md - wiki/sources/descriptions/gmh5225__avhook.md - wiki/sources/descriptions/martinjanas__Sensum.md - wiki/sources/descriptions/sodium-CrispyWafer__CrispyWafer-Anti-Cheat-Assistant-WaferACA.md - wiki/sources/descriptions/soyware__heck_csgo_external.md - wiki/sources/descriptions/si1kyyy__csgo_cheat_external.md - wiki/sources/descriptions/rrpvm__csgo-external-cheat.md - wiki/sources/descriptions/Half-People__HPCS2.md - wiki/sources/descriptions/Atonl200__ProjectNexus-CSGO.md - wiki/sources/descriptions/BrufelFX__RabsztynCC-CS2-Internal.md - wiki/sources/descriptions/Broihon__GH-Injector-Library.md - wiki/sources/descriptions/BoondockSulfur__BS-AntiCheat.md - wiki/sources/descriptions/realkyx29-design__LarpingAntiCheat.md - wiki/sources/descriptions/ByteCorum__DragonBurn.md - wiki/sources/descriptions/HadockKali__battleye-user-mode-bypass.md - wiki/sources/descriptions/HackOvert__AntiDBG.md - wiki/sources/descriptions/CheckPointSW__Nodejs-Tracer.md - wiki/sources/descriptions/CheckPointSW__showstopper.md - wiki/sources/descriptions/CasualX__obfstr.md - wiki/sources/descriptions/EvilBytecode__Ebyte-Syscalls.md - wiki/sources/descriptions/EvilBytecode__GhostVEH.md - wiki/sources/descriptions/EvilBytecode__GoDefender.md - wiki/sources/descriptions/GravitLauncher__Avanguard.md - wiki/sources/descriptions/HeathHowren__CSGO-Cheats.md - wiki/sources/descriptions/gmh5225__cfclap.md - wiki/sources/descriptions/gmh5225__cerberus.md - wiki/sources/descriptions/gmh5225__cheat-attack-thread-slemu.md - wiki/sources/descriptions/gmh5225__Hidden-Thread-Finder.md - wiki/sources/descriptions/gmh5225__csgo_external_ahk_hack.md - wiki/sources/descriptions/Lexikos__AutoHotkey_L.md - wiki/sources/descriptions/sneakyevilSK__CSGO_BacktrackPatch.md - wiki/sources/descriptions/wesmar__FileRecoveryTool.md - wiki/sources/descriptions/wesjian__GenericGameDetourAPIHook.md - wiki/sources/descriptions/thewhiteninja__ntfstool.md - wiki/sources/descriptions/strozfriedberg__ntfs-linker.md - wiki/sources/descriptions/NTFSparse__ntfs_parse.md - wiki/sources/descriptions/rbmm__USN.md - wiki/sources/descriptions/mdilai__Shtreeba.md - wiki/sources/descriptions/mgeeky__ShellcodeFluctuation.md - wiki/sources/descriptions/mgeeky__ntfs-journal-viewer.md - wiki/sources/descriptions/MahmoudZohdy__IAT-Obfuscation.md - wiki/sources/descriptions/MahmoudZohdy__Process-Injection-Techniques.md - wiki/sources/descriptions/KuryCat__GhostJoin.md - wiki/sources/descriptions/Eangly99__AstroX-AntiCheat.md - wiki/sources/descriptions/GhostNgEnd__Ghost-AntiCheat.md - wiki/sources/descriptions/Gingerbeard5773__dino-printer.md - wiki/sources/descriptions/Charlie328402__Sentinel-Anti-Cheat.md - wiki/sources/descriptions/NaySurGithub__Amethyst.md - wiki/sources/descriptions/ManInMyVan__Minecraft-Anticheat-List.md - wiki/sources/descriptions/ManulMap__malstring.md - wiki/sources/descriptions/Metick__Anti-Debug.md - wiki/sources/descriptions/MemNixFS__MemNixFS.md - wiki/sources/descriptions/MatheuZSecurity__ksentinel.md - wiki/sources/descriptions/MatheuZSecurity__Rootkit.md - wiki/sources/descriptions/MatheuZSecurity__RingReaper.md - wiki/sources/descriptions/Midi12__QueryWorkingSetExample.md - wiki/sources/descriptions/MrDiamond64__Scythe-AntiCheat.md - wiki/sources/descriptions/MrMugiwara__FTK-imager-OSX.md - wiki/sources/descriptions/Murka007__Glotus-Client.md - wiki/sources/descriptions/Mowokuma__vm_str.hpp.md - wiki/sources/descriptions/mexploitui__FakeEye.md - wiki/sources/descriptions/Hypercall__FakeEye.md - wiki/sources/descriptions/Hexze__anticheat.md - wiki/sources/descriptions/masterpastaa__BattlEye-Handler-BYPASS.md - wiki/sources/descriptions/mastershadow547__Advanced-Anticheat.md - wiki/sources/descriptions/med0x2e__SigFlip.md - wiki/sources/descriptions/medievalghoul__hwid-checker-mg.md - wiki/sources/descriptions/rbmm__SearchEx.md - wiki/sources/descriptions/rbmm__LockFile-Poc.md - wiki/sources/descriptions/thetuh__anticheat-poc.md - wiki/sources/descriptions/PatchRequest__PeregrineAntiCheat.md - wiki/sources/descriptions/HEEAAP__Sentinel-Anti-Cheat.md - wiki/sources/descriptions/niemand-sec__AntiCheat-Testing-Framework.md - wiki/sources/descriptions/noahware__darken-anticheat.md - wiki/sources/descriptions/weak1337__ricochet_deobfuscator.md - wiki/sources/descriptions/weak1337__NvidiaApi.md - wiki/sources/descriptions/weak1337__NO_ACCESS_Protection.md - wiki/sources/descriptions/weak1337__ModExMap.md - wiki/sources/descriptions/weak1337__DetectTpmSpoofing.md - wiki/sources/descriptions/weak1337__CEDetector.md - wiki/sources/descriptions/weak1337__BE-Shellcode.md - wiki/sources/descriptions/gmh5225__BE-Emulator.md - wiki/sources/descriptions/gmh5225__BE-BattlEye_shellcode.md - wiki/sources/descriptions/gmh5225__BE-Forcer-Fortnite.md - wiki/sources/descriptions/gmh5225__Alcatraz.md - wiki/sources/descriptions/gmh5225__AcDrv.md - wiki/sources/descriptions/gmh5225__AetherVisor.md - wiki/sources/descriptions/gmh5225__ANGRYORCHARD.md - wiki/sources/descriptions/weak1337__Alcatraz.md - wiki/sources/descriptions/mike1k__perses.md - wiki/sources/descriptions/trustdecision__trustdevice-ios.md - wiki/sources/descriptions/trustdecision__trustdevice-android.md - wiki/sources/descriptions/mrx7014__SpoofingCollection.md - wiki/sources/descriptions/imxiaoc996__DeviceWarLock.md - wiki/sources/descriptions/inpeacedTeams__phantom-client.md - wiki/sources/descriptions/unleg1t__Yuri.md - wiki/sources/descriptions/lolizei__Lenrete-Mod.md - wiki/sources/descriptions/NekoyaHouse__Epsilon.md - wiki/sources/descriptions/wbenny__scfw.md - wiki/sources/descriptions/wbenny__injdrv.md - wiki/sources/descriptions/wbenny__DetoursNT.md - wiki/sources/descriptions/stevemk14ebr__PolyHook_2_0.md - wiki/sources/descriptions/stevemk14ebr__PolyHook.md - wiki/sources/descriptions/regomne__ilhook-rs.md - wiki/sources/descriptions/aquasecurity__tracee.md - wiki/sources/descriptions/wazuh__wazuh.md - wiki/sources/descriptions/TheHive-Project__TheHive.md - wiki/sources/descriptions/Fahersto__code_injection.md - wiki/sources/descriptions/Deniskore__CompileTimeRandom.md - wiki/sources/descriptions/Deputation__hygieia.md - wiki/sources/descriptions/DejavuSecure__DetectNtoskrnlIntegrity.md - wiki/sources/descriptions/FaEryICE__MemScanner.md - wiki/sources/descriptions/FarmEquipment69__umap-mapper.md - wiki/sources/descriptions/Th3Spl__IoCreateDriver.md - wiki/sources/descriptions/1hAck-0__zeroimport.md - wiki/sources/descriptions/Th3Spl__NoImportz.md - wiki/sources/descriptions/Teach2Breach__moonwalk.md - wiki/sources/descriptions/waryas__xign_poc_april_2026.md - wiki/sources/descriptions/waryas__WaryasSWHE.md - wiki/sources/descriptions/waldo-vision__waldo.md - wiki/sources/descriptions/waldo-vision__aimbot-detection-prototype.md - wiki/sources/descriptions/wflores9__Ironwall.md - wiki/sources/descriptions/web-coder-lab__chessking.md - wiki/sources/descriptions/tgillam__HumanMouseMovement.md - wiki/sources/descriptions/AryuInka__Valorant-Cheat-External.md - wiki/sources/descriptions/AlSch092__UltimateAntiCheat.md - wiki/sources/descriptions/AlSch092__EasyHandles.md - wiki/sources/descriptions/Abdelnour2__MiniAntiCheatV2.md - wiki/sources/descriptions/AlfredIU__Spoofer.md - wiki/sources/descriptions/AsfhtgkDavid__windmouse.md - wiki/sources/descriptions/petercunha__Pine.md - wiki/sources/descriptions/w1u0u1__kinject.md - wiki/sources/descriptions/sum-catnip__kptnhook.md - wiki/sources/descriptions/vxlang__vxlang-page.md - wiki/sources/descriptions/vxCrypt0r__Voidmaw.md - wiki/sources/descriptions/saveme712__BinCon.md - wiki/sources/descriptions/sapdragon__syscalls-cpp.md - wiki/sources/descriptions/gmh5225__dse_hook.md - wiki/sources/descriptions/gmh5225__Dse-Patcher-2.md - wiki/sources/descriptions/gmh5225__DisableDSE.md - wiki/sources/descriptions/gmh5225__DSEDodge-Signed-Kernel-Driver.md - wiki/sources/descriptions/gmh5225__Disable-Windows-Defender-.md - wiki/sources/descriptions/gmh5225__Driver-WatchOwl.md - wiki/sources/descriptions/gmh5225__ezDrvBAK.md - wiki/sources/descriptions/gmh5225__inline-syscall.md - wiki/sources/descriptions/JustasMasiulis__inline_syscall.md - wiki/sources/descriptions/gmh5225__injection.md - wiki/sources/descriptions/hanickadot__cthash.md - wiki/sources/descriptions/hanickadot__compile-time-regular-expressions.md - wiki/sources/descriptions/sapdragon__hint-break.md - wiki/sources/descriptions/thefLink__DeepSleep.md - wiki/sources/descriptions/janoglezcampos__DeathSleep.md - wiki/sources/descriptions/Kudaes__Dumpy.md - wiki/sources/descriptions/Kudaes__Shelter.md - wiki/sources/descriptions/Kudaes__Puzzle.md - wiki/sources/descriptions/KooroshRZ__Evader.md - wiki/sources/descriptions/Fatmike-GH__Fatpack.md - wiki/sources/descriptions/Eronana__packer.md - wiki/sources/descriptions/EgeBalci__amber.md - wiki/sources/descriptions/CookiePLMonster__UptimeFaker.md - wiki/sources/descriptions/CoderYiXin__PalOpsWeb.md - wiki/sources/descriptions/CDJuaum__RunEXE.md - wiki/sources/descriptions/Compiled-Code__be-injector.md - wiki/sources/descriptions/ComodoSecurity__openedr.md - wiki/sources/descriptions/0xrawsec__whids.md - wiki/sources/descriptions/0xf1a__DSMM.md - wiki/sources/descriptions/0xflux__Sanctum.md - wiki/sources/descriptions/0xMohammedHassan__morphkatz.md - wiki/sources/descriptions/0xor0ne__debugoff.md - wiki/sources/descriptions/0xTriboulet__T-1.md - wiki/sources/descriptions/ContionMig__LSASS-Usermode-Bypass.md - wiki/sources/descriptions/ConWan30__QorTroller.md - wiki/sources/descriptions/Cracked5pider__KaynStrike.md - wiki/sources/descriptions/EBalloon__MapPage.md - wiki/sources/descriptions/EBalloon__Remap.md - wiki/sources/descriptions/EBalloon__MmCopyMemory.md - wiki/sources/descriptions/EBalloon__EasyAntiCheat-SRC.md - wiki/sources/descriptions/Ezmatehw__Encryptix-Crypter.md - wiki/sources/descriptions/vvb2060__MagiskDetector.md - wiki/sources/descriptions/rushiranpise__detection.md - wiki/sources/descriptions/reveny__Android-Native-Root-Detector.md - wiki/sources/descriptions/reveny__Android-Native-Import-Hide.md - wiki/sources/descriptions/vvb2060__KeyAttestation.md - wiki/sources/descriptions/shakevsky__keybuster.md - wiki/sources/descriptions/topjohnwu__Magisk.md - wiki/sources/descriptions/vsteffen__woody_woodpacker.md - wiki/sources/descriptions/timhsutw__elfuck.md - wiki/sources/descriptions/craids__AresFramework.md - wiki/sources/descriptions/cryonumb__elfloader.md - wiki/sources/descriptions/n4sm__m0dern_p4cker.md - wiki/sources/descriptions/mix64__ELFpacker.md - wiki/sources/descriptions/droberson__ELFcrypt.md - wiki/sources/descriptions/dimkr__papaw.md - wiki/sources/descriptions/dr4k0nia__Origami.md - wiki/sources/descriptions/r0ngwe1__petoy.md - wiki/sources/descriptions/phra__PEzor.md - wiki/sources/descriptions/nqntmqmqmb__xorPacker.md - wiki/sources/descriptions/phajmvawnsix__com.sipvlib.anticheat.md - wiki/sources/descriptions/gmh5225__genshin-cheat.md - wiki/sources/descriptions/phonowell__genshin-impact-script.md - wiki/sources/descriptions/khang06__mhynot2.md - wiki/sources/descriptions/gmh5225__Genshin-EasyPeasy-Bypass.md - wiki/sources/descriptions/kanekikun420__NoCheatZ-3.md - wiki/sources/descriptions/karola3vax__CS2AC.md - wiki/sources/descriptions/Pintuzoft__OSAntiCheat.md - wiki/sources/descriptions/IntelSDM__7DTD.md - wiki/sources/descriptions/majimaakane__7dtd-AntiCheatMod.md - wiki/sources/descriptions/irembo337__Fusion-AntiCheat.md - wiki/sources/descriptions/hfiref0x__NtCall64.md - wiki/sources/descriptions/void-stack__Hypervisor-Detection.md - wiki/sources/descriptions/hypervisor__kli.md - wiki/sources/descriptions/gmh5225__integrity_experiments.md - wiki/sources/descriptions/gmh5225__ghostbusters.md - wiki/sources/descriptions/gmh5225__alt-V-Anticheat-Guide.md - wiki/sources/descriptions/gmh5225__WeirdAntiCheatIdeas.md - wiki/sources/descriptions/gmh5225__kli-ex.md - wiki/sources/descriptions/huntandhackett__process-cloning.md - wiki/sources/descriptions/huoji120__Etw-Syscall.md - wiki/sources/descriptions/hotline1337__page_no_access.md - wiki/sources/descriptions/hotline1337__umium.md - wiki/sources/descriptions/haram__splendid_implanter.md - wiki/sources/descriptions/ashleyhung__WinRing0.md - wiki/sources/descriptions/hubblo-org__windows-rapl-driver.md - wiki/sources/descriptions/hackerhouse-opensource__SignToolEx.md - wiki/sources/descriptions/Jemmy1228__HookSigntool.md - wiki/sources/descriptions/hzqst__FuckCertVerifyTimeValidity.md - wiki/sources/descriptions/hzqst__VmwareHardenedLoader.md - wiki/sources/descriptions/therealdreg__anticuckoo.md - wiki/sources/descriptions/donnaskiez__ac.md - wiki/sources/descriptions/donnaskiez__nmi-callback-handler.md - wiki/sources/descriptions/1401199262__NMIStackWalk.md - wiki/sources/descriptions/1401199262__HookSwapContext.md - wiki/sources/descriptions/1401199262__HookHvcallCodeVa.md - wiki/sources/descriptions/dobin__SuperMega.md - wiki/sources/descriptions/doomedraven__Tools.md - wiki/sources/descriptions/theo-abel__awesome-anti-virtualization.md - wiki/sources/descriptions/su-vikas__conbeerlib.md - wiki/sources/descriptions/strazzere__anti-emulator.md - wiki/sources/descriptions/gmh5225__Android-Emulator-Detection.md - wiki/sources/descriptions/reveny__Android-Emulator-Detection.md - wiki/sources/descriptions/strazzere__android-unpacker.md - wiki/sources/descriptions/violetweather__Certael.md - wiki/sources/descriptions/somewhatpublicacc__wellsanticheat.md - wiki/sources/descriptions/GiannBart__BanMod.md - wiki/sources/descriptions/ricardoofnl__open.mp-anticheat.md - wiki/sources/descriptions/multitheftauto__mtasa-blue.md - wiki/sources/descriptions/mihaly044__pedigest.md - wiki/sources/descriptions/microsoft__SDCM.md - wiki/sources/descriptions/michaelmsonne__SignToolGUI.md - wiki/sources/descriptions/mathisvickie__sign-expired.md - wiki/sources/descriptions/mtrojnar__osslsigncode.md - wiki/sources/descriptions/muellerberndt__frida-detection.md - wiki/sources/descriptions/oomph-ac__oomph.md - wiki/sources/descriptions/nsharp-collab__AvAAntiCheat.md - wiki/sources/descriptions/norbertbaricz__DakotaAC.md - wiki/sources/descriptions/NoCheatPlus__NoCheatPlus.md - wiki/sources/descriptions/shalzuth__PalWorldAntiCheat.md - wiki/sources/descriptions/veryboreddd__Return-address-spoofer.md - wiki/sources/descriptions/susMdT__LoudSunRun.md - wiki/sources/descriptions/xec412__NocturneLdr.md - wiki/sources/descriptions/nodiuus__nocturne.md - wiki/sources/descriptions/mrexodia__AppInitHook.md - wiki/sources/descriptions/mrexodia__RiscyWorkshop.md - wiki/sources/descriptions/mrexodia__NtPhp.md - wiki/sources/descriptions/mq1n__HiddenModuleDetector.md - wiki/sources/descriptions/mq1n__DLLThreadInjectionDetector.md - wiki/sources/descriptions/mq1n__NoMercy.md - wiki/sources/descriptions/noahware__binprotect.md - wiki/sources/descriptions/badhive__stitch.md - wiki/sources/descriptions/keowu__Ryujin.md - wiki/sources/descriptions/nelfo__Milfuscator.md - wiki/sources/descriptions/noahware__apic.md - wiki/sources/descriptions/noahware__armcall.md - wiki/sources/descriptions/venkata-ram__DroidShield.md - wiki/sources/descriptions/talsec__Free-RASP-Community.md - wiki/sources/descriptions/talsec__Free-RASP-Unity-POC.md - wiki/sources/descriptions/talsec__Free-RASP-ReactNative.md - wiki/sources/descriptions/talsec__Free-RASP-Android.md - wiki/sources/descriptions/talsec__Free-RASP-Capacitor.md - wiki/sources/descriptions/talsec__Free-RASP-Cordova.md - wiki/sources/descriptions/talsec__Free-RASP-iOS.md - wiki/sources/descriptions/talsec__Free-RASP-Flutter.md - wiki/sources/descriptions/talsec__Free-RASP-KMP.md - wiki/sources/descriptions/rajssinde__rs-native-kit-security.md - wiki/sources/descriptions/valium007__BareSVM.md - wiki/sources/descriptions/tandasat__MiniVisorPkg.md - wiki/sources/descriptions/umpolungfish__byvalver.md - wiki/sources/descriptions/utoni__PastDSE.md - wiki/sources/descriptions/secretsquirrel__SigThief.md - wiki/sources/descriptions/Sentient111__StealingSignatures.md - wiki/sources/descriptions/SV-Foster__UnSign.md - wiki/sources/descriptions/KriyosArcane__TrustMeBro.md - wiki/sources/descriptions/rhboot__pesign.md - wiki/sources/descriptions/namazso__MagicSigner.md - wiki/sources/descriptions/user23333__veh.md - wiki/sources/descriptions/tym32167__arma3beclient.md - wiki/sources/descriptions/Skengdo__arma3-external-variable-manager.md - wiki/sources/descriptions/travisfoley__dfirtriage.md - wiki/sources/descriptions/gravemaulr__MLAntiCheat.md - wiki/sources/descriptions/greyb1t__GreyM.md - wiki/sources/descriptions/gtworek__VolatileDataCollector.md - wiki/sources/descriptions/mubix__netview.md - wiki/sources/descriptions/tr1xxx__battleye-region-walking.md - wiki/sources/descriptions/euuuuuuan__gatewarden-public.md - wiki/sources/descriptions/eversinc33__unKover.md - wiki/sources/descriptions/ex0dus-0x__ward.md - wiki/sources/descriptions/experienceds__battleye-re.md - wiki/sources/descriptions/dllcrt0__bedaisy-reversal.md - wiki/sources/descriptions/dllcrt0__battleye-shellcode.md - wiki/sources/descriptions/dllcrt0__battleye-decryption.md - wiki/sources/descriptions/es3n1n__be-shellcode-tester.md - wiki/sources/descriptions/toneillcodes__windows-process-injection.md - wiki/sources/descriptions/gavz__Jektor.md - wiki/sources/descriptions/g8tsz__deadlock-anti-cheat.md - wiki/sources/descriptions/g91__PalAntiCheat-poc.md - wiki/sources/descriptions/guided-hacking__GuidedHacking-Injector.md - wiki/sources/descriptions/tingwei1111__maplestory-worlds-automation.md - wiki/sources/descriptions/thesecretclub__CVEAC-2020.md - wiki/sources/descriptions/thexin7__kernel-cve-analysis.md - wiki/sources/descriptions/vul-os__magnetite.md - wiki/sources/descriptions/t0asts__DIE-engine-web.md - wiki/sources/descriptions/pandora-analysis__pandora.md - wiki/sources/descriptions/pavelinbs-afk__anticheatsystem.md - wiki/sources/descriptions/synctop__tpm-mmio.md - wiki/sources/descriptions/s0ngidong3__TPM-SPOOFER.md - wiki/sources/descriptions/SamLarenN__PePacker.md - wiki/sources/descriptions/SamLarenN__CPUZ-DSEFix.md - wiki/sources/descriptions/SamuelTulach__tpm-spoofer.md - wiki/sources/descriptions/SamuelTulach__meme-rw.md - wiki/sources/descriptions/SamuelTulach__HookGuard.md - wiki/sources/descriptions/SamuelTulach__BetterTiming.md - wiki/sources/descriptions/SamuelTulach__SecureGame.md - wiki/sources/descriptions/illegal-instruction-co__CountHook.md - wiki/sources/descriptions/svespalec__faultline.md - wiki/sources/descriptions/nelfo__PGHooker.md - wiki/sources/descriptions/stuxnet147__Known-Driver-Mappers.md - wiki/sources/descriptions/TheAenema__hm-pe-packer.md - wiki/sources/descriptions/ATsahikian__pe-protector.md - wiki/sources/descriptions/87andrewh__CornerCulling.md - wiki/sources/descriptions/87andrewh__CornerCullingSourceEngine.md - wiki/sources/descriptions/87andrewh__DeepAimDetector.md - wiki/sources/descriptions/89luca89__pakkero.md - wiki/sources/descriptions/TheCruZ__kdmapper.md - wiki/sources/descriptions/eddeeh__kdmapper.md - wiki/sources/descriptions/rmccrystal__kdmapper-rs.md - wiki/sources/descriptions/paysonism__saturn-mapper.md - wiki/sources/descriptions/steffalon__battleye-rust.md - wiki/sources/descriptions/st4ckh0und__hook-buster.md - wiki/sources/descriptions/mike1k__HookHunter.md - wiki/sources/descriptions/0x6461726B__Hook-Detector.md - wiki/sources/descriptions/m417z__thread-call-stack-scanner.md - wiki/sources/descriptions/momo5502__patch-finder.md - wiki/sources/descriptions/momo5502__hypervisor.md - wiki/sources/descriptions/mischasan__aho-corasick.md - wiki/sources/descriptions/miyakejima__xigncode3-blackdesert.md - wiki/sources/descriptions/gmh5225__XignCode3-bypass.md - wiki/sources/descriptions/gmh5225__XignCode3-bypass-alternative.md - wiki/sources/descriptions/gmh5225__XignCode-Dump.md - wiki/sources/descriptions/momalab__e3.md - wiki/sources/descriptions/push0ebp__xMalHunter.md - wiki/sources/descriptions/spyder1g__a-pasted-rust-script.md - wiki/sources/descriptions/singhhdev__Spoofer-AMIDEWIN.md - wiki/sources/descriptions/semihcevik__hwidspoofer.md - wiki/sources/descriptions/gmh5225__Wizard-Loader.md - wiki/sources/descriptions/gmh5225__wizard101-spoofer.md - wiki/sources/descriptions/gmh5225__Apex-Spoofer.md - wiki/sources/descriptions/gmh5225__hv-detect.md - wiki/sources/descriptions/gmh5225__Go-Detection-Hyper-v.md - wiki/sources/descriptions/gmh5225__Detection-Hyper-v.md - wiki/sources/descriptions/gmh5225__Detect-Hypervisor_detect_ring_0.md - wiki/sources/descriptions/gmh5225__Detection-CheatEngine.md - wiki/sources/descriptions/gmh5225__Detection-CheatEngine-Ring0.md - wiki/sources/descriptions/gmh5225__Voyager.md - wiki/sources/descriptions/backengineering__Voyager.md - wiki/sources/descriptions/NurdAlert__modded-voyager.md - wiki/sources/descriptions/gmh5225__Full-Hwid-Spoofer-V6.md - wiki/sources/descriptions/gmh5225__Fortnite-External-5.md - wiki/sources/descriptions/gmh5225__hwid-spoofer.md - wiki/sources/descriptions/gmh5225__Hwid-Spoofer-EAC-BE.md - wiki/sources/descriptions/gmh5225__HWID-EclipsedSpoofer-EAC-BE.md - wiki/sources/descriptions/gmh5225__HWID-Kernel-Spoofer.md - wiki/sources/descriptions/gmh5225__HWID-Permanent-HWID-Spoofer.md - wiki/sources/descriptions/gmh5225__HWID-Pasted-Hwid-Spoofer.md - wiki/sources/descriptions/gmh5225__HWID-Spoofer-UD-Fortnite-WarZone-Apex-Rust-Escape-From-Tarkov-and-all-EAC-BE-Games-IMGUI-Loader-Base.md - wiki/sources/descriptions/gmh5225__HWID-SteamSpywareTerminator.md - wiki/sources/descriptions/gmh5225__PrecisionSpoofer-CPP.md - wiki/sources/descriptions/gmh5225__Uncloaking-RAID0-HWID-Serials.md - wiki/sources/descriptions/gmh5225__query-gpu-name-rs.md - wiki/sources/descriptions/gmh5225__AurumRE.md - wiki/sources/descriptions/gmh5225__ricochet-disabler.md - wiki/sources/descriptions/gmh5225__rust-dll-crab.md - wiki/sources/descriptions/gmh5225__SetWindowsHookEx-Injector.md - wiki/sources/descriptions/gmh5225__MMFCodeInjection.md - wiki/sources/descriptions/gmh5225__nullmap.md - wiki/sources/descriptions/gmh5225__Driver-SessionMapper.md - wiki/sources/descriptions/gmh5225__CallMeWin32kDriver.md - wiki/sources/descriptions/gmh5225__Driver-Detect-nullshit.md - wiki/sources/descriptions/gmh5225__Driver-DriverNoImage.md - wiki/sources/descriptions/gmh5225__Driver-HideKernelThread-IoCancelIrp.md - wiki/sources/descriptions/gmh5225__osu-aac.md - wiki/sources/descriptions/gmh5225__OW2-wardenrekter.md - wiki/sources/descriptions/dword64__Ow-Anti-Flag.md - wiki/sources/descriptions/gmh5225__OW-Aeternum.md - wiki/sources/descriptions/gmh5225__packer-tutorial.md - wiki/sources/descriptions/gmh5225__awesome-executable-packing.md - wiki/sources/descriptions/gmh5225__pHake.md - wiki/sources/descriptions/gmh5225__SpookiMystic-GTA-Leak.md - wiki/sources/descriptions/gmh5225__EntropyReducer.md - wiki/sources/descriptions/gmh5225__Dynsec.md - wiki/sources/descriptions/gmh5225__shellcode-EntropyFix.md - wiki/sources/descriptions/gmh5225__spoof-stack-SafeCall.md - wiki/sources/descriptions/gmh5225__TWMS-Hacking-Data.md - wiki/sources/descriptions/gmh5225__underTheHoodOfExecutables.md - wiki/sources/descriptions/gmh5225__custom-VEH.md - wiki/sources/descriptions/gmh5225__veh-printf-hook.md - wiki/sources/descriptions/gmh5225__no-access-protection-x86.md - wiki/sources/descriptions/gmh5225__MemoryGuard.md - wiki/sources/descriptions/gmh5225__Malicious-code-detection-bugu.md - wiki/sources/descriptions/gmh5225__Mandragora.md - wiki/sources/descriptions/gmh5225__Anticheat-android-cheap-engine.md - wiki/sources/descriptions/gmh5225__AntiCheat.md - wiki/sources/descriptions/gmh5225__AntiCheat-chrysalis.md - wiki/sources/descriptions/gmh5225__Basic_Anti-Cheat.md - wiki/sources/descriptions/gmh5225__memory-relocalloc.md - wiki/sources/descriptions/gmh5225__Kernel-VAD-Injector.md - wiki/sources/descriptions/gmh5225__cs16-trigger-kvm.md - wiki/sources/descriptions/gmh5225__kvm-csgo-cheat.md - wiki/sources/descriptions/gmh5225__LostArk.md - wiki/sources/descriptions/gmh5225__veh_hide_memory.md - wiki/sources/descriptions/gmh5225__vgk-illegal-pf-logger.md - wiki/sources/descriptions/gupr0x4__HWID-Spoofer-for-Fortnite-and-Valorant.md - wiki/sources/descriptions/guidoreina__minivers.md - wiki/sources/descriptions/namazso__hdd_serial_spoofer.md - wiki/sources/descriptions/roomyoni__Nvidia-GPU-Spoof.md - wiki/sources/descriptions/shalzuth__NativeNetSharp.md - wiki/sources/descriptions/samshine__ScyllaHideDetector2.md - wiki/sources/descriptions/rrbranco__blackhat2012.md - wiki/sources/descriptions/rogerxiii__kernel-codecave-poc.md - wiki/sources/descriptions/vovasicidk__sentinelac.md - wiki/sources/descriptions/razixNew__CompiledProtection.md - wiki/sources/descriptions/raskolnikov90__Beatrice.py.md - wiki/sources/descriptions/rabbitstack__fibratus.md - wiki/sources/descriptions/progmboy__openprocmon.md - wiki/sources/descriptions/rad9800__BootExecuteEDR.md - wiki/sources/descriptions/rad9800__BloatedHammer.md - wiki/sources/descriptions/rafalimma__ModelAnti-Cheat.md - wiki/sources/descriptions/qwqdanchun__Pillager.md - wiki/sources/descriptions/qtkite__defender-control.md - wiki/sources/descriptions/qtfreet00__AntiFrida.md - wiki/sources/descriptions/qiufuyu123__Positron.md - wiki/sources/descriptions/lfreist__hwinfo.md - wiki/sources/descriptions/lavoiesl__osx-cpu-temp.md - wiki/sources/descriptions/paradoxwastaken__WindowsHardwareInfo.md - wiki/sources/descriptions/openhardwaremonitor__openhardwaremonitor.md - wiki/sources/descriptions/olafhartong__BamboozlEDR.md - wiki/sources/descriptions/notscimmy__libelevate.md - wiki/sources/descriptions/gmh5225__Handle-Ripper.md - wiki/sources/descriptions/gmh5225__LSASS-DumpThatLSASS.md - wiki/sources/descriptions/b4rtik__ATPMiniDump.md - wiki/sources/descriptions/not1cyyy__Kiroshi.md - wiki/sources/descriptions/not1cyyy__Anti-Cheat-Amateur.md - wiki/sources/descriptions/not1cyyy__PowerVM.md - wiki/sources/descriptions/notgoodusename__OsirisAndExtra.md - wiki/sources/descriptions/nkga__cheat-driver.md - wiki/sources/descriptions/nikaiw__VMkatz.md - wiki/sources/descriptions/nickcano__RelocBonus.md - wiki/sources/descriptions/caprinux__rel-fuscate.md - wiki/sources/descriptions/can1357__ThePerfectInjector.md - wiki/sources/descriptions/magnussen7__Embuche.md - wiki/sources/descriptions/ls9512__USecurity.md - wiki/sources/descriptions/litemars__hARMless.md - wiki/sources/descriptions/longqun__Packer.md - wiki/sources/descriptions/cxxrev0to1dev__nb_obfuscator.md - wiki/sources/descriptions/cursey__x64-virtualizer-rs.md - wiki/sources/descriptions/czs108__PE-Packer.md - wiki/sources/descriptions/gmh5225__AtomPePacker.md - wiki/sources/descriptions/hid3rx__PEPacker.md - wiki/sources/descriptions/jnastarot__HIGU_ntcall.md - wiki/sources/descriptions/jnastarot__shibari.md - wiki/sources/descriptions/jnastarot__furikuri.md - wiki/sources/descriptions/jnastarot__ice9.md - wiki/sources/descriptions/jnastarot__anti-cheat.md - wiki/sources/descriptions/maoabc__nmmp.md - wiki/sources/descriptions/nulli83__Mj-lnir.md - wiki/sources/descriptions/gmh5225__ce-EasyAntiCheat-Bypass.md - wiki/sources/descriptions/NulledNah__cheat-engine-undetectable.md - wiki/sources/descriptions/gmh5225__Bypassing-EasyAntiCheat-Integrity-check.md - wiki/sources/descriptions/gmh5225__EazyAntiCheatSRC.md - wiki/sources/descriptions/gmh5225__EAC-EasyAntiCheat-Src-1.md - wiki/sources/descriptions/gmh5225__EasyAntiCheat-Reversing.md - wiki/sources/descriptions/gmh5225__EAC.md - wiki/sources/descriptions/chaeyk__eac-leak.md - wiki/sources/descriptions/ch4ncellor__EAC-Reversal.md - wiki/sources/descriptions/BishopTopG__all-about-eac.md - wiki/sources/descriptions/gmh5225__EAC-Driver-UD-for-now.md - wiki/sources/descriptions/gmh5225__EAC-EasyAntiCheatMemorySig.md - wiki/sources/descriptions/gmh5225__EAC-shellcode-1.md - wiki/sources/descriptions/gmh5225__EAC-VmCheck.asm.md - wiki/sources/descriptions/gmh5225__EAC-Kernel-Packet-Fucker.md - wiki/sources/descriptions/gmh5225__EAC-HydraHook.md - wiki/sources/descriptions/gmh5225__EAC-Runtime-Extractor.md - wiki/sources/descriptions/gmh5225__byfron-bypass.md - wiki/sources/descriptions/gmh5225__PAGE_NO_ACCESS-not-byfron.md - wiki/sources/descriptions/gmh5225__NeacSafe-Analysis.md - wiki/sources/descriptions/gmh5225__CapcomLib.md - wiki/sources/descriptions/gmh5225__CyberAntLoader.md - wiki/sources/descriptions/fiord__ADB-Debug-Detect-Checker.md - wiki/sources/descriptions/absoIute__Speedhack.md - wiki/sources/descriptions/poli0981__wardsweep.md - wiki/sources/descriptions/Veuqx0__ImGui-Spoofer-Leaked.md - wiki/sources/descriptions/Theordernarkoz__Hwid-Spoofer.md - wiki/sources/descriptions/Theordernarkoz__Hwid--Spoofer.md - wiki/sources/descriptions/TheMille-Dev__AntiGuard.md - wiki/sources/descriptions/VeroFess__PalWorld-Server-Unoffical-Fix.md - wiki/sources/descriptions/Visual1mpact__Paradox_AntiCheat.md - wiki/sources/descriptions/Washi1337__AwaitFuscator.md - wiki/sources/descriptions/WeiNaYongQ__OmniClutch.md - wiki/sources/descriptions/Shadow-46__adaptive-boss-arena.md - wiki/sources/descriptions/Timehue__ShinobiX.md - wiki/sources/descriptions/aryribeiro__cobra.md - wiki/sources/descriptions/Ricardonacif__launcher-abuser.md - wiki/sources/descriptions/IcEy-999__Drv_Hide_And_Camouflage.md - wiki/sources/descriptions/ExpLife0011__HideDriver.md - wiki/sources/descriptions/IamSanjid__ce_speed_hack.md - wiki/sources/descriptions/IamFriendly0242u__The-Dreamers-Guards.md - wiki/sources/descriptions/Idov31__NovaHypervisor.md - wiki/sources/descriptions/Idov31__Venom.md - wiki/sources/descriptions/ION28__BLUESPAWN.md - wiki/sources/descriptions/Remus3__Lanternlight.md - wiki/sources/descriptions/RiseShieldDev__AntiXrayViewer.md - wiki/sources/descriptions/boggymc__PetalAntiFreecam.md - wiki/sources/descriptions/trevorftp__ServerGuard.md - wiki/sources/descriptions/Pryaxis__TShock.md - wiki/sources/descriptions/Rwkeith__Diglett.md - wiki/sources/descriptions/Rwkeith__Nomad.md - wiki/sources/descriptions/Rycooop__Bloom-Anticheat.md - wiki/sources/descriptions/no1qq__RustBlox.md - wiki/sources/descriptions/no1qq__UAGC.md - wiki/sources/descriptions/Lazyzouo__ICUAC.md - wiki/sources/descriptions/LAC-Japan__IDA_Plugin_AntiDebugSeeker.md - wiki/sources/descriptions/LaihoE__DLAC.md - wiki/sources/descriptions/NHCM-dev__BytecodeVM.md - wiki/sources/descriptions/DownWithUp__CallMon.md - wiki/sources/descriptions/0xcpu__WinAltSyscallHandler.md - wiki/sources/descriptions/Dor00tkit__BamExtensionTableHook.md - wiki/sources/descriptions/D4stiny__PeaceMaker.md - wiki/sources/descriptions/Dead-Scripts__Dead_antiCheat.md - wiki/sources/descriptions/u8012146108-bit__anticheat-qa.md - wiki/sources/descriptions/CodeMaxx__windows-runtime-attestation-report.md - wiki/sources/descriptions/AdvDebug__AntiCrack-DotNet.md - wiki/sources/descriptions/Ahora57__MAJESTY-technologies.md - wiki/sources/descriptions/ApexLegendsUC__anti-cheat-emulator.md - wiki/sources/descriptions/lsxll666__AntiCheatToggle.md - wiki/sources/descriptions/BUNNY-19C__DLSSG-30s-manager.md updated: 2026-09-15 confidence: high --- # Anti-Cheat Layered game protection across kernel drivers, privileged services, in-game modules, and backend telemetry. Modern systems monitor handles, image loads, memory integrity, driver trust, virtualization abuse, DMA, and suspicious input. (source: wiki/sources/skills/anti-cheat.md) ## System map Map five roles before product-specific analysis: **protected asset** (fairness goal or integrity target), **attacker capability** (memory R/W, injection, DMA, synthesized input, etc.), **observation point** (client module, kernel driver, server replay, backend), **detector** (rule, model, heuristic), and **enforcement authority** (kick, ban, shadow flag, appeal workflow). Separate confirmed vendor or product behavior from general defensive patterns—README listings and bypass PoCs illustrate threat models and lab artifacts, not guaranteed live enforcement. (source: wiki/sources/skills/anti-cheat.md) ## Topic routing | Question lane | Route | |---------------|-------| | Product layers, client/kernel/memory/process/behavior signals | Detection methodology below; [[easy-anti-cheat]], [[battleye]], major-system entries | | Analysis methods, bypass categories, telemetry ethics | [[research-rigor]]; README `Detection:*` tree | | Collection source selection | [[resource-selection]], [[repository-navigation]] | | Input trust, units, missing-event coverage | [[input-provenance]] | | Shadow/canary rollout, collector faults vs misconduct | [[detector-operations]] | | Shared network, association, rate-limit vs sanction | [[network-environment-evidence]] | | DMA/PCIe boundary dominates | [[overviews/dma-attack]], [[dma]] | | Kernel driver trust dominates | [[overviews/windows-kernel]] | | Graphics/present path dominates | [[overviews/graphics-api]] | | Mobile integrity dominates | [[overviews/mobile-security]], [[mobile-anti-cheat]] | Use sibling skill topics when one boundary dominates the question; apply [[research-rigor]] to consequential or disputed claims. (source: wiki/sources/skills/anti-cheat.md) ## Detection methodology Use [[research-rigor]] when turning detector hits into enforcement. The anti-cheat skill frames seven decision steps: (1) define the decision unit (player/engagement/session/account/device/build) with game mode, patch, platform, input method, and timeframe; (2) establish telemetry trust via [[input-provenance]] labels; (3) keep **observation → finding → attribution → action** separate—a detector hit is not proof of cheating or intent; (4) calibrate features, sample floors, and thresholds on representative held-out data; (5) measure deployment risk (prevalence, FPR/FNR, precision, recall, calibration, review volume); (6) corroborate with causally distinct signals and measured joint error—correlated detectors can fail together; (7) preserve counterevidence and appeal paths before high-impact punitive action. Invariant findings need rollback/reconnect/replication-delay/game-bug exclusions before calling exploitation; describe as state-integrity violations until exploitation and attribution are separately supported. (source: wiki/sources/skills/anti-cheat.md) **Evidence packages** should retain raw artifacts or immutable references, timestamps/ordering, schema/game/detector versions, feature transforms, threshold/model version, sample counts, provenance, contradictory evidence, limitations, and the exact rule that fired. For threat framing, describe each case by capability needed, resource exposed, trust boundary crossed, and observation point available—compare host, device, graphics, input, and server observations without assuming one collector sees all layers. Separate detector design from server/backend correctness (game-server-security skill lane; see [[overviews/overview]] routing), Linux/Proton observations ([[are-we-anti-cheat-yet]], [[linux-anticheat]]), firmware/DMA assurance ([[dma]], [[iommu]], [[hvci]]), and network association claims ([[network-environment-evidence]]). Production rollout, shadow/canary evaluation, and collector-health diagnosis follow [[detector-operations]]. (source: wiki/sources/skills/anti-cheat.md) [[game-cheating-exploit-detection-agent-skill]] (dungnotnull; Python) pairs a Claude Code skill with a six-step executable engine—statistical and invariant detectors for aimbots, wallhacks, macros, memory tampering, and economy/duplication exploits—plus CI-verifiable harnesses, telemetry ingestion, quality gates, and a self-updating knowledge base from academic/domain crawls for structured decision support. (source: wiki/sources/descriptions/dungnotnull__game-cheating-exploit-detection-agent-skill.md) Title-specific R6 ranked-stat suspicion tooling such as [[r6-intel]] (baldspots440; Node.js/Express; R6Data API K/D/headshot/win-rate heuristics with historical snapshot comparison and sample-size weighting; community integrity leads—not enforcement verdicts) illustrates third-party statistical anomaly scoring beside kernel AC under [[battleye]]. (source: wiki/sources/descriptions/baldspots440__R6Intel.md) [[r6-siege-battleye-launch-bug]] (brandenbailey23) is a Markdown launch-regression report for Siege Y11S3: client exit during the BattlEye + Ubisoft Sentinel handshake on standard paths while `RainbowSixHelper.exe` succeeds—structured Windows/Ubisoft/BEDaisy evidence and checksum parity support launch-path bootstrapping or server-side negotiation hypotheses over corrupt installs. (source: wiki/sources/descriptions/brandenbailey23__r6-siege-battleye-launch-bug.md) Structured research indexes such as [[anti-cheat-research-index]] catalog public AC architecture, kernel execution/memory integrity, VT-x/EPT instrumentation, graphics presentation-path integrity, and x86/x64 RE references (shellcode, attach, present-hook, hardware-trace detection) for defensive engineering—not a standalone codebase. (source: wiki/sources/descriptions/xhscfq__anti-cheat-research-index.md) Defensive write-ups on publicly disclosed Windows kernel CVEs from anti-cheat/EDR telemetry and mitigation angles such as [[kernel-cve-analysis]] (thexin7; IOCTL/load/token/crash signals, Sigma sketches, hardening checklists) sit in the same Guide lane. (source: wiki/sources/descriptions/thexin7__kernel-cve-analysis.md) Foundational C **linking/loading/executable-format** guide [[underthehoodofexecutables]] supports the same defensive-engineering primer lane. (source: wiki/sources/descriptions/gmh5225__underTheHoodOfExecutables.md) Unconventional AC design notes such as [[weird-anti-cheat-ideas]] (gmh5225; anti-cheat research, networking, and modding surfaces) collect offbeat defensive ideas for AC engineers. (source: wiki/sources/descriptions/gmh5225__WeirdAntiCheatIdeas.md) Unity reference [[adaptive-boss-arena]] (Shadow-46; assembly firewalls + delayed perception so adaptive boss AI cannot read raw player input—cheat-resistant PvE fairness pattern with edit/play-mode tests) complements that design lane. (source: wiki/sources/descriptions/Shadow-46__adaptive-boss-arena.md) Legitimate post-uninstall AC residue cleanup such as [[wardsweep]] (poli0981; Rust broker + WPF UI; signed TOML catalog for Vanguard/EAC/BattlEye/ACE; read-only audit, official uninstallers, orphan driver/service/registry/filesystem sweep with quarantine/rollback; split-privilege IPC; rejects ban evasion and runtime AC tampering) complements forensic inspection tools—not an AC bypass lane. (source: wiki/sources/descriptions/poli0981__wardsweep.md) ## Major systems - [[easy-anti-cheat]] — service + driver + game-facing integrity (Fortnite, Apex, Rust); Integrity Checks PoC [[cveac-2020]] (WDK driver vs EAC kernel-module vuln; enum / PE / hooks) (source: wiki/sources/descriptions/thesecretclub__CVEAC-2020.md); CE tool-detection bypass [[ce-easyanticheat-bypass]] (CE process/window class/driver/memory-access signature evasion; cheat / UD CE; gmh5225) (source: wiki/sources/descriptions/gmh5225__ce-EasyAntiCheat-Bypass.md); multi-tier CE evasion research build [[cheat-engine-undetectable]] (NulledNah; direct syscalls, PE metadata mutation, BYOVD kernel bridge with CR3 memory access and ObCallback bypass; AC architecture study) (source: wiki/sources/descriptions/NulledNah__cheat-engine-undetectable.md); driver-assisted Rust external cheat samples such as [[lord-abbot-rust-external-cheat]] (LordAbbot; custom kernel driver + external DLL + ImGui/DirectX overlay; ESP/aimbot/recoil; AC detection-surface study around kernel-assisted externals; cheat / game:rust [External]) (source: wiki/sources/descriptions/LordAbbot__Rust-External-Cheat.md); static RustSecure client-agent RE [[rustsecure-re]] (Leeksov; loader/encrypted payload/CLR bridge/Core DLL; 13 detection modules—anti-debug/VM, direct NT syscalls, HWID, BepInEx/kdmapper, screenshots, WebSocket telemetry; Python/C# decrypt/deobfuscate tooling; static-only ILSpy/dnfile/IDA; Anti Cheat / game:rust) (source: wiki/sources/descriptions/Leeksov__rustsecure-re.md) - [[eac-extractor-utility]] — decrypt/extract EAC kernel driver, UM modules, and config from game dir + driver store for offline static RE (Dump lane) (source: wiki/sources/descriptions/lguilhermee__EAC-Extractor-Utility.md) - [[eac-runtime-extractor]] — MinHook DLL intercepts file I/O + driver load; captures EAC kernel driver from memory before disk write for offline RE (Runtime dump lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC-Runtime-Extractor.md) - [[eazy-anti-cheat-src]] — reversed EAC source representation: reimplemented detection routines, driver communication, and integrity validation from binary analysis (Reversed Source lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EazyAntiCheatSRC.md) - [[eac-easyanticheat-src-1]] — reconstructed/leaked EAC source representation: internal detection routines, driver communication protocols, and client-side integrity validation (Reversed Source lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC-EasyAntiCheat-Src-1.md) - [[easyanticheat-reversing]] — IDA Pro 7.7 decompilation dump of `EasyAntiCheat.sys`; searchable C-like driver output with registry strings and policy routines (Decompile dump lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EasyAntiCheat-Reversing.md) - [[easyanticheat-src]] — Hex-Rays decompiled source-style snapshot of EAC kernel driver; large C output + headers with function prototypes and data structures; process memory ops, validation, and anti-cheat control paths (Decompile dump lane; EBalloon) (source: wiki/sources/descriptions/EBalloon__EasyAntiCheat-SRC.md) - [[eac]] — mixed EAC study pack: reversed `easyanticheat.sys` kernel callback/heuristic logic + EAC/EOS SDK drop with headers and `EOS_FileDecryptionTool` (Study pack lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC.md) - [[eac-reversal]] — updated devirtualized EAC driver internals: callback checks, dispatch verification, callback enumeration, certificate validation, and code integrity as C++ pseudocode (Reversed driver lane; ch4ncellor) (source: wiki/sources/descriptions/ch4ncellor__EAC-Reversal.md) - [[all-about-eac]] — Memflow-only external-VM RE dossier on one captured Fortnite `EasyAntiCheat_EOS.sys` build; passive physical-memory acquisition + matched kernel PDB layouts; maps process/thread/image callbacks, Ob handle policy, registry callbacks, minifilter, device IPC, and per-thread callback contexts; evidence-labeled claims + Python validation; studies lifecycle/persistence/executable-mapping/platform-state monitoring; no bypass material (External VM memory-forensics lane; BishopTopG) (source: wiki/sources/descriptions/BishopTopG__all-about-eac.md) - [[eac-emu]] — simple x64 EAC DLL emulator stub; exports expected anti-cheat API functions with placeholder implementations; C++ plus assembly patch helpers; PoC for RE and compatibility testing of EAC-linked client code (Client stub lane; Rat431) (source: wiki/sources/descriptions/Rat431__EAC_Emu.md) - [[easyanticheat-emulator]] — lightweight EAC client-interface DLL stub; fake client-side exports so game binaries proceed as if anti-cheat is present; debugging-oriented; no server-side protocol spoofing (Client stub lane; CamxxCore [EAC Emulator]) (source: wiki/sources/descriptions/CamxxCore__EasyAntiCheat-Emulator.md) - [[eac-leak]] — leaked EAC server implementation with EOS SDK anti-cheat session handling; game-server ↔ EAC cloud validation protocol RE (Server-side lane; chaeyk) (source: wiki/sources/descriptions/chaeyk__eac-leak.md) - [[eac-shellcode-1]] — archived raw EAC shellcode memory dump (~8.5 MB; hook entry points base+0x79204 / base+0x79304) from protected-game dumper ~Mar 2023 for offline shellcode layout / hook-flow RE (Shellcode lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC-shellcode-1.md) - [[eac-vmcheck-asm]] — recovered `easyanticheat.sys` VM-detection assembly (`CheckVM` → `ExecVMREAD`; VMREAD probe; VM-found / VM-not-found branches) from driver `vm` directory for offline virtualization-check RE (Virtual machine checking lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC-VmCheck.asm.md) - [[eac-easyanticheatmemorysig]] — documented EAC in-memory byte-pattern corpus for known cheat frameworks, injectors, and hack modules (Memory sig maker lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC-EasyAntiCheatMemorySig.md) - [[eac-bypass]] — offensive EAC bypass research (C++; kernel driver + shader work; cheat / explore anticheat:eac) (source: wiki/sources/descriptions/ksoju__Eac-Bypass.md) - [[eac-dbp]] — EAC debug/bypass PoC; kernel driver + user-mode module; callback/minifilter/control-path interference + user-layer API interception; Visual Studio/WDK; controlled RE and security testing of EAC-protected processes (Debug lane; Schnocker) (source: wiki/sources/descriptions/Schnocker__EAC_dbp.md) - [[eac-kernel-packet-fucker]] — kernel-mode EAC telemetry suppression; hijacks dynamically imported `ExAllocatePoolWithTag` via writable section pointer so ~33 KB violation reports fail allocation and never reach backend servers (Packet suppression lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC-Kernel-Packet-Fucker.md) - [[eac-hydrahook]] — Hydra KM↔UM channel hooking framework; intercepts and suppresses EAC detection reports on the Hydra protocol before backend upload (Packet suppression lane; gmh5225) (source: wiki/sources/descriptions/gmh5225__EAC-HydraHook.md) - [[eac-driver-ud-for-now]] — kernel driver framed to evade EAC driver scanning; cross-process memory R/W via stealth KM↔UM channel avoiding known kernel-cheat detection vectors (Offensive driver UD lane; gmh5225 [Sample]) (source: wiki/sources/descriptions/gmh5225__EAC-Driver-UD-for-now.md) - [[bypassing-easyanticheat-integrity-check]] — EAC kernel driver self-integrity RE + bypass; CreateProcess/LoadImage notify section validation; Capstone garbage-instruction stripper; reconstructed C++ section-compare against stored driver copy (Integrity check bypass lane; gmh5225 [Bypassing integrity check]) (source: wiki/sources/descriptions/gmh5225__Bypassing-EasyAntiCheat-Integrity-check.md) - [[hiearchy-eac]] — EAC kernel driver self-integrity bypass PoC; call-hierarchy + memory-read manipulation; hooks verification routines toward cleaned image copy; module-load monitoring; EAC driver boundary tracking; stack/register spoofing during integrity accesses (Integrity Checks lane; Sinclairq) (source: wiki/sources/descriptions/Sinclairq__hiearchy-eac.md) - [[battleye]] — handle protection, process/memory scanning (PUBG, R6, DayZ); research ref [[blindeye]] drops BE report-path pool allocs via hooked `ExAllocatePool*` (source: wiki/sources/descriptions/zouxianyu__BlindEye.md); user-mode shellcode RE via [[be-shellcode]] (dump/disasm thread scan, VEH enum, module integrity) (source: wiki/sources/descriptions/weak1337__BE-Shellcode.md); runtime server-streamed scanning modules intercepted pre-execution via [[battleye-shellcode-dumper]] (payloads + decryption keys; BEClient2.dll Dumper) (source: wiki/sources/descriptions/lguilhermee__Battleye-Shellcode-Dumper.md); runtime shellcode module dump via [[be-shellcode-dump]] (gmh5225; Reversed BE Shellcode; offline RE of detection signatures) (source: wiki/sources/descriptions/gmh5225__be_shellcode_dump.md); recent BE shellcode scan-stage reimplementation via [[be-battleye-shellcode]] (gmh5225; DLL study scaffold; hidden system threads, KiUserExceptionDispatcher hook detection, module/signature/thread scans, VEH-guarded Win32/CRT targets; [shellcode]) (source: wiki/sources/descriptions/gmh5225__BE-BattlEye_shellcode.md); sandbox execution/analysis of dumped BE shellcode modules via [[be-shellcode-tester]] (es3n1n; C++; logs memory scans, hash checks, detection routines; controlled RE without live game) (source: wiki/sources/descriptions/es3n1n__be-shellcode-tester.md); VirtualQuery region-walk heuristics for shellcode/manual-map via [[battleye-region-walking]] (source: wiki/sources/descriptions/tr1xxx__battleye-region-walking.md); title-specific BattlEye Tool [[arma3beclient]] (C# / PowerShell; Arma 3) (source: wiki/sources/descriptions/tym32167__arma3beclient.md); external Arma 3 mission-variable editor [[arma3-external-variable-manager]] (Skengdo; C++; dump/read/edit active mission vars; BE-disabled servers; extra bypass noted for online BE-protected use; cheat / game:arma3 [External]) (source: wiki/sources/descriptions/Skengdo__arma3-external-variable-manager.md); RCON UDP protocol lib [[battleye-rust]] (Rust; packet checksum + socket I/O) (source: wiki/sources/descriptions/steffalon__battleye-rust.md); init emulator [[fakeeye]] (Hypercall; lightweight C++ BattlEye-style launcher-side emulator; SCM + BE-style game launch; isolated lab compatibility testing; [Emulator]) (source: wiki/sources/descriptions/Hypercall__FakeEye.md); historical service-layer bypass toolkit [[noeye]] (Schnocker; C++ service/runtime + C# setup; service install, process interaction, runtime control; older BE bypass reference) (source: wiki/sources/descriptions/Schnocker__NoEye.md); client-side protocol emulator [[be-emulator]] (gmh5225; BE comm protocol, heartbeat, module-load interface; run without active BE; explore anticheat system:be) (source: wiki/sources/descriptions/gmh5225__BE-Emulator.md); minimal BE client DLL interface PoC [[beclient]] (LilPidgey; C++; callback registration + run/command/exit handlers; client integration RE scaffold) (source: wiki/sources/descriptions/LilPidgey__BEClient.md); handle-stripping bypass [[battleye-handler-bypass]] (KMDF driver; re-create handles before ~5s BE cleanup; IOCTL usermode comms) (source: wiki/sources/descriptions/masterpastaa__BattlEye-Handler-BYPASS.md); handle-access assumption study [[badeye]] (gmh5225; C++ memory analysis; BE trusts handle rights and uses handles only for EPROCESS→MmCopyVirtualMemory; cheat / explore anticheat system:be) (source: wiki/sources/descriptions/gmh5225__BadEye.md); BEDaisy.sys report suppression [[bedaisy-bypass]] (block outbound reports; preserve service responses; cheat / explore anticheat system:be) (source: wiki/sources/descriptions/gmh5225__bedaisy-bypass.md); BEDaisy.sys RE reference [[battleye-re]] (experienceds; PE layout, dynamic kernel API resolve, IOCTL dispatch, HAL verification, anti-DMA, VM obfuscation, security-cookie derivation; JSON/disasm/hex corpus; educational RE) (source: wiki/sources/descriptions/experienceds__battleye-re.md); comprehensive BEDaisy detection-mechanism RE [[bedaisy-reversal]] (dllcrt0; integrity validation, callback enumeration, HAL verify, manual-map detection, handle protection, minifilter checks, physmem scan, CSRSS integrity, graphics verify, thread/image notify callbacks; educational RE) (source: wiki/sources/descriptions/dllcrt0__bedaisy-reversal.md); decompiled BE UM shellcode modules [[battleye-shellcode]] (dllcrt0; AutoHotKey detection, swap-chain Present hook scan, stack-walking return-address checks; runtime integrity RE; [shellcode]) (source: wiki/sources/descriptions/dllcrt0__battleye-shellcode.md); BEService↔BEDaisy named-pipe packet decryption [[battleye-decryption]] (dllcrt0; XOR multi-layer decrypt, hardware-info crypto, second-stage key-derived routines; client-driver comm protocol RE) (source: wiki/sources/descriptions/dllcrt0__battleye-decryption.md); Fortnite BE init forcer [[be-forcer-fortnite]] (gmh5225; forces/manipulates BE initialization to disable title-specific detection checks; cheat injection / memory access; cheat / explore anticheat system:be / game:fortnite) (source: wiki/sources/descriptions/gmh5225__BE-Forcer-Fortnite.md); user-mode-only BE-compatible injector [[splendid-implanter]] (secret.club; exploits UM BE flaw; Injector) (source: wiki/sources/descriptions/haram__splendid_implanter.md); historical UM loading-path bypass PoC [[battleye-user-mode-bypass]] (HadockKali; C++ Visual Studio implanter + sample DLL; CreateFileW hook + file-check masquerade; trusted-module masquerade; SetWindowsHookExW) (source: wiki/sources/descriptions/HadockKali__battleye-user-mode-bypass.md) - [[vanguard]] — boot-start driver, early driver allowlisting (Valorant, LoL); update alerts via [[vanguard-update-notifier]] (Discord bot; clientconfig poll + setup hash drift) (source: wiki/sources/descriptions/luavmload__vanguard-update-notifier.md); SCM auto-start control via [[vanguard-service-manager-vgk-control]] (`vgkChecker` status + `noVanguard` auto-start toggle; Karwmam) (source: wiki/sources/descriptions/Karwmam__Vanguard-Service-Manager-vGK-Control.md); illegal PF logging via [[vgk-illegal-pf-logger]] (`vgk.sys` page-fault integrity checks) (source: wiki/sources/descriptions/gmh5225__vgk-illegal-pf-logger.md); RITO streamed-module → PE via [[augur-riot]] (hashed import resolve, section reconstruct; gmh5225) (source: wiki/sources/descriptions/gmh5225__augur-riot.md); protected `vgk` import resolve via [[vanguard-import-resolver]] (kernel import address resolution; import-protection RE; gmh5225) (source: wiki/sources/descriptions/gmh5225__VanguardImportResolver.md); encrypted import decrypt/intercept via [[vanguardtrace]] (signature-scan import table, decrypt/re-encrypt hook flow; `CiCheckSignedFile` sample; armvirus) (source: wiki/sources/descriptions/armvirus__VanguardTrace.md); driver-assisted Valorant external cheat frameworks such as [[valorant-cheat-external]] (AryuInka; C++ aimbot/ESP; overlay rendering + HWID-spoofing workflows; bundled bypass tooling; cheat / game:valorant `[External]`) illustrate kernel-assisted out-of-process threats under Valorant (source: wiki/sources/descriptions/AryuInka__Valorant-Cheat-External.md); out-of-process TFT OCR automation such as [[tft-ocr-bot]] (Python; overlay + screen OCR; no injection; cheat / game:lol `[TFT]`) illustrates visual-bot threats beside kernel-protected LoL clients (source: wiki/sources/descriptions/gmh5225__TFT-OCR-BOT.md) - FACEIT AC — [[ec-pro-lan]] (ekknod; C++/C; driver development / OpenGL; cheat / explore anticheat system:faceit) (source: wiki/sources/descriptions/ekknod__EC_PRO-LAN.md); VAC (user-mode signatures), GameGuard — curated online-game security papers and corpora such as [[hacking-online-games]] (dsasmblr; GameGuard architecture, map-hack prevention, MMORPG protocol deciphering; cheat / guide) (source: wiki/sources/descriptions/dsasmblr__hacking-online-games.md), XIGNCODE3 — title-specific TWMS live-client GameGuard bypass notes and packet/crypto corpora such as [[twms-hacking-data]] (gmh5225; memory offsets, packet structures, encryption keys; cheat / game:maplestory [TMS CT]) (source: wiki/sources/descriptions/gmh5225__TWMS-Hacking-Data.md); static reconstruction [[xigncode3-blackdesert]] (Black Desert: `xmag`/`xnina` unpack → 17 UM modules, Lua 5.3, VMProtect `xhunter1`; IPC/detection specs + live capture) (source: wiki/sources/descriptions/miyakejima__xigncode3-blackdesert.md); client-module dump [[xigncode-dump]] (gmh5225; modding / offline RE; cheat / explore anticheat:xigncode) (source: wiki/sources/descriptions/gmh5225__XignCode-Dump.md); vuln PoC [[xign-poc-april-2026]] on `xhunter64.sys` `IRP_MJ_WRITE` → phys R/W / kernel leak / process kill (source: wiki/sources/descriptions/waryas__xign_poc_april_2026.md); Rust PoC suite [[axhunter]] (BlackSnufkin; `xhunter1.sys`/`xhunter2.sys` CVE-2026-15430; WriteFile command frames → auth bypass, PPL-bypass handles, arbitrary process R/W, LSA/WDigest credential extraction, Defender handle close, SYSTEM via winlogon; driver exploitation research) (source: wiki/sources/descriptions/BlackSnufkin__AxHunter.md); bypass research [[xigncode3-bypass-alternative]] / [[xigncode3-bypass]] (C++; hooking / memory analysis; cheat / explore anticheat:xigncode; gmh5225) (source: wiki/sources/descriptions/gmh5225__XignCode3-bypass-alternative.md); NetEase **NeacSafe** minifilter IPC probe [[neacsafe-analysis]] (C++; `FilterConnectCommunicationPort` on `\NeacSafePort`, 0x28-byte `NeacSafeConnectContext`, encoded request buffers; Pediy writeup reproduction; explore anticheat; gmh5225) (source: wiki/sources/descriptions/gmh5225__NeacSafe-Analysis.md); ACE, Warden (Blizzard / WoW) - EQU8 — [[equ8-poc]] full C++ kernel driver reimplementation from companion article (explore anticheat:equ8; driver development / kernel RE) (source: wiki/sources/descriptions/kkent030315__EQU8-PoC.md); user-mode bypass [[equ8-bypass]] (registry driver-path lookup + IOCTL handle close; cheat / explore anticheat:equ8) (source: wiki/sources/descriptions/hotline1337__equ8_bypass.md) - Byfron (Roblox client AC) — [[byfron-bypass]] offensive bypass research (C++; asset pipelines / editor tooling; cheat / explore anticheat:byfron; gmh5225) (source: wiki/sources/descriptions/gmh5225__byfron-bypass.md); third-party Windows launcher [[rustblox]] (no1qq; Rust; isolated official-CDN Roblox install; **TheWatcher** client-side watchdog scans cheat processes, suspicious memory, DLL injection, and script executors while Roblox runs; FastFlags + egui dashboard) adds optional session protection beside the default client (source: wiki/sources/descriptions/no1qq__RustBlox.md) - [[vac3-inhibitor]] — C++ VAC3 exploration (hooking / memory analysis) under cheat → explore anticheat:vac (source: wiki/sources/descriptions/zyhp__vac3_inhibitor.md) - [[vac3-dumper]] — dumps VAC3 modules loaded at different times for offline RE (Dump lane) (source: wiki/sources/descriptions/x1tan__vac3-dumper.md) - [[vackeyretrieval]] — retrieves VAC module ICE encryption key (C++; explore anticheat:vac) (source: wiki/sources/descriptions/shuruk421__VACKeyRetrieval.md) - [[vac-module-dumper]] — VAC module dump for offline RE (C/C++; Dump lane; explore anticheat:vac) (source: wiki/sources/descriptions/nevioo1337__VAC-ModuleDumper.md) - [[vac-dumper]] — DLL injected into `steam.exe`; MinHook on `steamservice.dll` VAC module loader; live capture at load time to `C:\Modules` (gmh5225; Dump lane; explore anticheat:vac) (source: wiki/sources/descriptions/gmh5225__VACDumper.md) - [[dumpvac]] — PoC to disable VAC module execution and dump received modules with automatic decryption; hooks Steam/module-loading paths (RenardDev; C/C++; Dump lane; explore anticheat:vac) (source: wiki/sources/descriptions/RenardDev__DumpVAC.md) - [[vacation3-emu]] — C++ VAC3 module emulator (fake game memory + scan logging outside Steam; explore anticheat:vac) (source: wiki/sources/descriptions/ioncodes__vacation3-emu.md) - [[vac-emulator]] — VAC module emulator (sandboxed module execution + detection/signature logging; gmh5225; explore anticheat:vac) (source: wiki/sources/descriptions/gmh5225__Vac-Emulator.md) - [[prevent-vac]] — hooks `steamserver.dll` and WinAPI returns to spoof monitoring errors; `vac_monitor_manager` fully blocks VAC game monitoring (trust-factor side effect noted; gmh5225; explore anticheat:vac) (source: wiki/sources/descriptions/gmh5225__PreventVAC.md) - [[hwid-steam-spyware-terminator]] — blocks or removes Steam client hardware fingerprinting and telemetry so HWID data is not transmitted to Valve servers (gmh5225; README [Steam]) (source: wiki/sources/descriptions/gmh5225__HWID-SteamSpywareTerminator.md) - [[vook]] — VAC hook research (explore anticheat:vac) (source: wiki/sources/descriptions/krispybyte__Vook.md) - [[vac-hooks]] — C DLL hooks WinAPI functions used by VAC; log calls and intercept arguments/return values (danielkrupinski; explore anticheat:vac) (source: wiki/sources/descriptions/danielkrupinski__vac-hooks.md) - [[vac-bypass]] — C DLL disables VAC scanning in Steam client; injects into `Steam.exe`, patches `steamservice.dll`, hooks `LoadLibraryExW`/`GetProcAddress`/`GetSystemInfo` so VAC modules abort scans (danielkrupinski; explore anticheat:vac) (source: wiki/sources/descriptions/danielkrupinski__VAC-Bypass.md) - [[jackbail4-vac-bypass]] — archived C++ Detours PoC; signature scan + internal routine patching; hooks `VirtualQuery`, process/module enumeration, debugger checks, and memory-read paths to reduce VAC scanner visibility in Steam service context (Jackbail4; non-working; historical bypass research) (source: wiki/sources/descriptions/Jackbail4__VAC-Bypass.md) - [[vac-bypass-loader]] — C loader/injector for [[vac-bypass]] into Steam (VS 2019 / v142; danielkrupinski; explore anticheat:vac) (source: wiki/sources/descriptions/danielkrupinski__VAC-Bypass-Loader.md) - [[vac-bypass-kernel]] — kernel-mode VAC bypass against external scanner memory reads via syscalls such as `NtReadVirtualMemory` (crvvdev; explore anticheat:vac) (source: wiki/sources/descriptions/crvvdev__vac-bypass-kernel.md) - [[vac]] — decompiled/annotated VAC module RE corpus (detection modules, signature scanning, process memory checks, module integrity verification, Steam server comms; danielkrupinski; explore anticheat:vac) (source: wiki/sources/descriptions/danielkrupinski__VAC.md) - [[valveanticheat1]] — GoldSrc/WON-era VAC1 ModuleC/ModuleS bytecode-VM rebuild (2002–2004; RE notes + decrypt/repack tooling) for studying early network-delivered detection architecture (source: wiki/sources/descriptions/shefben__VALVeAntiCheat1.md) - [[como-funciona-vac]] — CS2 VAC usermode architecture write-up (Trusted Launch in `cs2.exe`, `client.dll` scanners, `steam.exe` external scanner; PE hashing, interface CRC, thread inspection, VEH hardware-breakpoint checks, protobuf evidence reports; forensic overview, not a bypass) (source: wiki/sources/descriptions/ianveig29__como-funciona-vac.md) - [[cs2-anticheat]] — CS2 in-binary anticheat code documentation (danielkrupinski; June 2023 update snapshot; modding/debugging; explore anticheat:cs2) (source: wiki/sources/descriptions/danielkrupinski__cs2-anticheat.md) - [[cs2-p2c-templates]] — CS2 VAC Live P2C research templates (ccsimplyspolit; VMProtect-protected anti-VAC helper RE port; `VacLiveBypass` input-history/view-angle protobuf mutation; kernel spoof drivers; explore anticheat:vac / cs2; insecure local or CTF study) (source: wiki/sources/descriptions/ccsimplyspolit__CS2-P2C-TEMPLATES.md) - [[hpcs2]] — External CS2 cheat test project (Half-People; C++ Visual Studio; process memory utilities + handle hijacking + INI-configured aim/RCS/ESP; educational study of out-of-process cheat surface and defender response against VAC-era external scanners; cheat / game:cs2 [External]) (source: wiki/sources/descriptions/Half-People__HPCS2.md) - [[dragonburn]] — External CS2 framework (ByteCorum; C++; kernel-assisted read-only memory access; ImGui ESP/radar overlays + offset automation; cheat development experiments and anti-cheat detection research; cheat / game:cs2 [External]) (source: wiki/sources/descriptions/ByteCorum__DragonBurn.md) - [[csgosimple]] — spirthack/MarkHC Internal CS:GO baseline for studying injected-cheat surface against VAC (source: wiki/sources/descriptions/spirthack__CSGOSimple.md) - [[csgo-aw-v5.1.13]] — leaked AimWare v5.1.13 internal CS:GO source (aimbot, visuals, movement, anti-aim, hooking framework) for studying commercial injected-cheat surface against VAC (source: wiki/sources/descriptions/gmh5225__CSGO-aw-v5.1.13.md) - [[csgo-nixware-csgo]] — leaked Nixware internal CS:GO source (aimbot, ESP, movement hacks, skin changer; full CS:GO SDK + ImGui overlay) for studying commercial injected-cheat surface against VAC (source: wiki/sources/descriptions/gmh5225__CSGO-NIXWARE-CSGO.md) - [[csgo-alphen]] — internal CS:GO source (full SDK with entity/weapon structures and rendering primitives; ImGui menu; ESP, aimbot, visual mods) for studying SDK-backed injected-cheat surface against VAC (source: wiki/sources/descriptions/gmh5225__CSGO-Alphen.md) - [[solace-csgo]] — internal CS:GO source (emilyinure; modern C++; polished ImGui menu; ESP, aimbot, triggerbot, movement assistance, skin changer, visual mods via Source SDK hooking; modular architecture) for studying injected-cheat surface and detection characteristics against VAC (source: wiki/sources/descriptions/emilyinure__solace-csgo.md) - [[osiris]] — open-source internal CS:GO cheat (danielkrupinski; ESP, glow, aimbot, triggerbot, backtrack, skin/inventory manipulation; interface pointers, pattern scanning, VMT hooking) for studying feature-complete Source 1 injected-cheat surface and detection characteristics against VAC (source: wiki/sources/descriptions/danielkrupinski__Osiris.md) - [[osiris-and-extra]] — Internal CS:GO sample (C/C++; driver / OpenGL / rendering) for studying injected-cheat surface against VAC (source: wiki/sources/descriptions/notgoodusename__OsirisAndExtra.md) - [[dainsleif]] — simple Internal CS:GO RE-training sample for studying injected-cheat surface against VAC (source: wiki/sources/descriptions/s3pt3mb3r__Dainsleif.md) - [[avhook]] — CS:GO training software (gmh5225; Windows; joke features) for studying injected-cheat surface against VAC (source: wiki/sources/descriptions/gmh5225__avhook.md) - [[sensum]] — actively developed Internal CS:GO sample for studying injected-cheat surface against VAC (source: wiki/sources/descriptions/martinjanas__Sensum.md) - [[gamesneeze]] — Linux CS:GO sample (seksea) for studying non-Windows cheat surface against VAC (source: wiki/sources/descriptions/seksea__gamesneeze.md) - [[csgo-linux-cheat-sdk]] — Linux CS:GO cheat SDK (otvv; C++; rendering / networking / modding) for studying non-Windows cheat surface against VAC (source: wiki/sources/descriptions/otvv__csgo-linux-cheat-sdk.md) - [[anubis]] — Linux-native internal CS:GO cheat (danielkrupinski; C++; process injection; ESP, aimbot via Source SDK hooks on client rendering and game events) for studying non-Windows injected-cheat surface against VAC (source: wiki/sources/descriptions/danielkrupinski__Anubis.md) - [[heck-csgo-external]] — External CS:GO sample (C++; SDK generation / memory analysis) for studying out-of-process cheat surface against VAC (source: wiki/sources/descriptions/soyware__heck_csgo_external.md) - [[csgo-cheat-external]] — External CS:GO sample (C++; driver development) for studying driver-backed out-of-process cheat surface against VAC (source: wiki/sources/descriptions/si1kyyy__csgo_cheat_external.md) - [[csgo-external-cheat]] — External CS:GO sample (C++; RPM or kernel-driver reads; ESP / aimbot / radar; no inject) for studying out-of-process cheat surface against VAC (source: wiki/sources/descriptions/rrpvm__csgo-external-cheat.md) - [[csgo-cheats]] — Tutorial external CS:GO examples (HeathHowren; C++; window/process attach + memory R/W wrappers; offset maintenance; beginner manipulation study and defender mapping of common external cheat patterns) (source: wiki/sources/descriptions/HeathHowren__CSGO-Cheats.md) - [[goesp]] — cross-platform external CS:GO ESP (danielkrupinski; Dear ImGui overlay; memory-read boxes/names/health/weapons via game render path; Windows and Linux) for studying external overlay ESP and overlay-based detection against VAC (source: wiki/sources/descriptions/danielkrupinski__GOESP.md) - External overlay window-hijack PoCs such as [[window-hijack-overlay]] (SurgeGotTappedAgain; reuse existing overlay HWNDs while preserving native flags; SetWindowsHookEx input; DX11/ImGui; studies visibility vs AC overlay-detection tradeoffs) complement overlay-monitoring and HWND-enumeration defenses. (source: wiki/sources/descriptions/SurgeGotTappedAgain__Window-Hijack.md) - [[topmost-detection]] — minimal Win32 HWND enumeration utility (Oliver-1-1; C++; visible-window scan + `WS_EX_TOPMOST` flagging; companion topmost test console via `SetWindowPos`; basic overlay-detection prototyping for AC development) (source: wiki/sources/descriptions/Oliver-1-1__TOPMOST-Detection.md) - [[autohotkey-l]] — upstream AutoHotkey interpreter platform (Lexikos; Windows macro/hotkey scripting; input automation; game-adjacent macro experimentation and defensive analysis of script-driven behavior; underpins script-based samples like [[csgo-external-ahk-hack]]) (source: wiki/sources/descriptions/Lexikos__AutoHotkey_L.md) - [[csgo-external-ahk-hack]] — AutoHotkey external CS:GO sample (gmh5225; script RPM; triggerbot / bhop / basic ESP; no compiled cheat binary) for studying script-based out-of-process cheat surface and detection characteristics against VAC (source: wiki/sources/descriptions/gmh5225__csgo_external_ahk_hack.md) - [[nv-v2]] — CS:GO sound ESP sample (ekknod; C/C++; hooking; audio-derived positional awareness without visual overlay; cheat / game:csgo [Sound ESP]) for studying non-visual ESP cheat surface against VAC (source: wiki/sources/descriptions/ekknod__nv_v2.md) - [[csgo-backtrack-patch]] — CS:GO backtrack patch sample (C/C++; hooking / memory analysis) for studying lag-compensation / tick-history cheat surface against VAC (source: wiki/sources/descriptions/sneakyevilSK__CSGO_BacktrackPatch.md) - [[kvm-csgo-cheat]] — Rust CS:GO cheat in QEMU/KVM/PVE/VBox lane (gmh5225) for studying VM-isolated / below-OS cheat surface against VAC (source: wiki/sources/descriptions/gmh5225__kvm-csgo-cheat.md) - [[cs16-trigger-kvm]] — KVM/QEMU host-side CS1.6 triggerbot (gmh5225; guest memory read + input injection invisible to in-guest AC) for studying hypervisor-based cheat surface (source: wiki/sources/descriptions/gmh5225__cs16-trigger-kvm.md) - [[cfclap]] — CrossFire (CF) memory-manipulation cheat sample (gmh5225; ESP / aimbot / combat advantages via client memory reads) for studying title-specific client-side protection and cheat-detection mechanisms (source: wiki/sources/descriptions/gmh5225__cfclap.md) - [[lost-ark]] — Lost Ark MMORPG client memory-manipulation cheat sample (gmh5225; ESP / gameplay mods / automation) for studying title-specific UE MMORPG client-side protection and cheat-detection mechanisms (source: wiki/sources/descriptions/gmh5225__LostArk.md) - [[unmapper]] — automatic dumped-PE header repair so decompilers load cleanly (Dump Fix) (source: wiki/sources/descriptions/t3ssellate__unmapper.md) - [[fix-arxan]] — Arxan PE protector: loader info + decrypted working image for research (Dump Fix) (source: wiki/sources/descriptions/pr701__fix-arxan.md) - [[s2x]] — runtime Arxan anti-tamper bypass, code healing, and integrity-check neutralization in a COD MW2 (2009) client mod framework (Brentdevent; Anti Tamper / Integrity) (source: wiki/sources/descriptions/Brentdevent__S2x.md) - [[android-unpacker]] — Android packed-sample unpack tooling for malware RE (Sample Unpacker; handle samples carefully) (source: wiki/sources/descriptions/strazzere__android-unpacker.md) - [[mal-unpack-drv]] — experimental test-signed kernel driver for Windows malware sample unpacking (VM-only; Sample Unpacker) (source: wiki/sources/descriptions/hasherezade__mal_unpack_drv.md) - [[malicious-code-detection-bugu]] — Go gRPC microservices malware-scan platform (Bugu; file upload, hash verification, automated analysis; Protobuf gRPC+HTTP API; gmh5225; Malicious code detection and obfuscation) (source: wiki/sources/descriptions/gmh5225__Malicious-code-detection-bugu.md) - [[pandora]] — file-suspicion analysis framework with convenient result UI (Analysis Framework; Ubuntu 24.04 recommended) (source: wiki/sources/descriptions/pandora-analysis__pandora.md) - [[kiroshi]] — IDA Pro plugin to detect common Anti-Cheat artifacts (RE/academic; cheat / IDA Plugins) (source: wiki/sources/descriptions/not1cyyy__Kiroshi.md) - [[anti-cheat-amateur]] — MemRE injectable memory editor + GothGirlFeet kdmapper-compatible KMDF driver (NUL-device IOCTL cross-process R/W; DBVM hypercall shims bypass RPM blocks); CE-style scan/pointer workflows, UE GWorld/GNames, Tencent ACE evasion research (source: wiki/sources/descriptions/not1cyyy__Anti-Cheat-Amateur.md) - [[sguard-limit]] — Windows ACE-Guard client restriction/patch toolkit (H3d9; user-mode C++ controller + kernel C/asm module; virtual memory ops, VAD traversal, suspend/resume, detour hooks; Visual Studio solution; anti-cheat RE / bypass experimentation) (source: wiki/sources/descriptions/H3d9__sguard_limit.md) - [[ff-ace-anticheat-analysis]] — Tencent ACE (libanogs/libanort) Free Fire byte-level RE post-mortem (Lixense; Python/JS IDA automation + SQLite detection index; APK hash, cert parsing, inline-hook scans, self-integrity checksum catalog; Explore AntiCheat System:ACE defensive research) (source: wiki/sources/descriptions/Lixense__ff-ace-anticheat-analysis.md) - [[anticheattoggle]] — WinForms utility to temporarily stop/disable Tencent ACE, Perfect World Arena, and Reason CyberSecurity kernel drivers that block VirtualBox VM spawn (`supR3HardenedWinReSpawn` VERR_INVALID_NAME -104); backs up service start types; CLI `--off`/`--on`/`--status`; research-host virtualization troubleshooting (lsxll666; Cheat / QEMU/KVM/PVE/VBOX) (source: wiki/sources/descriptions/lsxll666__AntiCheatToggle.md) - [[battlefn-cheat-analysis]] — detected Fortnite cheat post-mortem (0dayatday0; written analysis + sample modules + manual-map / privileged-memory PoCs; batch + C++ usermode→kernel paths; real-world tradecraft and mistake catalog for defensive researchers) (source: wiki/sources/descriptions/0dayatday0__BattleFN-cheat-analysis.md) - [[meme-rw]] — C++/CMake protected-process memory access PoC; vulnerable-driver mapping framework with driver-load helpers, process/module utilities, and memory R/W control; end-to-end target-process open + memory ops for anti-cheat bypass experimentation and defensive protected-memory research (SamuelTulach; cheat / kdmapper) (source: wiki/sources/descriptions/SamuelTulach__meme-rw.md) - [[remap]] — Windows kernel page-remapping PoC; copies protected-process pages into another process VA space for memory R/W and dump workflows after setup; documents Windows 10 range limits, operational caveats, and cleanup crash risks; anti-cheat bypass and low-level process-memory research (EBalloon; cheat / Clone process) (source: wiki/sources/descriptions/EBalloon__Remap.md) - [[mm-copy-memory]] — targeted MmCopyMemory scan-path bypass PoC; explains kernel AC memory-scan behavior; minimal C++ example patches a specific check path to alter scan handling; bypass research and defensive kernel memory-inspection study (EBalloon; cheat / Bypass MmCopyMemory) (source: wiki/sources/descriptions/EBalloon__MmCopyMemory.md) - [[map-page]] — post-kdmapper mapped-driver memory trace reduction PoC; `MmFreePagesFromMdl` + pool cleanup; `NtUserGetObjectInformation` data-pointer comm channel; driver-mapping stealth / AC bypass research (EBalloon; cheat / `[NtUserGetObjectInformation]`) (source: wiki/sources/descriptions/EBalloon__MapPage.md) - [[mandragora]] — educational ring-3 usermode anti-cheat for Assault Cube (purposefully weak; unobfuscated source for RE practice; follow-up after Assault Cube hacking; gmh5225) (source: wiki/sources/descriptions/gmh5225__Mandragora.md) - [[kernel-ac]] — educational Windows kernel anti-cheat graduation project (LucasAlgera; KMDF driver + C++ SCM launcher; ObRegisterCallbacks on process/thread handle create/duplicate; strips dangerous access rights; trusted-process whitelist e.g. explorer.exe/discord.exe; IOCTL game-PID registration; learner-oriented) (source: wiki/sources/descriptions/LucasAlgera__Kernel-AC.md) - [[mini-anti-cheat-v2]] — educational Windows kernel anti-cheat PoC (Abdelnour2; user-mode game + kernel driver; IOCTL blacklist checks, game PID registration, shield disable; process-creation notify blocks Notepad.exe at start and runtime; V2 ObRegisterCallbacks memory shield strips VM read/write and terminate from other processes; learner-oriented; not production AC) (source: wiki/sources/descriptions/Abdelnour2__MiniAntiCheatV2.md) - [[peregrine-anticheat]] — educational full-stack Windows AC (kernel minifilter, ObCallbacks, APC injection, MinHook API hooks, ETW-TI, YARA, in-process stack/HWBP scans, named-pipe backend reports, Tauri GUI, cheat test suite; PatchRequest) (source: wiki/sources/descriptions/PatchRequest__PeregrineAntiCheat.md) - [[sentinel-anti-cheat]] — educational usermode AC daemon (HEEAAP; suspended launch + pre-resume attach; remote-debugger checks, HWBP/debug-register scans, PEB-based memory reads, INT 3 code-section breakpoints; configurable log/suspend/terminate policies; TaskDialog splash; Open Source Anti Cheat System) (source: wiki/sources/descriptions/HEEAAP__Sentinel-Anti-Cheat.md) - [[pi-defender]] — kernel security driver blocking process injection by filtering dangerous handle rights (remote memory write / operation permissions); docs/tests for hollowing, doppelgänging, ghosting, and DLL injection; defensive AC hardening research (PI-Defender) (source: wiki/sources/descriptions/PI-Defender__pi-defender.md) - [[raccine]] — lightweight Windows anti-ransomware (Neo23x0; debugger registration for `vssadmin`/`wmic`; YARA command-line rules; parent-chain termination + event logging; no resident agent; blocks shadow-copy deletion; C/C++/C#; README [EDR]) (source: wiki/sources/descriptions/Neo23x0__Raccine.md) - [[bluespawn]] — open-source Windows active defense / EDR platform (ION28; Hunt/Mitigate/Monitor/Scan workflows; ATT&CK-oriented detections, YARA scanning, ETW monitoring, automated quarantine/process suspension; C++; rule-driven content; blue-team endpoint defense; README [EDR]) (source: wiki/sources/descriptions/ION28__BLUESPAWN.md) - [[openedr]] — open-source EDR platform (Comodo Security; C++; system monitoring, event collection, threat detection, AWS SDK cloud analysis integration; real-time Windows endpoint telemetry/response; EDR architecture / endpoint monitoring study; README [EDR]) (source: wiki/sources/descriptions/ComodoSecurity__openedr.md) - [[whids]] — open-source Windows EDR platform (0xrawsec; Go; detection-driven response; ETW + Sysmon telemetry; Gene rule engine; near real-time alert-triggered artifact collection; manager + admin API; incident response / enterprise endpoint monitoring; README [EDR]) (source: wiki/sources/descriptions/0xrawsec__whids.md) - [[sanctum]] — experimental Windows EDR PoC (0xflux; Rust; kernel driver + user-mode engine + Tauri UI; process/thread/filesystem/syscall monitoring; ETW consumers, minifilter, kernel hooking/containment; low-level defensive tooling research; README [EDR]) (source: wiki/sources/descriptions/0xflux__Sanctum.md) - [[stresser]] — endpoint security platform (AvivShabtay; C++ host agents + centralized management; UM/KM telemetry, artifact processing, policy handling, detection logic; ETW-driven monitoring + dynamic/static analysis + coordinated response; malware defense / enterprise endpoint protection experiments; README Anti Virus in fact but also Anti Cheat) (source: wiki/sources/descriptions/AvivShabtay__Stresser.md) - [[irontrace]] — Windows hardware and forensic integrity scanner for game-server administrators (codedevdev; C# WPF/CLI + optional ASP.NET Core server; PCI/PCIe/USB/driver inventory, DMA masquerade indicators, BYOVD/HWID/execution-artifact layers, LOLDrivers correlation; explainable JSON verdicts without auto-ban; optional self-hosted admin triage; Detection:DMA / hardware integrity auditing) (source: wiki/sources/descriptions/codedevdev__irontrace.md) - [[hawkeye]] — Windows kernel security research console for anti-cheat analysis and live forensics (hawkeye-Leo; host-native driver Win10/11 x64; `!probe` symbol/module inspection, `!etw` execution sampling + call-stack tracing, `!kernel_region` VA classification; Hawkeye Lab `!analyze` scored memory-mapping/active-page/kernel-injection reports; GPL Community + paid Lab; authorized AC/kernel RE) (source: wiki/sources/descriptions/hawkeye-Leo__hawkeye.md) - [[basic-anti-cheat]] — basic C/C++ anti-cheat teaching sample (process integrity, cheat signature scan, debugger detection, suspicious module enum, memory region validation; gmh5225; beginners) (source: wiki/sources/descriptions/gmh5225__Basic_Anti-Cheat.md) - [[uac]] — anti-cheat development platform with Visual Studio kernel-mode driver (common cheat-technique detection routines; C++ framework for testing/validating kernel-level detection; cheat-dev weakness probing; c4kef; Cheat developer platform) (source: wiki/sources/descriptions/c4kef__UAC.md) - [[quack]] — universal anti-cheat research kit (C++; modular client-side monitoring, game integration examples, documentation, companion red-team adversarial tooling; experimentation/validation—not production; JonathanBerkeley) (source: wiki/sources/descriptions/JonathanBerkeley__Quack.md) - [[blc-gamesec-lab]] — authorized game-security validation and regression orchestration CLI (Python; BLCReverseLab intake, evidence graphs, build diffing, incremental anti-cheat retest scoping; `blc.gamesec.report/v1`; BLCCoreStudio; defensive authorized regression testing) (source: wiki/sources/descriptions/BLCCoreStudio__BLCGameSecLab.md) - [[dead-anticheat]] — FiveM server-side Lua CitizenFX anticheat (Dead-Scripts; noclip/spectate/godmode/infinite-ammo/mod-menu globals; JSON ban list + Discord webhook logging with optional screenshots; configurable event/key/command/entity blacklists; staff bypass) (source: wiki/sources/descriptions/Dead-Scripts__Dead_antiCheat.md) - [[aeterna-rongroi]] — offline read-only FiveM PC-check tool (aeterna; Rust/Tauri 2 + React UI + CLI; YAML rules engine + read-only collectors; Found/NotFound/Unmeasured cheat-trace evidence without clean/guilty verdicts; self-check/screenshare modes with path redaction and consent; Secure Boot posture inspection; no host writes or networking) (source: wiki/sources/descriptions/aeterna__aeterna-rongroi.md) - [[error-pc-check]] — consensual remote Minecraft Java Edition screenshare workflow (NotSkrib; Error SMP Screenshare; signed C#/.NET 8 client agent + React/TypeScript staff web panel + Supabase; one-time keys; consent-gated TLS scan with live progress; Prefetch/BAM/UserAssist/ShimCache/USN/registry/recycle-bin/browser-download/Minecraft signature collectors; correlation engine for anti-forensic tampering; severity-ranked human-review reports; Anti Cheat / game:minecraft) (source: wiki/sources/descriptions/NotSkrib__error-pc-check.md) - [[tshock]] — Terraria server framework (Pryaxis; C# .NET; Terraria Server API plugin; **Bouncer** packet/action anti-cheat; permissions, regions, warps, item bans; SQLite/MySQL/PostgreSQL + REST + plugin system; protocol guards for known Terraria networking flaws; Open Source Anti Cheat System) (source: wiki/sources/descriptions/Pryaxis__TShock.md) - [[deadlock-anti-cheat]] — UrnIt user-mode Deadlock session AC (process list, game-window PNG screenshots, focused-window key input, CPU/GPU HWID, cheat-process signatures with optional forum scrape, macro/bot key-timing variance; Discord webhook on exit/F12; tournament/session logging vs kernel enforcement; g8tsz) (source: wiki/sources/descriptions/g8tsz__deadlock-anti-cheat.md) - [[anti-cheat-chrysalis]] — C/C++ reference AC / chrysalis guide (process integrity, module scan, memory pattern detection, debugger detection, overlay monitoring, kernel driver comm, OpenGL; gmh5225; Anti Cheat / guide; alias [[anticheat]]) (source: wiki/sources/descriptions/gmh5225__AntiCheat-chrysalis.md) (source: wiki/sources/descriptions/gmh5225__AntiCheat.md) - [[anticheat-android-cheap-engine]] — sample Android anti-cheat implementation (C/C++; open-source AC system lane; defensive researchers; gmh5225) (source: wiki/sources/descriptions/gmh5225__Anticheat-android-cheap-engine.md) - [[android-anti-cheat]] — open-source Android anti-cheat research (C/C++; anti-cheat, modding, hooking; codetronik; open-source AC system lane; defensive researchers) (source: wiki/sources/descriptions/codetronik__AndroidAntiCheat.md) - [[rebirth-guard]] — Windows C++ open-source anti-cheat library (chztbby; modding / SDK generation; Open Source Anti Cheat System lane; defensive researchers) (source: wiki/sources/descriptions/chztbby__RebirthGuard.md) - [[ultimate-anti-cheat]] — open-source Windows C++ anti-cheat framework (AlSch092; user-mode debug/memory-patch/runtime tamper detection; optional client-server heartbeat; configurable hybrid user-mode + kernel-assisted deployment; educational AC evaluation reference; Open Source Anti Cheat System) (source: wiki/sources/descriptions/AlSch092__UltimateAntiCheat.md) - [[betashield]] — C++/Boost client-side AC protection (integrity checking, process monitoring, tamper detection; Boost.Asio networking; cross-platform Boost utilities; open-source AC system lane; JackBro) (source: wiki/sources/descriptions/JackBro__BetaShield.md) - [[cheatguard]] — Rust engine-agnostic loaded-module scanner (JSON signature ruleset; weighted signals—known cheat names, suspicious paths, unsigned modules, module-count anomalies; Win32 module enum; deterministic 0–100 CLEAN/SUSPICIOUS/MALICIOUS JSON report; library + CLI; blue-team process-integrity / custom AC forensics; JUS7205) (source: wiki/sources/descriptions/JUS7205__cheatguard.md) - [[tlac-modern-local-anti-cheat-reunioned]] — lightweight open-source local anti-cheat for Linux (Rust + C eBPF/kernel module + Python ONNX; user-space wildcard memory signature scan, SHA256 self-integrity, HWID bans, Tokio local IPC; optional eBPF tracepoints on open/exec/ptrace/clone; behavioral anomaly detection; MIT-licensed; Steam Deck; TuncorReUnion; Open Source Anti Cheat System) (source: wiki/sources/descriptions/TuncorReUnion__TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED.md) - [[vigil]] — Rust eBPF Linux-native anti-cheat (BPF ELF loading, perf events, CLI, client–server distributed monitoring; kernel-level event tracing and threat detection; TOSTcRa; Open Source Anti Cheat System) (source: wiki/sources/descriptions/TOSTcRa__vigil.md) - [[linux-anticheat]] — WIP kernel-level Linux console AC (mikio815; Rust daemon + LSM eBPF ptrace/W^X/bpf() detection + thin C kernel module for eBPF integrity + planned BitVisor EPT write-protect; Aya; Linux 5.17+ BTF + BPF LSM; Steam Deck target; Open Source Anti Cheat System) (source: wiki/sources/descriptions/mikio815__linux-anticheat.md) - [[ac-compat-research]] — vendor-agnostic Linux kernel AC hosting feasibility study (IZxMD; LSM/signing/isolation/ABI constraints; non-virtualized architecture dossier + knowledge graph; no bypass material; Anti Cheat / Guide) (source: wiki/sources/descriptions/IZxMD__ac-compat-research.md) - [[gexec]] — register-machine bytecode interpreter for Windows kernel drivers (gasm, gvmlift PE lifter, embeddable host API; updatable portable logic without native recompile; zer0condition; kernel AC development research) (source: wiki/sources/descriptions/zer0condition__gexec.md) - [[anti-debug]] — Windows C++ PoC; `ResumeThread` suspend-count detects debugger attachment via WinAPI return value; minimal single-signal anti-debug study sample (Metick; Anti Debugging) (source: wiki/sources/descriptions/Metick__Anti-Debug.md) - [[ida-plugin-antidebugseeker]] — IDA Pro plugin; automated rule-based Windows API + keyword anti-debug detection; match highlighting, address annotation, quick navigation; configurable rules + in-IDE editor (LAC-Japan; Extract anti-debugging) (source: wiki/sources/descriptions/LAC-Japan__IDA_Plugin_AntiDebugSeeker.md) - [[antidebugandmemorydump]] — Android anti-debug + memory analysis / emulation / debugging reference (Java + C/C++; Anti Debugging lane; defensive researchers; gmh5225) (source: wiki/sources/descriptions/gmh5225__AntiDebugandMemoryDump.md) - [[adb-debug-detect-checker]] — Android Java ADB/debug-state detection reference (whether ADB debugging is available; Anti Debugging; fiord) (source: wiki/sources/descriptions/fiord__ADB-Debug-Detect-Checker.md) - [[antidebug-antivm]] — anti-debug + VirtualBox anti-VM technique examples (reference snippets; not a standalone build; Anti Debugging / Detection:Virtual Environments; defensive researchers; gmh5225) (source: wiki/sources/descriptions/gmh5225__AntiDebug-AntiVM.md) - [[antidbg-hackovert]] — Windows curated anti-debug technique collection (HackOvert; C/C++ + x86/x64 asm; memory structure, CPU/timing, forced exceptions; gauntlet sequential test app; RE education + anti-analysis defense evaluation; Anti Debugging) (source: wiki/sources/descriptions/HackOvert__AntiDBG.md) - [[cpp-anti-debug]] — Windows C++ anti-debugging library (BaumFX; PEB/API/exception/timing/debug-register checks; per-check functions + combined runtime security-check entry; anti-tamper prototyping and debugger-detection technique study; Anti Debugging) (source: wiki/sources/descriptions/BaumFX__cpp-anti-debug.md) - [[ladd]] — Linux C anti-debugging detection tool (BarakAharoni; ptrace behavior, LD_PRELOAD tampering, TracerPid in /proc/self/status; early runtime checks; anti-analysis research and defensive hardening experiments; Anti Debugging) (source: wiki/sources/descriptions/BarakAharoni__LADD.md) - [[debugoff]] — Linux Rust anti-analysis/anti-debug library (0xor0ne; direct syscalls without libc; syscall obfuscation; chained/randomized ptrace validation with tamper termination; binary hardening against RE; Anti Debugging / Linux) (source: wiki/sources/descriptions/0xor0ne__debugoff.md) - [[showstopper]] — Windows anti-debug exploration tool (CheckPointSW; large malware/research check collection; exposes function addresses; attach debuggers and compare tools/plugins/mitigations; anti-anti-debug validation; Anti Debugging) (source: wiki/sources/descriptions/CheckPointSW__showstopper.md) - [[racecondition]] — Windows C++ Visual Studio PoC; native NT API probes of debug ports, hidden-thread behavior, and debugger artifacts; race-condition timing bypasses against common userland hide mechanisms; anti-anti-debug technique research (Ahora57; Anti Debugging) (source: wiki/sources/descriptions/Ahora57__RaceCondition.md) - [[majesty-technologies]] — experimental Windows kernel driver; DKOM-style structure manipulation, instrumentation callback checks, hardware breakpoint checks, process/thread flag hardening, anti-hypervisor timing/anomaly probes; anti-cheat and protection research for kernel-level debugger resistance (Ahora57; Anti Debugging) (source: wiki/sources/descriptions/Ahora57__MAJESTY-technologies.md) - [[avanguard]] — Win32 anti-intrusion library (GravitLauncher; C/C++; anti-debug, anti-injection, memory/call-stack analysis, integrity checks, callback filtering, module checks; game-client hardening; Anti Debugging) (source: wiki/sources/descriptions/GravitLauncher__Avanguard.md) - [[godefender]] — Windows Go security toolkit (EvilBytecode; anti-debug, anti-virtualization, anti-DLL-injection, hook detection; modular internal components; low-level WinAPI defensive signals; security-sensitive Go app hardening; Anti Debugging) (source: wiki/sources/descriptions/EvilBytecode__GoDefender.md) - [[anticrack-dotnet]] — .NET protection toolkit (AdvDebug; C#; anti-debug, anti-virtualization, anti-injection, hook detection; PEB/thread flags, sandbox heuristics, syscall probes, integrity hardening; detects anti-anti-debug user-mode hooks and runtime tamper; software hardening and AC/anti-crack defensive components; Anti Debugging) (source: wiki/sources/descriptions/AdvDebug__AntiCrack-DotNet.md) - [[chessking]] — Rust Axum multiplayer chess platform with layered server-side AC (risk scoring, device fingerprinting, match integrity, IP reputation, chess-themed CAPTCHA step-up, ban escalation; shakmaty move validation; admin dashboard; educational reference; web-coder-lab) (source: wiki/sources/descriptions/web-coder-lab__chessking.md) - [[7dtd-anticheatmod]] — C# .NET 4.8 server mod for 7 Days to Die dedicated hosts without EAC; blocks cheat console/chat commands; movement thresholds for fly/teleport/speed/godmode; admin exemption; warning→kick→ban escalation; admin alerts + detection log (majimaakane) (source: wiki/sources/descriptions/majimaakane__7dtd-AntiCheatMod.md); contrast offensive end-to-end cheat delivery such as [[7dtd]] (IntelSDM; Unity/Mono loader + C# modules + C++ auth/transport backend; ESP/aimbot/weapon mods/player spoofing; anti-cheat bypass; cheat / game:7dtd) (source: wiki/sources/descriptions/IntelSDM__7DTD.md) - [[iw4madmin-sebzanticheat]] — IW4X server-side suspicion telemetry + IW4MAdmin review dashboard; GSC aim/visibility/radar checks; JS plugins + Discord case workflow; separate risk/confidence scoring; watch/clear/purge/recover moderation; no auto-ban (crazythecoder) (source: wiki/sources/descriptions/crazythecoder__IW4MAdmin-SebzAntiCheat.md) - [[little-anti-cheat]] — open-source SourceMod anti-cheat plugin for Source engine servers (SourcePawn; aimbot/aimlock, abnormal angles, bhop automation, fast duck, suspicious ConVar states; interpolation/backtrack countermeasures, optional high-ping enforcement, logging/translation; TF2/CS community servers; J-Tanzanite; For Source Games) (source: wiki/sources/descriptions/J-Tanzanite__Little-Anti-Cheat.md) - [[corner-culling]] — server-side occlusion-culling system (87andrewh; C++ + Unreal Engine; analytical ray casts, BVH + recent-occluder caching, latency-aware lookahead; reduces wallhack visibility in multiplayer shooters; scalable line-of-sight enforcement research) (source: wiki/sources/descriptions/87andrewh__CornerCulling.md) - [[corner-culling-source-engine]] — Source engine anti-wallhack extension (87andrewh; C++ extension + SourceMod + map occluders; strict server-side visibility culling; ray-cast correctness, low overhead, latency-safe; competitive Source servers; For Source Games) (source: wiki/sources/descriptions/87andrewh__CornerCullingSourceEngine.md) - [[anticheatsystem]] — CS2 MetaMod:Source 2 native module for dedicated Linux servers (pavelinbs-afk; C++17/CMake; modular aim snap, wallhack visibility, movement speed, session stats, and client integrity analyzers; JSON-configured suspicion scoring; AdminPlugin/PlaytimeReporter ban and ticket integration; Docker HL2SDK-CS2 linuxsteamrt64 builds; Open Source Anti Cheat System) (source: wiki/sources/descriptions/pavelinbs-afk__anticheatsystem.md) - [[sac-the-server-anticheat]] — CS2 server-side algorithmic AC for Metamod:Source and CounterStrikeSharp (IDELd; C#/.NET 8; 17 detection modules for aimbot/silent aim/bhop/injection/invalid input; in-game reporting; four-stage progressive warning/ban; mass-check sensitivity after multiple reports; optional demo recording + anonymized event logs; Open Source Anti Cheat System) (source: wiki/sources/descriptions/IDELd__SAC-The-server-AntiCheat.md) - [[tf2bd-database]] — community-maintained TF2 cheater/suspicious-player/scammer JSON lists and chat word-filter rules for TF2 Bot Detector (TF2BD v3 playerlist/rules schemas; last-seen metadata + proof; client-side alerts via surepy/tf2_bot_detector; Garou3299) (source: wiki/sources/descriptions/Garou3299__tf2bd-database.md) - [[gatewarden-public]] — Godot 4.7 tower defense prototype with published PathValidator placement-abuse rejection codes (flow-field softlock/maze checks; 30 Hz deterministic sim; 59 GUT tests + headless bot; test-driven validation reference; euuuuuuan) (source: wiki/sources/descriptions/euuuuuuan__gatewarden-public.md) - [[shinobix]] — live browser MMORPG with server-authoritative combat and documented auth/reward-integrity anti-cheat patterns (settlement receipts, currency ledgers, save locks; HTTP hardening + parity/settlement test coverage; Timehue; Open Source Anti Cheat System) (source: wiki/sources/descriptions/Timehue__ShinobiX.md) - [[cobra-snake]] — production web Snake (TypeScript/Next.js/React; HTML5 Canvas; LibSQL Top 10 leaderboard) with HMAC-signed game sessions, score plausibility checks, rate-limited submissions, and silent forged-score rejection; Anti-Cheat Programming reference (aryribeiro) (source: wiki/sources/descriptions/aryribeiro__cobra.md) - [[pokealliance-anti-cheat-analysis]] — PokeAlliance OTCv8 Pokémon MMO client static/dynamic audit (LordeTyrael; server-triggered process/module/window enumeration, login hardware fingerprinting, Lua startup blacklists, server-driven bot checks over traditional anti-debug; Frida JS hooks + Python live tracer; Anti Cheat defensive research) (source: wiki/sources/descriptions/LordeTyrael__PokeAllianceAntiCheatAnalysis.md) - [[r6-siege-battleye-launch-bug]] — R6 Siege Y11S3 BattlEye/Sentinel handshake failure on standard launch paths with BEDaisy telemetry, checksum evidence, and working bypass via RainbowSixHelper.exe (brandenbailey23; Explore AntiCheat System:BE launch regression report) (source: wiki/sources/descriptions/brandenbailey23__r6-siege-battleye-launch-bug.md) - [[void-engine]] — Godot 4.x editor plugin with WhiteVoid AntiCheat autoload (debugger/process/window detection, honeypot integrity checks, HWID ban enforcement); GDScript; VoidNet ENet/Firebase WebRTC multiplayer stack; lannden1245; Open Source Anti Cheat System) (source: wiki/sources/descriptions/lannden1245__Void-Engine.md) - [[dot-server-security]] — Godot 4 dedicated-server security addon (GDScript rule engine; movement re-simulation + shot validation; sliding-window rate limits; warn/gag/mute/kick/ban escalation; external ban feeds; dry-run default; modcommunity; Open Source Anti Cheat System) (source: wiki/sources/descriptions/modcommunity__dot-server-security.md) - [[ricochet-deobfuscator]] — C/C++ Ricochet deobfuscator (driver / memory analysis; explore anticheat:ricochet) (source: wiki/sources/descriptions/weak1337__ricochet_deobfuscator.md) - [[aurum-re]] — Aurum RE Ricochet anti-cheat research (reverse engineering + driver development; explore anticheat:ricochet) (source: wiki/sources/descriptions/gmh5225__AurumRE.md) - [[ricochet-disabler]] — disable/bypass Ricochet kernel driver and user-mode monitoring for COD AC architecture research (source: wiki/sources/descriptions/gmh5225__ricochet-disabler.md) - [[hidden-syscall-monitoring]] — C/C++ monitor of hidden syscalls from Call of Duty anticheat (hooking / memory analysis) (source: wiki/sources/descriptions/ssnob__hidden_syscall_monitoring.md) - [[callmon]] — Windows kernel-driver syscall monitor via **PsAltSystemCallHandlers** (DownWithUp; per-process intercept; trap frame + stack telemetry through named pipe; C + optional Rust driver; process-level API monitoring / AC research; AltSystemCallHandlers) (source: wiki/sources/descriptions/DownWithUp__CallMon.md) - [[win-alt-syscall-handler]] — Windows kernel research PoC exploring alternate system call handler mechanics (0xcpu; C; registration limits, dispatch conditions, thread debug flags, trap-frame usage; syscall interception / stability study; AltSystemCallHandlers) (source: wiki/sources/descriptions/0xcpu__WinAltSyscallHandler.md) - [[executive-callback-objects]] — Windows executive callback object research collection (0xcpu; C kernel PoCs + notes; register/inspect/analyze callback activity across networking, system state, boot, and security families; telemetry visibility / AC+EDR analysis; README Callback) (source: wiki/sources/descriptions/0xcpu__ExecutiveCallbackObjects.md) - [[bam-extension-table-hook]] — Windows kernel PoC hooking process notifications via BAM extension table (Dor00tkit; swaps `bam!BampCreateProcessCallback` on extension-host path vs standard notify array; ntoskrnl offset lookup + notify-mask handling; AC/EDR callback bypass research; README [bam!BampCreateProcessCallback]) (source: wiki/sources/descriptions/Dor00tkit__BamExtensionTableHook.md) - [[badlion-logger]] — KiFilterFiberContext PoC kernel logger for black-box AC driver observation (IAT hooks on image-load callbacks; VMProtect-virtualized target module; C++; driver-level monitoring research) (source: wiki/sources/descriptions/KiFilterFiberContext__BadlionLogger.md) - [[kn-win32-api-monitor]] — Tauri 2 Win32 API trace workstation (IAT hooks; ~30k APIs; `.knapm` replay; security/RE/anti-cheat research; kernullist) (source: wiki/sources/descriptions/kernullist__KnWin32ApiMonitor.md) - [[syscall-detect]] — C PoC detecting direct/indirect syscalls via Instrumentation Callback or thread stack inspection (flags custom stubs vs ntdll) (source: wiki/sources/descriptions/jackullrich__syscall-detect.md); internal CS2 research frameworks such as [[rabsztyncc-cs2-internal]] (BrufelFX; direct NT syscalls + PE header wipe + signature busting + thread hiding + optional kernel shared-memory IPC; cheat / game:cs2 [Internal]) and hybrid suites such as [[projectnexus-csgo]] (Atonl200; manual-map loader via direct syscalls + optional [[byovd]] / kernel driver / PE mapper; shared-memory IPC to external overlay; cheat / game:cs2 [Internal]) illustrate the same usermode evasion surface AC must instrument beside [[modfinder]] PE-header heuristics. (source: wiki/sources/descriptions/BrufelFX__RabsztynCC-CS2-Internal.md) (source: wiki/sources/descriptions/Atonl200__ProjectNexus-CSGO.md) - [[armcall]] — header-only C++20 ARM64 Windows direct syscall library (noahware; ntdll export parse + SVC immediate extraction; dynamic executable stubs bypass hooked user-mode APIs; AC_SYSCALL macros; WoA game security / AC evasion / low-level RE) (source: wiki/sources/descriptions/noahware__armcall.md) - [[nt-unhooker]] — Rust NTDLL inline/IAT hook detect + restore vs clean reference image (PE parse; symbol-based clean DLL; CLI + library; defender / malware-analysis hook-tampering study) (source: wiki/sources/descriptions/Teach2Breach__nt_unhooker.md) - [[hook-detector]] — Windows usermode inline/IAT hook detector (0x6461726B; C++20 DX11/ImGui GUI; module scan + remote PE parse + manual PEB traversal; in-memory vs on-disk code compare; x86/x64; anti-cheat dev / game-security RE; Detection:hook) (source: wiki/sources/descriptions/0x6461726B__Hook-Detector.md) - [[known-dll-unhook]] — KnownDlls-backed `.text` restore for loaded modules (map clean `\KnownDlls` copies; native syscalls; EDR/AC hook detection & evasion research; ORCx41) (source: wiki/sources/descriptions/ORCx41__KnownDllUnhook.md) - [[moonwalk]] — Rust PEB-less DLL base discovery via TEB/stack walk (VirtualQuery or API-free variants; CLI + library; evades monitored PEB module-enumeration paths) (source: wiki/sources/descriptions/Teach2Breach__moonwalk.md) - [[kaspersky-hook]] — syscall hooking via Kaspersky `klhk.sys` hypervisor (`IA32_LSTAR` dispatch-table redirect + custom driver; gmh5225; README `[Kaspersky]`) (source: wiki/sources/descriptions/gmh5225__KasperskyHook.md) - [[hook-hvl-switch-virtual-address-space]] — `HvlSwitchVirtualAddressSpace` hook; CR3 transition manipulation hides pages from process memory scans during address-space context switches (gmh5225; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/gmh5225__Hook-HvlSwitchVirtualAddressSpace.md) - [[hook-guard]] — global exception-hook chain driver; monitors/obfuscates CR3 address-space switches and logs protected-context transition attempts; PatchGuard-aware/HVCI-compatible defensive memory-access-control research (SamuelTulach; README Global exception/KdpDebugRoutineSelect) (source: wiki/sources/descriptions/SamuelTulach__HookGuard.md) - [[driver-hypercall-page-hook]] — `nt!HvcallCodeVa` hypercall-page hook; custom dispatcher + `HvlEnlightenments` flip routes context-switch hypercalls through callbacks (gmh5225; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/gmh5225__Driver-HypercallPageHook.md) - [[hook-swap-context]] — ETW/CKCL-based SwapContext scheduling-path hook; custom stack-frame checks invoke handler during selected thread scheduling flow (1401199262; C++ kernel PoC; README SwapContext hook) (source: wiki/sources/descriptions/1401199262__HookSwapContext.md) - [[hook-hvcall-code-va]] — HvcallCodeVa hypercall code callback hook during address-space switching; pattern-scan internals, custom callback, enlightenment-flag adjustment, CR3 + per-CPU hypercall page setup (1401199262; C++ kernel PoC; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/1401199262__HookHvcallCodeVa.md) - [[hyperdeceit]] — reusable C++ Hyper-V impersonation library; intercepts selected kernel hypercalls with ready-to-hook TLB flush, sleep/shutdown, address-space switch, and spinlock paths (Xyrem; README `[HvcallCodeVa]`) (source: wiki/sources/descriptions/Xyrem__HyperDeceit.md) - [[x14-08-coverstory-blizzard]] — WoW cheat framework with Warden loader hooks / RunScript injection (research ref for Warden internals) (source: wiki/sources/descriptions/xakepru__x14.08-coverstory-blizzard.md) - [[sky-engine]] — WoW protected-Lua unlocker via taint-state reset (adde88; C++; cheat prototyping and client-script detection research; cheat / game:wow [Wow Lua Unlocker]) (source: wiki/sources/descriptions/adde88__SkyEngine.md) - [[ow2-wardenrekter]] — Overwatch 2 Warden disable DLL (VEH/INT3 neutralization via `KiUserExceptionDispatcher` RET patch, DbgBreakPoint NOP, PEB debugger hiding, `GetTickCount64` timing stub, `NtQuerySystemInformation` block; DR0 via `SetThreadContext`; README `[Emulate OW2 AC]`; gmh5225) (source: wiki/sources/descriptions/gmh5225__OW2-wardenrekter.md) - [[ow-aeternum]] — Overwatch C/C++ POC spanning anti-cheat research, rendering, and hooking (author-flagged rough POC; cheat / game:overwatch; gmh5225) (source: wiki/sources/descriptions/gmh5225__OW-Aeternum.md) - [[pareidolia-triggerbot]] — hypervisor-based external Overwatch Widowmaker triggerbot (blackhades00; VivienneVMM + MouClassInputInjection; bypasses Overwatch Anti-Cheat) for studying below-OS external triggerbot surface against Blizzard Warden (source: wiki/sources/descriptions/blackhades00__PareidoliaTriggerbot.md) - [[ow-anti-flag]] — Overwatch chainban anti-flag console tool (dword64; modern C++; clears directories/registry keys Blizzard and cheat malware use to flag devices; cheat / HWID) (source: wiki/sources/descriptions/dword64__Ow-Anti-Flag.md) - [[spoofer]] — Windows C++ mixed overlay-cheat and HWID-evasion package (AlfredIU; user-mode aimbot/ESP/entity caching/projectile prediction via DirectX9 ImGui plus kernel driver artifacts; bundled identity-evasion workflows beside live cheat modules; cheat / HWID research) (source: wiki/sources/descriptions/AlfredIU__Spoofer.md) ## Key sub-areas **Detection:** Segment Heap–aware [[kernel-pool-scanning]] (BigPool/VS/kLFH walks, PoolTag cross-ref, executable NonPagedPool, KDP-protected rule tables); memory hashing / manual-map detection (usermode working-set page-fault monitors such as [[faultline]] — `InitializeProcessForWsWatch` / `GetWsChangesEx` / `QueryWorkingSet`; PEB-unlisted FaultingPc; suspend + stack walk) (source: wiki/sources/descriptions/svespalec__faultline.md); mapped-region DOS-header scanners such as [[modfinder]] (Nou4r; C++; enumerate process regions + MZ/PE heuristics incl. stripped optional headers; x86 runtime manual-map forensics; Mapped Dll) (source: wiki/sources/descriptions/Nou4r__ModFinder.md); offensive working-set bypass PoCs such as [[count-hook]] (WorkingSet; bypass count-oriented memory checks used by page-protection monitors) on the cheat bypass side (source: wiki/sources/descriptions/illegal-instruction-co__CountHook.md); physical-memory **copy-on-write bypass** injectors such as [[be-injector]] (Compiled-Code; C++; patch signed module pages via physical mapping to avoid COW artifacts; evades thread/API/signature scrutiny around loaded modules; Attack COW; detection-resilience research) (source: wiki/sources/descriptions/Compiled-Code__be-injector.md); lightweight `.text` working-set shared-page integrity demos such as [[query-working-set-example]] (Midi12; C; `QueryWorkingSet` metadata flags breakpoint/protection tamper in non-writable regions) (source: wiki/sources/descriptions/Midi12__QueryWorkingSetExample.md); CFG bitmap inconsistency shellcode scanners such as [[cfg-find-hidden-shellcode]] (C; executable regions valid as CFG call targets but outside known module code; Detection:ShellCode) (source: wiki/sources/descriptions/jdu2600__CFG-FindHiddenShellcode.md); process handle stripping; offensive handle-elevation libs such as [[libelevate]] (driver/KM primitives → full-access process handles for RPM study opposite AC handle protection) (source: wiki/sources/descriptions/notscimmy__libelevate.md); driver+DLL ObOpenPointerToObject handle bypass such as [[easy-handles]] (AlSch092; usermode OpenProcess hook → IOCTL → kernel path past ObRegisterCallbacks; debugger attach to callback-protected targets; PPL limits; AC/EDR handle-protection research) (source: wiki/sources/descriptions/AlSch092__EasyHandles.md); timing-attack handle elevation such as [[van1338]] (object-callback design complexity; AC stress testing) (source: wiki/sources/descriptions/kkent030315__Van1338.md); object-callback redirect and integrity-hook tampering PoCs such as [[pink-eye]] (SurgeGotTappedAgain; KMDF driver; code-cave callback redirection; kernel AC detection/hardening study) (source: wiki/sources/descriptions/SurgeGotTappedAgain__Pink-Eye.md); handle-theft LSASS dump PoCs such as [[lsass-dump-that-lsass]] (duplicate existing `lsass.exe` process handles → unhooked `MiniDumpWriteDump`; credential-extraction / hook-evasion research) (source: wiki/sources/descriptions/gmh5225__LSASS-DumpThatLSASS.md); handle-reuse LSASS dump PoCs such as [[dumpy]] (Kudaes; Rust; duplicate pre-opened LSASS handles via system/object APIs; XOR dump output; optional HTTP exfil; avoids obvious direct-open telemetry; Elevating Handle By LSASS) (source: wiki/sources/descriptions/Kudaes__Dumpy.md); user-mode LSASS handle-reuse bypass demos such as [[lsass-usermode-bypass]] (ContionMig; C++; memory access via recycled LSASS handles without kernel driver; stability-risk notes; game AC bypass tradeoff study; Elevating Handle By LSASS) (source: wiki/sources/descriptions/ContionMig__LSASS-Usermode-Bypass.md); Ring3 MiniDump callback instrumentation such as [[atpminidump]] (b4rtik; C/C++; aTPMiniDump callback; memory analysis; defensive AC / callback lane) (source: wiki/sources/descriptions/b4rtik__ATPMiniDump.md); minimal handle-hijack teaching PoCs such as [[handle-ripper]] (gmh5225; enumerate system handles → duplicate target handle cross-process; `DuplicateHandle` parameter study; not a general framework) (source: wiki/sources/descriptions/gmh5225__Handle-Ripper.md); [[kernel-callbacks]]; Segment Heap–aware pool scanning; behavioral/ML aimbot signals — see [[ai-aimbot-detection]] for server-side replay features, ML classifiers, and hardware-input context; corpus refs include CS:GO demo per-shot ML [[dlac]] (source: wiki/sources/descriptions/LaihoE__DLAC.md), CS2 demo-telemetry ML [[cs2guard]] (source: wiki/sources/descriptions/Driw0x__CS2Guard.md), CS2 deep-learning [[waldo]], clip prototype [[aimbot-detection-prototype]], [[pine]], [[human-mouse-movement]] (source: wiki/sources/descriptions/waldo-vision__waldo.md) (source: wiki/sources/descriptions/waldo-vision__aimbot-detection-prototype.md); MapleStory synthetic detection-sample generators such as [[maplestory-detection-sample-generator]] (gmh5225; cheat-pattern simulation + ML object-detection exports for AC algorithm training/validation; game:maplestory) (source: wiki/sources/descriptions/gmh5225__MapleStoryDetectionSampleGenerator.md); hybrid CS2 design proposals such as [[cs2-hybrid-anticheat-proposal]] (Python PoC; VAC Live–style ML + Glicko-2 weighted Overwatch judges, invisible honeypot entities, 2–3 match shadow monitoring) illustrate automated-plus-human review pipelines (source: wiki/sources/descriptions/mishka-sit2002__CS2-Hybrid-AntiCheat-Proposal.md); offensive human-like mouse movement samples such as [[human-mouse-movement]] inform the same Detection:Aimbot input-trajectory lane (source: wiki/sources/descriptions/tgillam__HumanMouseMovement.md); Python WindMouse path libraries such as [[windmouse]] (AsfhtgkDavid; curved variable-speed trajectories; AutoHotkey/PyAutoGUI; bot-behavior evasion in UI/game scripting) sit on the offensive side of that lane (source: wiki/sources/descriptions/AsfhtgkDavid__windmouse.md); defensive deep-learning human-vs-bot mouse classifiers such as [[delbot-mouse]] (Bureau404 internship; University of Mons; Detection:triggerbot & aimbot) (source: wiki/sources/descriptions/chrisgdt__DELBOT-Mouse.md); hardware-rooted controller attestation such as [[qortroller]] (ConWan30; VAPI + DualShock bridge; PoEP presence challenges; Circom/Groth16 verified-human proofs; session receipts; game security / anti-cheat research) (source: wiki/sources/descriptions/ConWan30__QorTroller.md); behavioral AC test bench [[laneguard]] (JoshKappler; TypeScript/Next.js; lane-change skill-game sim; attacker ladder from naive bots to motor-noise camouflage bots; client kinematic/behavioral-texture detector with ROC calibration; headless batch runners + economy break-even; stealth bots evade client motor forensics while rake/win-rate/population stats bind server-side; Anti Cheat / behavioral detection) (source: wiki/sources/descriptions/JoshKappler__laneguard.md); minimal Windows software-vs-hardware mouse movement PoCs such as [[mousedetection]] (Oliver-1-1; native C++; movement-behavior monitoring + simulated motion APIs for testing; input validation research; README [Mouse]) (source: wiki/sources/descriptions/Oliver-1-1__MouseDetection.md); kernel-mode **MouseClassServiceCallback** hook-detection PoCs such as [[detect-mouseclassservicecallback]] (KANKOSHEV; WDK driver; observe/validate mouse callback execution paths; rootkit / input-interception detection research) complement that user-mode lane. (source: wiki/sources/descriptions/KANKOSHEV__Detect-MouseClassServiceCallback.md) kernel-mode **KeAttachProcess** usage-detection PoCs such as [[detect-keattachprocess]] (KANKOSHEV; continuously running WDK driver; process/thread enumeration + thread-context inspection for unexpected attached targets; covert cross-process attach monitoring research) extend that defensive kernel lane. (source: wiki/sources/descriptions/KANKOSHEV__Detect-KeAttachProcess.md) ETW USB-telemetry keyboard input-integrity PoCs such as [[etw-keyboard-detection]] (Oliver-1-1; C++; compares physical vs software-generated key events; manual setup + keyboard tuning; README [ETW]) (source: wiki/sources/descriptions/Oliver-1-1__EtwKeyboardDetection.md); neural-network aim/trigger research such as [[pine]] (CS:GO / Fortnite / Overwatch–oriented; Neural Network) informs the same Detection:triggerbot & aimbot threat model (source: wiki/sources/descriptions/petercunha__Pine.md); screenshot + heartbeat (image tampering forensics via [[sherloq]] — ELA/EXIF/cloning/TruFor; AC screenshot-authenticity review; GuidoBartoli) (source: wiki/sources/descriptions/GuidoBartoli__sherloq.md); ETW provider/event discovery for telemetry design (e.g. [[etw-explorer]]; cross-OS manifest diff via [[etw-watcher]]) (source: wiki/sources/descriptions/jonny-jhnson__EtwWatcher.md); EtwTi registration fluctuation tamper monitors such as [[etwti-fluctuation-monitor]] (C; real-time callback-manipulation alerts when ETW TI telemetry is blinded) (source: wiki/sources/descriptions/jdu2600__EtwTi-FluctuationMonitor.md); ThreatIntel injection consumers such as [[tietwagent]] (Microsoft-Windows-Threat-Intelligence + krabsetw/Yara; ELAM/PPL service path); no-driver / non-PPL ThreatIntel consume PoCs such as [[threat-intelligence-consumer]] (Win11 24H2/25H2; Cheat Windows kernel explorer) (source: wiki/sources/descriptions/preludeorg__ThreatIntelligenceConsumer.md); kernel event-stream observability / rule engines such as [[fibratus]] (Go ETW; process/thread/file/registry/network/driver; Elasticsearch sinks) (source: wiki/sources/descriptions/rabbitstack__fibratus.md); Procmon-inspired GUI monitors such as [[openprocmon]] (C++; ETW + minifilter; process/file/registry/network/DLL; filter/export) for host-activity telemetry study (source: wiki/sources/descriptions/progmboy__openprocmon.md). Virtualization-based ProcMon-style kernel tracers such as [[kernelmon]] (VMX/EPT interception; hooks selected KM APIs → usermode desktop UI; file/registry/process/thread; AC/malware behavior analysis in controlled VMs) (source: wiki/sources/descriptions/alal4465__KernelMon.md). User-mode directory-tree watchers such as [[readdirectorychanges]] (C++; `ReadDirectoryChangesW` wrapper; async recursive create/modify/delete/rename notify; sync/security monitoring) complement kernel/ETW file telemetry for AC integrity tooling. (source: wiki/sources/descriptions/jimbeveridge__readdirectorychanges.md). Synthetic multi-provider ETW event generators such as [[bamboozledr]] (TUI; realistic security events for EDR/detection and log-analysis lab testing) sit in the same AC / IS-forensics telemetry lane. (source: wiki/sources/descriptions/olafhartong__BamboozlEDR.md) ETW Testing / threat-tracing disable samples such as [[disable-threat-tracing]] (C; Anti Cheat stress-testing) exercise the opposite disable/blind surface for the same ThreatIntel telemetry lane. (source: wiki/sources/descriptions/muturikaranja__disable-threat-tracing.md) Kernel callback/ETW blinders such as [[telemetry-sourcerer]] (enumerate + disable callbacks/ETW; unsigned driver; test signing / DSE / cert signing) sit in the same Cheat Windows kernel explorer / ETW Testing lane. (source: wiki/sources/descriptions/jthuraisamy__TelemetrySourcerer.md) Ring3 Instrumentation Callback research such as [[instrumentation-callback-syscall-logger]] inspects each syscall on kernel return before user-mode resumes; [[instrumentation-callbacks]] (Deputation; C++/asm; TLS-based recursion control; syscall origin monitoring; analysis and abuse scenarios; Instrumentation Callback); [[instrumentation-callbacks-lib]] (1027565; user-mode library PoC; syscall/APC/exception/user-mode-callback/thread-init interception on kernel→user transitions; EDR telemetry + debugging research; Instrumentation Callback) (source: wiki/sources/descriptions/1027565__InstrumentationCallbacks.md) (source: wiki/sources/descriptions/Deputation__instrumentation_callbacks.md); hooking PoCs such as [[hooking-via-instrumentation-callback]] intercept returns via `NtSetInformationProcess` / `ProcessInstrumentationCallback` without patching ntdll stubs. BattlEye bypass PoCs such as [[beservice-intcallbacks]] (R4YVEN; C++/asm; instrumentation-callback behavior + symbol-handling; exploratory BE service bypass research; README Instrumentation Callback) sit in the same offensive Instrumentation Callback lane. (source: wiki/sources/descriptions/R4YVEN__beservice_intcallbacks.md) (source: wiki/sources/descriptions/secrary__Hooking-via-InstrumentationCallback.md) Alignment edge-case PoCs such as [[nasty-alignment]] trigger unaligned access under Instrumentation Callback handlers and surface `STATUS_DATATYPE_MISALIGNMENT` callback failures. (source: wiki/sources/descriptions/asamy__NastyAlignment.md) ETW TI–adjacent Instrumentation Callback syscall-hook research such as [[etwti-syscall-hook]] sits in the same Detection:hook lane. (source: wiki/sources/descriptions/paranoidninja__EtwTi-Syscall-Hook.md) ETW syscall hook/modding research such as [[etw-syscall]] (huoji120; C/C++; Some Tricks / Windows Ring3) sits in the same ETW/syscall instrumentation lane. (source: wiki/sources/descriptions/huoji120__Etw-Syscall.md) Title-specific hidden-syscall monitors such as [[hidden-syscall-monitoring]] (Call of Duty anticheat) sit in the same syscall-telemetry RE lane. (source: wiki/sources/descriptions/ssnob__hidden_syscall_monitoring.md) Defensive direct/indirect syscall origin checks such as [[syscall-detect]] (C; Instrumentation Callback or thread stack inspection; flags custom stubs vs ntdll) sit in the same syscall-evasion detection lane. (source: wiki/sources/descriptions/jackullrich__syscall-detect.md) Educational Windows AC PoCs such as [[anticheat-poc]] (debugger / code-integrity / cheat-signature memory scan / suspicious-process enum) and beginner fundamentals sample [[basic-anti-cheat]] (process integrity, signature scan, debugger detect, module enum, memory region validation; gmh5225) sit in the same Instrumentation Callback README lane. (source: wiki/sources/descriptions/thetuh__anticheat-poc.md) (source: wiki/sources/descriptions/gmh5225__Basic_Anti-Cheat.md) Linux decoy process generators such as [[d-process]] (C/shell; on-demand compile + nohup; arbitrary executable names in process lists; bulk killall; process-enumeration / tracker-check evasion research) (source: wiki/sources/descriptions/gigbh__d-process.md) sit in the adjacent Linux process-presence bypass lane. Kernel PoC stacks such as [[darken-anticheat]] (driver communication / process integrity / module verify / signature scan / debugger detect / overlay monitor) illustrate the same layered detection surface. (source: wiki/sources/descriptions/noahware__darken-anticheat.md) Experimental multi-telemetry kernel AC prototypes such as [[kernel-anti-cheat]] (gmh5225; NMI stack walks via `HalSendNMI`/`RtlCaptureStackBackTrace`, system-thread start scans, big-pool inspection, boot UUID, hypervisor checks, PiDDBCache kdmapper/drvmap residue; research sandbox with documented false-positive risk; README `[NMI]`) combine stack forensics, module-range validation, and mapper artifact checks in one driver. (source: wiki/sources/descriptions/gmh5225__Kernel_Anti-Cheat.md) Kernel AC simulation driver [[anti-cheat-emulator]] (ApexLegendsUC; C++ KM driver; system-thread/stack-trace/BigPool/PiDDB/dispatch-table/physical-memory-handle heuristics plus hypervisor and kernel-mapping checks; emulates practical anti-cheat telemetry for pipeline research and testing) extends that multi-heuristic defensive sandbox lane. (source: wiki/sources/descriptions/ApexLegendsUC__anti-cheat-emulator.md) Host-integrity prototype [[kernel-anticheat]] (Vasieco; unsigned/abnormal drivers, physical-memory handle abuse, hypervisor traces, big-pool artifacts, mapper residue, suspicious system threads; C/C++ Visual Studio driver; anti-cheat research) (source: wiki/sources/descriptions/Vasieco__Kernel-Anticheat.md) Focused NMI stack-walk callback teaching drivers such as [[nmi-callback-handler]] (donnaskiez; `KeRegisterNmiCallback`; MACHINE_FRAME/iretq interrupted-RIP capture across CPUs; flags execution from suspicious regions; README Mapped Driver by NMI Callback) (source: wiki/sources/descriptions/donnaskiez__nmi-callback-handler.md); [[nmi-stack-walk]] (1401199262; NMI callback stack backtrace on selected CPUs; no-module mapped-driver detection PoC; README Mapped Driver by NMI Callback) (source: wiki/sources/descriptions/1401199262__NMIStackWalk.md) heuristic mapped-driver/thread detector [[nomad]] (Rwkeith; thread stack walk + entry-point validation, big-pool abnormal refs, IOCTL hook signals; C++ WDK driver telemetry; README Mapped Driver) (source: wiki/sources/descriptions/Rwkeith__Nomad.md); Multi-vector open-source kernel AC reference [[ac]] (donnaskiez; NMI/APC/DPC stack analysis, `.text` integrity, ObRegisterCallbacks handle stripping, chained data-pointer detection, attached-thread and return-address exception-hook checks, system-module device verification, process handle-table enumeration; defensive AC engineering) (source: wiki/sources/descriptions/donnaskiez__ac.md); behavior-based kernel threat-detection platform [[peacemaker]] (D4stiny; process/image/remote-thread/hidden-code/FS+registry monitoring with stack-trace context; driver + CLI + Qt GUI; defensive anti-malware + AC research; README Anti Virus in fact but also Anti Cheat) (source: wiki/sources/descriptions/D4stiny__PeaceMaker.md) Demand-start reference frameworks such as [[oac]] (lauralex; Open Anti-Cheat — x64 kernel driver + user-mode client; pre-launch integrity gates, suspended launch, ObRegisterCallbacks handle filtering, cross-view integrity checks, optional PiDDB/`MmUnloadedDrivers` forensics, HVCI/code-integrity telemetry, privacy-preserving hardware identity, audit/test/production modes) target game security engineers building production-oriented kernel-assisted AC on Windows. (source: wiki/sources/descriptions/lauralex__OAC.md) Kernel monitoring driver samples such as [[acdrv]] (gmh5225; process/module callbacks, memory access interception, syscall monitoring via custom driver interface; README ETW Hook tag; anti-cheat driver component research) sit in the same prototype lane. (source: wiki/sources/descriptions/gmh5225__AcDrv.md) Unconventional Ring3 PoC collections such as [[function-collections]] (C; asset pipelines / memory analysis) support the same anti-cheat / Windows Ring3 callback research lane. (source: wiki/sources/descriptions/whokilleddb__function-collections.md) `LdrRegisterDllNotification` modding/research samples such as [[dllnotif]] (blaquee; C++/C++; defensive AC engineers studying Ring3 DLL load callbacks) (source: wiki/sources/descriptions/blaquee__dllnotif.md) sit in that same user-mode notification surface beside kernel [[kernel-callbacks]] image-load notify routines. Trusted-process mapping (e.g. [[lsass-extend-mapper]] hosting unsigned drivers via lsass address-space extend; LSASS-context **`KSecDD.sys` IOCTL kernel execution such as [[kexecdd]] — LSASS DLL inject → `IOCTL_KSEC_IPC_SET_FUNCTION_RETURN` arbitrary kernel exec + DSE disable via `ci.dll!g_CiOptions`; original PoC; gmh5225) (source: wiki/sources/descriptions/gmh5225__KExecDD.md) and enhanced fork [[kexecddplus]] — DSE bypass and arbitrary kernel memory manipulation; gmh5225) (source: wiki/sources/descriptions/gmh5225__KexecDDPlus.md) and post-execution map cleanup (e.g. [[revert-mapper]] freeing mapped driver memory and pool-tag traces; [[nullmap]] header zeroing + pool unlink after manual map; [[drv-hide-and-camouflage]] (IcEy-999; C ring-0; unsigned-driver load masking via unexported kernel routines, manual offset init, object/import-table manipulation; modern Windows tests; README Hide Driver) (source: wiki/sources/descriptions/IcEy-999__Drv_Hide_And_Camouflage.md); [[hidedriver]] (ExpLife0011; ETW symbol discovery; PatchGuard-aware `DriverObject->DriverSection` removal via `MiProcessLoaderEntry`; post-load cleanup thread; driver forensic footprint / AC evasion research; README `[Hide Driver By MiProcessLoaderEntry]`) (source: wiki/sources/descriptions/ExpLife0011__HideDriver.md); [[sinmapper]] section-overlay map into already-signed driver image with physmem/PTE permission changes + kernel bookkeeping cleanup (armvirus; Manual Map In Signed Driver) (source: wiki/sources/descriptions/armvirus__SinMapper.md); [[dsmm]] (0xf1a; C kernel PoC; manual map into discarded section of legitimate signed driver; post-boot system thread; PatchGuard-trigger avoidance research; README `[Discarded Driver Section Manual Map]`) (source: wiki/sources/descriptions/0xf1a__DSMM.md); [[lpmapper]] large-page driver mapper (VollRagm; shellcode into already-loaded large-page drivers without new allocation; registry large-page config; reduces pool/BigPool visibility vs pool-alloc mappers) (source: wiki/sources/descriptions/VollRagm__lpmapper.md); [[driver-dll-finder]] PE section-size scanner to locate replaceable driver/DLL hosts for section-overlay mappers (armvirus; Find Driver Useless Memory) (source: wiki/sources/descriptions/armvirus__DriverDllFInder.md); [[cos-mapper]] signed-helper maps unsigned payload via kernel hooks with unloaded-driver/cache cleanup (armvirus; Signed Driver Map) (source: wiki/sources/descriptions/armvirus__CosMapper.md); [[driver-session-mapper]] session-space map + loader-metadata scrub on unload; [[callmewin32kdriver]] win32k.sys session-driver unsigned load with anti-rootkit dump resistance and `MmCopyMemory`-scan bypass; PUBG cheat-driver lineage) (source: wiki/sources/descriptions/gmh5225__nullmap.md) (source: wiki/sources/descriptions/gmh5225__Driver-SessionMapper.md) (source: wiki/sources/descriptions/gmh5225__CallMeWin32kDriver.md) are common research counterparts to those scanners. Catalogs of known Driver Mappers such as [[known-driver-mappers]] support AC stress-testing and mapper-signature research. (source: wiki/sources/descriptions/stuxnet147__Known-Driver-Mappers.md) Custom **IoCreateDriver** load-path bypass research such as [[iocreatedriver]] (Th3Spl; reimplements driver creation to skip standard load visibility/logging; manual-map entry notes; offensive counterpart to PiDDB / load-artifact forensics) (source: wiki/sources/descriptions/Th3Spl__IoCreateDriver.md) Kernel hook-channel manual mapper [[umap-mapper]] (FarmEquipment69; C; `NtConvertBetweenAuxiliaryCounterAndPerformanceCounter` function-pointer hook receives map requests; in-kernel PE copy + import/reloc + entry; pattern scan + protected writes; driver-load evasion research) (source: wiki/sources/descriptions/FarmEquipment69__umap-mapper.md) Canonical manual mapper [[kdmapper]] (TheCruZ; C++; full map pipeline via `iqvw64e.sys`; trace-reduction + multi-build compatibility) and Rust ports such as [[kdmapper-rs]] illustrate the same unsigned-driver map surface for detection labs. (source: wiki/sources/descriptions/TheCruZ__kdmapper.md) (source: wiki/sources/descriptions/rmccrystal__kdmapper-rs.md) C++ Saturn kernel manual mapper [[saturn-mapper]] (PE sections / imports / relocs; `iqvw64e.sys`) sits in the same BYOVD map lane. (source: wiki/sources/descriptions/paysonism__saturn-mapper.md) Hidden module/DLL detectors such as [[hidden-module-detector]] (mq1n; C/C++; Detection:Hide) and Linux hidden LKM detectors such as [[modreveal]] (C; find concealed kernel modules; Detection:Hide) (source: wiki/sources/descriptions/jafarlihi__modreveal.md); offensive Windows minifilter concealment PoCs such as [[puzzle]] (Kudaes; Rust; bind links, ID mapping, cloud sync providers, WIM hash manipulation; stealth post-exploitation; cheat / hide) (source: wiki/sources/descriptions/Kudaes__Puzzle.md) and eBPF **getdents-flow timing-anomaly** rootkit research such as [[rootkit-detection-ebpf-time-trace]] (ait-aecid; behavior-based file-hiding detection; semi-supervised statistical anomaly scoring; kernel security research) (source: wiki/sources/descriptions/ait-aecid__rootkit-detection-ebpf-time-trace.md) and Linux LKM **syscall/hook integrity monitors** such as [[ksentinel]] (MatheuZSecurity; function prologue hashing, syscall table validation, LSTAR checks; configurable intervals + anti-unload; rootkit hook-tampering detection research) (source: wiki/sources/descriptions/MatheuZSecurity__ksentinel.md) and educational **Linux rootkit technique corpus** [[rootkit]] (MatheuZSecurity; kernel/user/eBPF subprojects; file/connection hiding, syscall/ftrace hooking, privesc, persistence, anti-forensics; anti-rootkit detection testing) (source: wiki/sources/descriptions/MatheuZSecurity__Rootkit.md) and Linux **io_uring post-exploitation agents** such as [[ring-reaper]] (MatheuZSecurity; C agent + Python control server; async kernel I/O replaces traditional read/write/send/receive syscalls; file transfer, process/user enum, network inspection, session control; EDR evasion testing in authorized environments) (source: wiki/sources/descriptions/MatheuZSecurity__RingReaper.md) and kernel-level DLL thread injection detectors such as [[dll-thread-injection-detector]] (mq1n; C/C++; Detection:Injection) and callback-based image-map stack validators such as [[driver-watchowl]] (gmh5225; load-image + thread notify; stack-trace check for suspicious user-mode mapping; Detection:Injection; README `[ImageNotify+Stack Trace]`) (source: wiki/sources/descriptions/gmh5225__Driver-WatchOwl.md) sit in the same concealment lane as thread-enumeration detectors (looking for manual-map worker threads) studied against threadless Ring0 PoCs such as [[zero-thread-kernel]], page-table/IDT/NMI-evasive covert system-thread PoCs such as [[covert-thread]] (brew02; remove loaded module from system page tables; custom address space + IDT; block per-thread NMI inspection; direct kernel fn exec without wrapper macros; covert thread / anti-forensic driver research) (source: wiki/sources/descriptions/brew02__CovertThread.md), and concealed-start PoCs such as [[driver-hide-kernel-thread-iocancelirp]] (gmh5225; visible thread start at `IoCancelIrp` with payload via IRP cancel path; README `[Hide Kernel Thread]`) (source: wiki/sources/descriptions/gmh5225__Driver-HideKernelThread-IoCancelIrp.md) and kernel thread-hiding PoCs such as [[diglett]] (Rwkeith; hide system threads + alter entry-address visibility; driver + client; README `[Hide Kernel Thread]`) (source: wiki/sources/descriptions/Rwkeith__Diglett.md) and thread sleep-emulation / context-manipulation PoCs such as [[cheat-attack-thread-slemu]] (gmh5225; Heartbeat Testing; hide cheat threads from AC enumeration) (source: wiki/sources/descriptions/gmh5225__cheat-attack-thread-slemu.md); KTHREAD field-spoof detection PoCs such as [[hidden-thread-finder]] (gmh5225; APC vs NMI callback recovery after tampering `SystemThread`/`ApcQueueable`/`StackBase`/`InitialStack`; Win10 20H2; hidden-thread inspection experiment) (source: wiki/sources/descriptions/gmh5225__Hidden-Thread-Finder.md); KPRCB-based hidden-thread detection PoCs such as [[detect-hiddenthread-via-kprcb]] (KANKOSHEV; walks KPRCB-related structures for threads removed from the process/thread ID table; thread lookup verification; Visual Studio kernel driver; anti-cheat integrity monitoring / forensic research) (source: wiki/sources/descriptions/KANKOSHEV__Detect-HiddenThread-via-KPRCB.md); multi-method hidden-thread/rootkit scanners such as [[unkover]] (eversinc33; scheduler/PspCidTable/stack-scan cross-ref; NMI/APC mapped-driver detection; kernel forensics) (source: wiki/sources/descriptions/eversinc33__unKover.md); process-hiding rootkit samples such as [[blanket]] (ActiveProcessLinks unlink + PspCidTable patch + `NtQuerySystemInformation` hook; cheat / hide) (source: wiki/sources/descriptions/kitty8904__blanket.md); multi-AC kernel bypass drivers such as [[battleye-vac-eac-kernel-bypass]] (daswareinfach; process hide + IOCTL kernel R/W; FSFilter + registry filter + process notify callbacks; README FsFilter Testing; [[battleye]]/[[easy-anti-cheat]]/VAC bypass framing) (source: wiki/sources/descriptions/daswareinfach__Battleye-VAC-EAC-Kernel-Bypass.md); CSRSS `CSR_PROCESS` list enumeration PoCs such as [[rootkit-2]] (gmh5225; CsrRootProcess hidden-process detection via `csrss.exe`; Detection:Hide / rootkit triage) (source: wiki/sources/descriptions/gmh5225__Rootkit-2.md); process/file obfuscation PoCs such as [[herpaderping]] (on-disk decoy vs mapped image; subverts callback / on-write `IRP_MJ_CLEANUP` attribution; cheat / hide) (source: wiki/sources/descriptions/jxy-s__herpaderping.md). (source: wiki/sources/descriptions/mq1n__HiddenModuleDetector.md) (source: wiki/sources/descriptions/mq1n__DLLThreadInjectionDetector.md) Kernel codecave PoCs such as [[kernel-codecave-poc]] plant shellcode in unused `.text` padding of loaded legitimate drivers to avoid new executable kernel allocations that pool/integrity scans target. (source: wiki/sources/descriptions/rogerxiii__kernel-codecave-poc.md) Driver dispatch hijack / no-image execution PoCs such as [[driver-driver-no-image]] (gmh5225; inject shellcode into existing drivers—e.g. NTFS dispatch handlers—via inline hooks + WP disable + trampolines; avoids standalone custom driver image path; README `[Hijack Driver]`) extend that concealment lane by running payloads through legitimate driver code paths. (source: wiki/sources/descriptions/gmh5225__Driver-DriverNoImage.md) HWID / GPU serial fingerprinting (undocumented NvAPI) is illustrated by [[nvidiaapi]]; NVIDIA GPU UUID spoof via `nvlddmkm.sys` patches such as [[nvidia-gpu-spoof]] extend the same Detection:HWID threat model (source: wiki/sources/descriptions/roomyoni__Nvidia-GPU-Spoof.md); game-side GPU hardware-check bypass DLLs such as [[hardware-bypass]] (Ke4ton; C++ VS; post-launch inject patches runtime validation; client integrity / hardware-gating RE) illustrate the offensive client-integrity bypass lane beside kernel HWID spoofing (source: wiki/sources/descriptions/Ke4ton__hardware_bypass.md); TPM EK spoofing via hooked `DeviceIoControl` / TPM device-stack filters is detected by [[detect-tpm-spoofing]] (IOCTL `TPM2_ReadPublic` vs `TPM.sys` cached buffers); offensive TPM identifier spoof via hooked TPM request paths such as [[tpm-spoofer]] (KM hook + UM EK/serial checker; SamuelTulach EK-interception PoC) (source: wiki/sources/descriptions/SamuelTulach__tpm-spoofer.md) (source: wiki/sources/descriptions/s0ngidong3__TPM-SPOOFER.md); MMIO-direct TPM 2.0 public EK reads that bypass OS hooks are illustrated by [[tpm-mmio]] (source: wiki/sources/descriptions/synctop__tpm-mmio.md); offensive AMIDEWIN system-identifier spoof samples such as [[spoofer-amidewin]] and full HWID spoofers such as [[hwidspoofer]] (modify hardware IDs + clean tracking traces) inform the same Detection:HWID threat model (source: wiki/sources/descriptions/singhhdev__Spoofer-AMIDEWIN.md) (source: wiki/sources/descriptions/semihcevik__hwidspoofer.md); kernel-level Fortnite/Valorant HWID spoof samples such as [[hwid-spoofer-for-fortnite-and-valorant]] (C/C++; gupr0x4) extend that model (source: wiki/sources/descriptions/gupr0x4__HWID-Spoofer-for-Fortnite-and-Valorant.md); Wizard101 HWID spoof samples such as [[wizard101-spoofer]] (disk/MAC/motherboard UUID; gmh5225) extend that model (source: wiki/sources/descriptions/gmh5225__wizard101-spoofer.md); Apex Legends HWID spoof samples such as [[apex-spoofer]] (gmh5225; kernel-level work; cheat / HWID; EAC-protected Apex) extend that model (source: wiki/sources/descriptions/gmh5225__Apex-Spoofer.md); bundled Apex Legends cheat resources such as [[apex-cheating]] (cheatingwitdacode; C# HWID spoofer + seasonal offset dumps + EAC bypass scripts; cheat / game:apex legends) aggregate HWID spoofing, offset tracking, and EAC bypass study in one repo (source: wiki/sources/descriptions/cheatingwitdacode__apex-cheating.md); EAC/BattlEye HWID spoofer samples such as [[hwid-spoofer]] (C/C++; gmh5225) extend that model (source: wiki/sources/descriptions/gmh5225__hwid-spoofer.md); [[hwid-spoofer-eac-be]] (disk serial / MAC / SMBIOS kernel hooks; EAC/BE HWID-ban evasion; gmh5225) extends that model (source: wiki/sources/descriptions/gmh5225__Hwid-Spoofer-EAC-BE.md); [[hwid-eclipsed-spoofer-eac-be]] (Eclipsed; disk serial / NIC / other HWIDs at kernel level; EAC/BE HWID-ban evasion; gmh5225) extends that model (source: wiki/sources/descriptions/gmh5225__HWID-EclipsedSpoofer-EAC-BE.md); [[hwid-kernel-spoofer]] (disk serial / MAC / SMBIOS / GPU via `IRP_MJ_DEVICE_CONTROL` dispatch hooks on storage/network drivers; gmh5225) extends that model (source: wiki/sources/descriptions/gmh5225__HWID-Kernel-Spoofer.md); [[hwid--spoofer]] (Theordernarkoz; C/KMDF kernel driver; disk/mount/network control-path hooks; disk/NIC/SMBIOS/GPU identifiers; anti-cheat evasion; cheat / HWID) extends that model (source: wiki/sources/descriptions/Theordernarkoz__Hwid--Spoofer.md); permanent reboot-persistent HWID spoof research such as [[hwid-permanent-hwid-spoofer]] (gmh5225; firmware-level IDs via kernel driver or registry; spoof survives reboot without re-run; cheat / HWID) extends that model (source: wiki/sources/descriptions/gmh5225__HWID-Permanent-HWID-Spoofer.md); comprehensive v6 permanent HWID spoofer such as [[full-hwid-spoofer-v6]] (gmh5225; disk/NIC/GPU/SMBIOS/registry via KdMapper kernel driver + ImGui GUI; AMD/Intel Win10/11; cheat / HWID) extends that model (source: wiki/sources/descriptions/gmh5225__Full-Hwid-Spoofer-V6.md); integrated external-cheat + HWID bundles such as [[fortnite-external-5]] (gmh5225; Fortnite external with built-in kernel disk-serial spoofer, ImGui overlay, FNV-1a string obfuscation, ESP/aimbot RPM; cheat / game:fortnite [External]) extend that model (source: wiki/sources/descriptions/gmh5225__Fortnite-External-5.md); compiled snippet-based HWID spoof research such as [[hwid-pasted-hwid-spoofer]] (gmh5225; disk serial / NIC MAC from public spoofing snippets; hardware-ban evasion; cheat / HWID) extends that model (source: wiki/sources/descriptions/gmh5225__HWID-Pasted-Hwid-Spoofer.md); C++ kernel-driver HWID spoof samples such as [[precision-spoofer-cpp]]; universal ImGui-loader HWID spoofer bases such as [[hwid-spoofer-ud-fortnite-warzone-apex-rust-escape-from-tarkov-and-all-eac-be-games-imgui-loader-base]] (gmh5225; disk/NIC/SMBIOS/GPU serial kernel spoof; EAC/BE; Fortnite/Warzone/Apex/Rust/Tarkov; cheat / HWID) extend that model (source: wiki/sources/descriptions/gmh5225__HWID-Spoofer-UD-Fortnite-WarZone-Apex-Rust-Escape-From-Tarkov-and-all-EAC-BE-Games-IMGUI-Loader-Base.md); leaked ImGui HWID spoofer research such as [[imgui-spoofer-leaked]] (Veuqx0; C++; ImGui GUI + loader/mapper kernel components + WinAPI routines; debugger/process anti-analysis; ban-evasion spoofer structure study; cheat / HWID) extends that model (source: wiki/sources/descriptions/Veuqx0__ImGui-Spoofer-Leaked.md); EAC-oriented ImGui HWID spoof toolkit such as [[hwid-spoofer-eac]] (BuzzerFelix; C++; ImGui GUI + driver mapper/loader + service handling; low-level hardware identifier changes; practical testing workflow; game bypass / anti-cheat HWID research; cheat / HWID) extends that model (source: wiki/sources/descriptions/BuzzerFelix__HWIDSpooferEAC.md); one-click ImGui+DX9 HWID spoofer launchers such as [[theordernarkoz-hwid-spoofer]] (Theordernarkoz; C++; Dear ImGui + DirectX 9 GUI; downloads external driver/helper binaries then CLI spoof step; anti-cheat bypass workflows; cheat / HWID) extend that model (source: wiki/sources/descriptions/Theordernarkoz__Hwid-Spoofer.md) (gmh5225; driver development; cheat / HWID) extend that model (source: wiki/sources/descriptions/gmh5225__PrecisionSpoofer-CPP.md); HDD serial spoof samples such as [[hdd-serial-spoofer]] (namazso; C/C++) target the disk-serial slice of that surface (source: wiki/sources/descriptions/namazso__hdd_serial_spoofer.md); educational Windows C++ HWID PoC samples such as [[skotschia-hwid-spoofer]] (Skotschia; disk serial / SMART / SMBIOS; low-level helper modules + VS project files; older PoC with detection-hardening gaps; cheat / HWID) extend that research lane (source: wiki/sources/descriptions/Skotschia__hwid_spoofer.md); open-source Windows 10/11 spoofing and cleanup toolkit such as [[windows-spoofer]] (Scrut1ny; Batch + PowerShell; system identifiers + network values + trace cleanup; volume ID / SMBIOS via external utilities; platform limits documented; anti-cheat fingerprinting research; cheat / HWID) extends that research lane (source: wiki/sources/descriptions/Scrut1ny__Windows-Spoofer.md); RAID0 disk-serial uncloaking such as [[uncloaking-raid0-hwid-serials]] (gmh5225; read true serials hidden behind RAID0 when spoofers mask identifiers) complements that detection surface (source: wiki/sources/descriptions/gmh5225__Uncloaking-RAID0-HWID-Serials.md). WMI-based Windows hardware inventory CLIs such as [[windows-hardware-info]] (C++; query hardware info of interest) support the same Detection:HWID enumeration lane. (source: wiki/sources/descriptions/paradoxwastaken__WindowsHardwareInfo.md). SMBIOS manufacturer/model/serial checkers such as [[hwid-checker-mg]] focus on system serial ranges for the same lane. (source: wiki/sources/descriptions/medievalghoul__hwid-checker-mg.md). PCI/AHCI direct HWID collection PoCs such as [[pciban]] (KDIo3; brute-force PCI enumeration for storage-controller identifiers without higher-level OS APIs; reduces hook/spoof exposure on conventional HWID queries; Detection:HWID; experimental) extend that lane toward bare-metal controller reads. (source: wiki/sources/descriptions/KDIo3__PCIBan.md). Open-source hardware monitors such as [[openhardwaremonitor]] (C#/JS; sensor/driver paths for CPU/GPU telemetry) sit in the same Detection:HWID surface. (source: wiki/sources/descriptions/openhardwaremonitor__openhardwaremonitor.md). Actively maintained fork [[libre-hardware-monitor]] (LibreHardwareMonitor; C# WinForms + .NET library; CPU/GPU/storage temps, fans, voltages, loads, clocks; game performance / environment-aware telemetry) extends that lane. (source: wiki/sources/descriptions/LibreHardwareMonitor__LibreHardwareMonitor.md). Cross-platform C++ inventory libraries such as [[hwinfo]] (CPU/RAM/GPU/disk/network; unified Windows/Linux/macOS API) support HWID tooling and inventory apps. (source: wiki/sources/descriptions/lfreist__hwinfo.md). Rust Windows GPU display-name query utilities such as [[query-gpu-name-rs]] (Detection:HWID; adapter name enumeration) complement that inventory lane. (source: wiki/sources/descriptions/gmh5225__query-gpu-name-rs.md). Windows kernel **RAPL** (Running Average Power Limit) energy-counter drivers such as [[windows-rapl-driver]] (`WindowsKernelModeDriver10.0`; bare-metal MSR reads; Detection:HWID) extend bare-metal hardware telemetry beside usermode sensor stacks. (source: wiki/sources/descriptions/hubblo-org__windows-rapl-driver.md). WinRing0 CPU temperature sample such as [[winring0]] (ashleyhung; WinRing0 driver/API → CPUID + MSR per-core temps; admin; hardware monitoring practice) illustrates the same MSR-access telemetry surface. (source: wiki/sources/descriptions/ashleyhung__WinRing0.md). macOS SMC CPU temperature CLI [[osx-cpu-temp]] (C; IOKit `AppleSMC`; °C/°F) exposes thermal sensor reads for Apple-host HWID/monitoring study. (source: wiki/sources/descriptions/lavoiesl__osx-cpu-temp.md). Stack / return-address spoof research such as [[return-address-spoofer]] (C/C++; illustrates spoofed call origins vs unwind checks), reusable libraries such as [[spoof-stack-safecall]] (gmh5225/SafeCall; fake legitimate return addresses before API calls; EDR/AC stack-walk evasion) (source: wiki/sources/descriptions/gmh5225__spoof-stack-SafeCall.md), and synthetic-frame stack spoofing such as [[loudsunrun]] (namazso / SilentMoonWalk / VulcanRaven lineage) inform the `Detection:Spoof Stack` lane; CET-compatible fully backed loaders such as [[nocturneldr]] (signed-module cave + donor unwind) stress both software walks and shadow-stack validation. (source: wiki/sources/descriptions/veryboreddd__Return-address-spoofer.md) (source: wiki/sources/descriptions/susMdT__LoudSunRun.md) (source: wiki/sources/descriptions/xec412__NocturneLdr.md) Cheat Engine presence (window classes / process names / driver / debug artifacts, incl. renamed or anti-detect CE) is illustrated by [[cedetector]]. Filesystem artifact heuristics via [[detection-cheat-engine]] (`ReadDirectoryChangesW` on profile/`C:\`; flags `ADDRESSES.FIRST` / `MEMORY.FIRST` table filenames from `CEInfo.h`; no memory/process scan) extend that lane. (source: wiki/sources/descriptions/gmh5225__Detection-CheatEngine.md) Kernel debug-print callback PoCs such as [[detection-cheat-engine-ring0]] (`DbgSetDebugPrintCallback`; scans incoming debug strings for `dbvm-mode`; minimal meme PoC—not a full CE/DBVM detector; gmh5225) explore whether kernel debug output exposes Cheat Engine or DBVM state in test environments. (source: wiki/sources/descriptions/gmh5225__Detection-CheatEngine-Ring0.md) Anti Debugging technique catalogs such as [[makin]] (C; 30+ API/PEB/HWBP/timing/TLS debugger checks with console pass/fail) sit in the `Anti Cheat → Anti Debugging` lane. (source: wiki/sources/descriptions/secrary__makin.md) C++ anti-debugging samples such as [[anti-debugging]] (revsic; debugger-resistance techniques for AC/defensive RE) sit in the same lane. (source: wiki/sources/descriptions/revsic__AntiDebugging.md) Windows C++ anti-debug protector/loader samples such as [[anti-debugger-protector-loader]] (YouNeverKnow00; continuous debugger-process/window-title/driver scans; multiple debugger-detection checks; configurable scan intervals + optional auto-termination; VMProtect SDK integration artifacts; software protection / anti-debug pattern study; Anti Debugging) sit in the same lane. (source: wiki/sources/descriptions/YouNeverKnow00__Anti-Debugger-Protector-Loader.md) Windows anti-tamper / anti-crack framework prototype [[anti-crack-system]] (ReFo0; C++; anti-debugging, anti-dump, anti-attach, integrity checks, process-kill routines, self-remapping code paths, string obfuscation + lightweight encryption helpers; software protection experiments adaptable to game security tooling; Anti Debugging) (source: wiki/sources/descriptions/ReFo0__anti-crack-system.md); compact C++ anti-analysis toolkit [[dynamizer]] (PaulNorman01; string obfuscation, anti-step-over, SW/HW breakpoint checks, `.text` integrity, return-address manipulation, system DLL unhooking; modular drop-in anti-tamper / dynamic-analysis evasion research; Anti Debugging) (source: wiki/sources/descriptions/PaulNorman01__Dynamizer.md) Windows userland anti-debug library [[antidbg]] (NotRequiem; C/C++; fully syscalled API/timing/process-environment/HWBP/exception checks + direct-syscall evasion; stealth-focused anti-RE CLI; Anti Debugging) (source: wiki/sources/descriptions/NotRequiem__antidbg.md); Windows anti-debug library [[antidbg-baka]] (C/C++; Baka; PEB/NtQueryInformationProcess/HWBP/timing/exception/parent checks; ScyllaHide/HyperHide/TitanHide detection; integratable primitives; Anti Debugging) (source: wiki/sources/descriptions/gmh5225__antidbg-Baka.md); anti-debug plugin [[antidbg-amogus-plugin]] (C/C++; hooking / plugin development / debugging integration; Anti Debugging; gmh5225) (source: wiki/sources/descriptions/gmh5225__AntiDbg-AmogusPlugin.md) Linux anti-debugging technique catalog such as [[adbg]] (C/C++; debugging-focused; Anti Debugging) (source: wiki/sources/descriptions/hiatus__adbg.md); early-runtime Linux debugger detector such as [[ladd]] (BarakAharoni; C; ptrace, LD_PRELOAD tampering, TracerPid checks; anti-analysis research and Linux binary hardening; Anti Debugging) (source: wiki/sources/descriptions/BarakAharoni__LADD.md) C++/CLI NT anti-tamper framework such as [[umium]] (undocumented Windows NT syscalls + runtime modifications; detect/neutralize debug, memory tamper, sandbox; Anti Debugging) sit in the same lane. (source: wiki/sources/descriptions/hotline1337__umium.md) TTD-based debug testing such as [[ttd-anti-debugging]] (C/C++; hooking + debugging under Time Travel Debugging; Anti Cheat stress-testing / Debug Testing) (source: wiki/sources/descriptions/liors619__TtdAntiDebugging.md) Black Hat 2012 sample suite [[blackhat2012]] covers Anti-Debugging / Anti-Disassembly / Obfuscation / Anti-VM PoCs (C/C++ VS2010 + Flat Assembler). (source: wiki/sources/descriptions/rrbranco__blackhat2012.md) ScyllaHide Detector V2 [[scyllahidedetector2]] (C/C++; find ScyllaHide use when debugging / restoring bytes) sits in the same Anti Debugging lane. (source: wiki/sources/descriptions/samshine__ScyllaHideDetector2.md) Debugger-use / anti-anti-debug trace detectors such as [[wubbaboomark]] (hfiref0x; Ghidra/IDA/OllyDbg/x32dbg/x64dbg/WinDbg + hide-plugin tampering artifacts; Anti Debugging) (source: wiki/sources/descriptions/hfiref0x__WubbabooMark.md) RE-tool decoder blind spots such as [[hint-break]] (`0F 1A` / `0F 1B` ghost opcodes; anti-debug / anti-disasm research) sit in the same Anti Debugging lane. (source: wiki/sources/descriptions/sapdragon__hint-break.md) Detection:Hook tooling such as [[hook-buster]] (C/Python; hook integrity / bust research for AC engineers) and process-wide hook/patch scanners such as [[hookhunter]] (Windows; scan target process, build hook/patch reports, follow generic hooks to final destinations) sit under `Detection:hook`. (source: wiki/sources/descriptions/st4ckh0und__hook-buster.md) (source: wiki/sources/descriptions/mike1k__HookHunter.md); kernel export-inline-hook scanners such as [[driver-detect-nullshit]] (gmh5225; detects mov rax, imm64; jmp rax export trampolines in core Windows modules with out-of-image targets; Detection:hook / manual-map; README Null driver detector) (source: wiki/sources/descriptions/gmh5225__Driver-Detect-nullshit.md) win32k global-hotkey keylogger detectors such as [[hotkeybased-keylogger-detector]] (AsuNa-jp; KMDF driver; walks win32kfull hotkey table for suspicious `RegisterHotKey` registrations; defensive endpoint / Windows security testing; README Detect RegisterHotKey API) (source: wiki/sources/descriptions/AsuNa-jp__HotkeybasedKeyloggerDetector.md) Thread call-stack scanners such as [[thread-call-stack-scanner]] (m417z; safe unload of dynamically loaded hooked DLLs without crashes) support AC module hot-reload / teardown when inline hooks remain installed. (source: wiki/sources/descriptions/m417z__thread-call-stack-scanner.md) Lightweight single-process scan engine [[pe-sieve]] (malware + injected/hooked material collection; Detection:hook) is the core library behind live wrappers such as [[xmalhunter]] (injected code / inline hooks / hollowed modules; libpeconv; Detect malicious materials) in the same runtime injection / process-integrity detection lane. (source: wiki/sources/descriptions/hasherezade__pe-sieve.md) (source: wiki/sources/descriptions/push0ebp__xMalHunter.md) Open-source Windows anti-rootkit and low-level system analysis platform [[winark]] (BeneficialCode; C++ driver/kernel-library ecosystem, symbol and PE parsers, monitoring modules, investigation UI; security research and anti-cheat internals analysis; Tool) complements GUI toolkits such as [[openark]] in the same lane. (source: wiki/sources/descriptions/BeneficialCode__WinArk.md) Windows console rootkit/cheat scanner such as [[slauc91-anticheat]] (SLAUC91; C++ + partial kernel driver; USN/DNS, PE/PEB, modules/handles/threads/drivers, pattern matching, user-mode IAT plus kernel MSR/IDT/SSDT/IRP hook detection; Anti Cheat / rootkit scanner) extends that hook-and-integrity lane. (source: wiki/sources/descriptions/SLAUC91__AntiCheat.md) Offensive headerless PE rebuild tooling such as [[pereconstruct]] (Python; recover manually-mapped DLLs with runtime-wiped headers for static analysis of what manual-map detectors target) complements those live scanners on the cheat-side RE lane. (source: wiki/sources/descriptions/diabloidyobane__PEReconstruct.md) Cross-platform Rust live injection scanners such as [[ghost]] (RWX regions, shellcode, API/library hooks, process hollowing, thread anomalies, optional YARA + MITRE ATT&CK mapping; CLI/TUI watch, baseline diff, webhooks; optional Python ML; Windows/Linux/macOS) extend that Detection:Injection lane for defenders and AC analysts. (source: wiki/sources/descriptions/pandaadir05__ghost.md) Offensive RWX page discovery utilities such as [[rwxfinder]] (S12cybersecurity; VirtualQueryEx target-process memory walk; size-filtered RWX regions for code-injection staging research; cheat / injection:windows) complement that defensive lane on the cheat-side prep surface. (source: wiki/sources/descriptions/S12cybersecurity__RWXFinder.md) Kernel-mode page-table RWX scanners such as [[rwxscanner]] (Oliver-1-1; WDK driver walks PML4/PDPT/PD/PT via physical memory reads; logs suspicious writable+executable mappings per process with image name and admin-token metadata; low-level AC/malware detection around injected or self-modifying code; README [RWX Memory scanner]) extend that lane on the defensive side. (source: wiki/sources/descriptions/Oliver-1-1__RwxScanner.md); kernel memory layout scanners such as [[memscanner]] (FaEryICE; C WDK/VS; enumerate `DRIVER_OBJECT`, LDR entries, section/file objects from live kernel regions; Win7–Win10; kernel forensics / AC-oriented structure research; README Memory scanner) (source: wiki/sources/descriptions/FaEryICE__MemScanner.md); paging-structure driver-artifact scanners such as [[hygieia]] (Deputation; C/C++ WDK driver; scan paging structures for traces left by vulnerable drivers; 1 GB/2 MB/4 KB page mappings; low-level memory forensics for prior unsigned-driver activity; anti-cheat / kernel security research) (source: wiki/sources/descriptions/Deputation__hygieia.md); minimal PiDDBCache/MmUnloadedDrivers cleanup driver such as [[trace-cleaner]] (BadPlayer555; C++ KM driver; manual-map trace hygiene; educational anti-cheat detection-surface research; README Driver Trace Cleaner) (source: wiki/sources/descriptions/BadPlayer555__TraceCleaner.md) Kernel-mode `IRP_MJ_DEVICE_CONTROL` hook scanners such as [[device-control-hooks-scanner]] (Luchinkin; KMDF driver enumerates `\Driver` objects; validates device-control dispatch pointers against driver image bounds; module resolution for out-of-range handlers; kernel integrity auditing / driver hook detection; README [device-control-hooks-scanner]) extend driver-dispatch integrity checks on the defensive side. (source: wiki/sources/descriptions/Luchinkin__device-control-hooks-scanner.md); offensive `IRP_MJ_DEVICE_CONTROL` hijack PoCs such as [[swap-control-ioctl]] (Barracudach; SpeedFan.sys dispatch trampoline redirect; process memory copy/allocation/protection + module-base ioctl handlers; driver comm hook / AC detection study; README [Hijack IRP SpeedFan.sys]) (source: wiki/sources/descriptions/Barracudach__Swap-control-ioctl.md); ntoskrnl memory-vs-disk integrity verification such as [[detect-ntoskrnl-integrity]] (DejavuSecure; C++; validate in-memory ntoskrnl against on-disk image; SSDT transforms, page-table randomization, retpoline-era behavior; anti-rootkit / AC / defensive kernel security research; README [Memory Integrity Verification with Disk Verification of ntoskrnl.exe]) (source: wiki/sources/descriptions/DejavuSecure__DetectNtoskrnlIntegrity.md) Frankenstein-style APC injection PoCs such as [[frankenstein-apc-injection]] (S12cybersecurity; reuse leaked handles + pre-existing RWX + `NtQueueApcThreadEx2`; skip VirtualAllocEx/VirtualProtectEx/CreateRemoteThread; optional encrypted shellcode; EDR/AC low-footprint inject evaluation) stress that same detection surface. (source: wiki/sources/descriptions/S12cybersecurity__FrankensteinAPCInjection.md) NTDLL-gadget APC injectors such as [[ntqueueapcthreadex-ntdll-gadget-injection]] (LloydLabs; C PoC; scans ntdll executable sections for pop-and-return sequences; queues shellcode via `NtQueueApcThreadEx` with module-legitimate routine pointers; documents likely detection vectors; AC/EDR APC-execution telemetry evaluation) extend that same low-footprint inject evaluation surface. (source: wiki/sources/descriptions/LloydLabs__ntqueueapcthreadex-ntdll-gadget-injection.md) IDA-side live-vs-on-disk PE comparison such as [[patch-finder]] (executable memory byte-compare against mapped on-disk image; highlight patched/hooked sites in disassembly) complements the same Detection:hook / memory-integrity lane. (source: wiki/sources/descriptions/momo5502__patch-finder.md) Header-only C/C++ memory-integrity experiment headers such as [[integrity-experiments]] (gmh5225; `Detection:Memory Integrity`) sit in the same defensive prototyping lane. (source: wiki/sources/descriptions/gmh5225__integrity_experiments.md) Header-only PE section checksum library [[integrity]] (afulsamet; baseline non-writable section hashes, SSE4.2 CRC32, compile-time algorithm hooks; tamper detection / AC hardening) extends that lane. (source: wiki/sources/descriptions/afulsamet__integrity.md) Reusable Windows memory-protection library [[memory-guard]] (gmh5225; `PAGE_GUARD` / VEH / periodic integrity checks; alert or revert cheat/debugger tampering; Page Protection) extends that lane. (source: wiki/sources/descriptions/gmh5225__MemoryGuard.md) Senior-design modding-oriented AC detection such as [[ghostbusters]] (C++; gmh5225) extends that educational prototyping lane. (source: wiki/sources/descriptions/gmh5225__ghostbusters.md) Compiled multi-pattern string automata such as [[aho-corasick]] (Aho-Corasick ISM; mmap-persistent rule tables; high-throughput signature/YARA-style memory and file scans) sit in the same Signature Scanning backend lane. (source: wiki/sources/descriptions/mischasan__aho-corasick.md) Android Magisk ([[magisk]] systemless root / MagiskHide) / root detection (AppZygote + AIDL isolated process; Magisk artifacts / mount-namespace anomalies) is illustrated by archived [[magiskdetector]] under `Detection:Magisk`. (source: wiki/sources/descriptions/topjohnwu__Magisk.md) (source: wiki/sources/descriptions/vvb2060__MagiskDetector.md) Broader Android environment-integrity multi-check collections such as [[detection]] (root / Xposed / Frida / VPN / developer options; Java FS/process/property/native probes) sit in the same Detection:Android-root lane. (source: wiki/sources/descriptions/rushiranpise__detection.md) Kotlin native Android root detection via [[android-native-root-detector]] sits in the same lane. (source: wiki/sources/descriptions/reveny__Android-Native-Root-Detector.md) Hardware-backed Android key attestation (Keymaster/KeyMint AIDL; locked bootloader / verified-boot / key properties) is illustrated by [[keyattestation]] under the Bootloader lane. (source: wiki/sources/descriptions/vvb2060__KeyAttestation.md) Offensive Samsung TrustZone S-Keymaster TA key extraction via [[keybuster]] (CVE-2021-25444/25490; `libkeymaster_helper`) stresses the same HW-key trust model. (source: wiki/sources/descriptions/shakevsky__keybuster.md) Client-side Android RASP (root/debugger/hook/emulator/tamper; polymorphic Gradle check ordering) is illustrated by [[droidshield]]. (source: wiki/sources/descriptions/venkata-ram__DroidShield.md) Focused Detection:Frida samples such as [[antifrida]] (Java/C++) and hooking-oriented [[frida-detection]] (Java/C++; muellerberndt) sit in the same mobile instrumentation-detection lane. (source: wiki/sources/descriptions/qtfreet00__AntiFrida.md) (source: wiki/sources/descriptions/muellerberndt__frida-detection.md) Mobile RASP community hub [[free-rasp-community]] (Talsec; aggregates Android/iOS/Flutter/React Native/Capacitor/Cordova/KMP/Unity/Unreal integrations; root/jailbreak/Frida/Xposed/repackaging/tamper/integrity; optional freeMalwareDetection; OWASP MASVS V8; callback API). (source: wiki/sources/descriptions/talsec__Free-RASP-Community.md) Unity freeRASP / Talsec mobile RASP via [[free-rasp-unity-poc]] (C# plugin; Android/iOS bridges; root/jailbreak/Frida/emulator/integrity/debug/screen-capture callbacks). (source: wiki/sources/descriptions/talsec__Free-RASP-Unity-POC.md) Unity UPM soft AC [[com-sipvlib-anticheat]] (server-verified GameTime + IntegrityChecker debugger/root/jailbreak/emulator/clock-drift heuristics). (source: wiki/sources/descriptions/phajmvawnsix__com.sipvlib.anticheat.md) React Native freeRASP sibling [[free-rasp-reactnative]] (TS/JS + Kotlin/Swift; Magisk/KernelSU/Frida/tamper/integrity; `useFreeRasp`). (source: wiki/sources/descriptions/talsec__Free-RASP-ReactNative.md) Capacitor freeRASP sibling [[free-rasp-capacitor]] (TS + Kotlin/Swift; root/jailbreak/Frida/Shadow/tamper/rebinding/screen-capture). (source: wiki/sources/descriptions/talsec__Free-RASP-Capacitor.md) Cordova freeRASP sibling [[free-rasp-cordova]] (TS + Kotlin/Swift; root/jailbreak/Frida/tamper/integrity/bootloader/automation/screen-capture/time·location-spoof). (source: wiki/sources/descriptions/talsec__Free-RASP-Cordova.md) Flutter freeRASP sibling [[free-rasp-flutter]] (Dart + Kotlin/Swift; root/jailbreak/Frida/debugger/emulator/tamper/Appium/VPN/location-spoof/multi-instance; optional termination). (source: wiki/sources/descriptions/talsec__Free-RASP-Flutter.md) Kotlin Multiplatform freeRASP sibling [[free-rasp-kmp]] (shared Kotlin + Gradle multiplatform; native Talsec runtime; root/jailbreak/Frida/untrusted installs/automation/suspicious apps; optional termination). (source: wiki/sources/descriptions/talsec__Free-RASP-KMP.md) Native iOS freeRASP SDK [[free-rasp-ios]] (TalsecRuntime XCFramework; Swift; jailbreak/Frida/hook/simulator/tamper/signature/Secure Enclave/passcode/VPN/screenshot/screen-recording/time-spoof). (source: wiki/sources/descriptions/talsec__Free-RASP-iOS.md) Native Android freeRASP sample [[free-rasp-android]] (Kotlin/Gradle; `TalsecConfig` + `ThreatListener`; root/Magisk/Frida/emulator/tamper/integrity/screen-capture/location·WiFi-spoof; `TalsecSecurity-Community` Maven). (source: wiki/sources/descriptions/talsec__Free-RASP-Android.md) React Native Nitro RASP SDK [[rs-native-kit-security]] (Kotlin/Swift + TS; JSI via Nitro Modules; root/jailbreak/Frida/Xposed/Magisk/emulator/integrity/VPN/proxy/screen-capture + device risk engine). (source: wiki/sources/descriptions/rajssinde__rs-native-kit-security.md) Android device-fingerprinting / integrity SDKs such as [[trustdevice-android]] (TrustDecision Kotlin/Java; unique IDs + risk signals; ProGuard) and iOS sibling [[trustdevice-ios]] (CocoaPod; ObjC/Swift) sit in the same mobile HWID / device-integrity lane. (source: wiki/sources/descriptions/trustdecision__trustdevice-android.md) (source: wiki/sources/descriptions/trustdecision__trustdevice-ios.md) Offensive Android build/prop spoof profiles such as [[spoofing-collection]] (paired Magisk modules + LSPosed `Build` hooks; manufacturer/model/fingerprint; attestation props) sit opposite those SDKs. (source: wiki/sources/descriptions/mrx7014__SpoofingCollection.md) Android device-lock / HWID SDK research such as [[device-warlock]] (Java/C++; networking, SDK generation, native hooking; Detection:HWID). (source: wiki/sources/descriptions/imxiaoc996__DeviceWarLock.md) Linux eBPF runtime security / forensics platforms such as [[tracee]] (Aqua Security; kernel event collection + behavioral detections; container/K8s deployment; threat detection + runtime forensics; source: wiki/sources/descriptions/aquasecurity__tracee.md) complement enterprise host XDR / HIDS platforms such as [[wazuh]] (agent–manager IDS, FIM, log correlation; Elasticsearch viz) and archived SOC case-management platforms such as [[the-hive]] (TheHive-Project; Scala backend + web UI; alert triage and incident workflows; historical IR architecture study; README [EDR]) adjacent to AC/EDR telemetry design under the README `[XDR]` / `[EDR]` lanes. (source: wiki/sources/descriptions/zorftw__lsass-extend-mapper.md) (source: wiki/sources/descriptions/TheHive-Project__TheHive.md) (source: wiki/sources/descriptions/zorftw__revert-mapper.md) (source: wiki/sources/descriptions/zodiacon__EtwExplorer.md) (source: wiki/sources/descriptions/xuanxuan0__TiEtwAgent.md) (source: wiki/sources/descriptions/zer0condition__ZeroThreadKernel.md) (source: wiki/sources/descriptions/x86matthew__InstrumentationCallbackSyscallLogger.md) (source: wiki/sources/descriptions/weak1337__NvidiaApi.md) (source: wiki/sources/descriptions/weak1337__DetectTpmSpoofing.md) (source: wiki/sources/descriptions/synctop__tpm-mmio.md) (source: wiki/sources/descriptions/weak1337__CEDetector.md); offensive timing-API speed manipulation PoCs such as [[speedhack]] (absoIute; C++ injectable DLL; Detours hooks accelerate/slow/pause perceived runtime; cheat development + `Detection:SpeedHack` time-tampering research) (source: wiki/sources/descriptions/absoIute__Speedhack.md); CE-style sibling [[speed-hack]] (Letomaniy; C++ Visual Studio injectable DLL; Detours timing hooks; keyboard slowdown/accelerate/restore; cheat practice + `Detection:SpeedHack` research) (source: wiki/sources/descriptions/Letomaniy__Speed-Hack.md); compact learner-oriented [[ce-speed-hack]] (IamSanjid; C++ CE-style speed hack; Detours timing hooks; core hooking logic without full cheat framework; user-mode time-manipulation study) (source: wiki/sources/descriptions/IamSanjid__ce_speed_hack.md) (source: wiki/sources/descriptions/wazuh__wazuh.md) **Architecture:** user-mode scanners → kernel callbacks/VAD → optional **hypervisor EPT defense** (protect AC driver code pages, callback lists, ETW structures from guest-kernel R/W even after [[byovd]]; VM exits on unauthorized writes; complements [[kernel-callbacks]] and [[hvci]]; DMA remains a separate threat) → server-side replay/stats. (source: wiki/sources/skills/anti-cheat.md) Offensive EPT **read/view deception** such as [[notruth]] (KelvinMsft; VT-x/EPT hides user-mode memory by serving fake values on reads while execution stays controlled; stresses checksum and memory-integrity scanners; README Hide Memory By VT) sits on the attacker side of that hypervisor lane. (source: wiki/sources/descriptions/KelvinMsft__NoTruth.md) Defensive counterpart [[novahypervisor]] (Idov31; Intel host hypervisor enforces memory access policies on selected kernel addresses; BYOVD mitigation + logging client; virtualized kernel security / endpoint defense research) (source: wiki/sources/descriptions/Idov31__NovaHypervisor.md) Linux console AC research such as [[linux-anticheat]] (mikio815; WIP four-layer stack—Rust daemon, LSM eBPF ptrace/W^X/bpf() guards, kernel module for eBPF integrity, planned BitVisor VMX/EPT static-kernel write-protect; Aya; Linux 5.17+ BTF + BPF LSM; Steam Deck / Secure Boot / lockdown / TPM attestation targets) extends EPT defense to locked-down native Linux game hosts. (source: wiki/sources/descriptions/mikio815__linux-anticheat.md) Self-hosted server-authoritative frameworks such as [[certael]] (Rust client runtime + C ABI; Godot/Unity/Unreal adapters; signed action intents / rule packs; .NET control plane) sit in the open-source AC infrastructure lane rather than proprietary kernel products. (source: wiki/sources/descriptions/violetweather__Certael.md) Operator-hosted Windows client AC for FiveM such as [[atomicshieldclient]] (C#/.NET tray agent + WebView2 dashboard; native C++ engine with process/module/heuristic/manual-mapping guards, anti-debug, HWID, screenshots; EngineLoader/RuntimeLoader in-process manual map + named pipes; encrypted HTTP/WebSocket server backend; adem-hosni) extends the client-side monitoring lane. (source: wiki/sources/descriptions/adem-hosni__AtomicShieldClient.md) Server-side Lua CitizenFX resources such as [[dead-anticheat]] (Dead-Scripts; FiveM; noclip/spectate/godmode/infinite-ammo/mod-menu globals; JSON ban list + Discord webhook logging with optional screenshots; configurable event/key/command/entity blacklists; staff bypass) complement client-side FiveM AC with lightweight server-authoritative checks. (source: wiki/sources/descriptions/Dead-Scripts__Dead_antiCheat.md) Full-stack reference implementations such as [[chessking]] (Rust Axum/SQLx multiplayer chess; layered server-side AC—risk scoring, device fingerprinting, match integrity via shakmaty, IP reputation, chess-themed CAPTCHA step-up, ban escalation; admin security dashboard; JWT/rate-limit/firewall docs; educational account-abuse/AC audit reference) illustrate application-layer competitive-game defenses without kernel components. (source: wiki/sources/descriptions/web-coder-lab__chessking.md) Godot tower-defense builds such as [[gatewarden-public]] (PathValidator publishes machine-readable placement-abuse rejection codes; flow-field softlock/maze checks; 59 GUT tests + headless bot) illustrate transparent, test-driven in-game validation without kernel components. (source: wiki/sources/descriptions/euuuuuuan__gatewarden-public.md) Browser-based NES MMO reference implementations such as [[ff3mmo]] (Node.js WebSocket server + canvas/jsnes ROM client; server arbiters + inventory mirrors validate combat, trades, and economy against crafted packets; moderation tooling) illustrate wire-validation and anti-dup patterns for untrusted browser clients. (source: wiki/sources/descriptions/joeltco__ff3mmo.md) Browser twin-stick leaderboard reference implementations such as [[pew-game]] (nocoo; TypeScript/Next.js/Bun; HMAC-signed session tokens at game start; server validates score submissions for signature integrity, score/wave/duration plausibility, and replay prevention; SQLite leaderboard; unit+E2E anti-cheat tests; practical browser score-tamper reference) complement that lane for lightweight online leaderboards. (source: wiki/sources/descriptions/nocoo__pew-game.md) Windows-first open-source skeletons such as [[sentinelac]] (thin in-process SDK + signed UM service + ObRegisterCallbacks/load-image kernel stub; pipes/ALPC; overlay isolation; stack-walk injection detect; Node mTLS/SSE signature backend) illustrate the classic SDK→service→driver layered layout. (source: wiki/sources/descriptions/vovasicidk__sentinelac.md) Multi-component Windows x64 AC prototypes such as [[bloom-anticheat]] (Rycooop; kernel driver + UM DLL/app; ObRegisterCallbacks handle protection for AC + target processes; Visual Studio projects; kernel-callback vs UM monitoring tradeoffs; AC experimentation) sit in the same research lane. (source: wiki/sources/descriptions/Rycooop__Bloom-Anticheat.md) Open-source CS2 dedicated-server Metamod:Source plugins such as [[cs2ac]] (C++; Windows/Linux x64; behavioral analysis of aim, movement, inputs, and client settings without client install; ~17 detection modules incl. aimbot/aimlock/silent aim/movement/input abuse; chat/on-screen alerts, kick/ban, whitelist, Discord webhooks) target community server operators. (source: wiki/sources/descriptions/karola3vax__CS2AC.md) Experimental CounterStrikeSharp CS2 server plugins such as [[osanticheat]] (Pintuzoft; C#/.NET; server-visible positions/view angles/shots/timing only; statistical spinbot/aimbot snap/triggerbot/wallhack detectors incl. tracking, gaze, McNemar null test; fusion suspicion engine with decay/corroboration → Watch/Review tiers; log-only, no auto kick/ban; calibration against demos/live data; Anti Cheat / Server) offer probability-based heuristic flagging for community operators. (source: wiki/sources/descriptions/Pintuzoft__OSAntiCheat.md) Client-side observable-data CS2 suspicion tools such as [[cs2-tracker]] (LooperSalty; Python FastAPI + SQLite; Steam Web API + Game State Integration feeds only—no memory read or inject; ~30 explainable heuristic detectors with Bayesian 0–100 scoring + optional C++ live overlay; competitive-player/analyst transparency lane) complement server-side heuristics. (source: wiki/sources/descriptions/LooperSalty__cs2-tracker.md) ModSharp CS2 server moderation plugins such as [[cs2-calladmin]] (C# modular suite; chat-initiated player reports with admin claim/handle/dismiss workflow; LiteDB/MySQL/PostgreSQL persistence; optional Discord webhook embeds that update in place; cooldowns, duplicate detection, auto-close; public plugin API; in-game admin panel integration) complement automated detection with structured human report triage. (source: wiki/sources/descriptions/cs2-server-plugins__cs2-calladmin.md) Source 1 dedicated-server plugins such as [[nocheatz-3]] (C/C++; serverside anti-cheat for CS:S, CS:GO, CS:P, TF2; plugin development + SDK generation) extend that server-operator lane to classic Source titles. (source: wiki/sources/descriptions/kanekikun420__NoCheatZ-3.md) Title-specific CS2 client-side kernel companions such as [[cs2kac]] (KMDF driver + C++ usermode service on `cs2.exe`; ObRegisterCallbacks / image / process / thread notify; unsigned modules, cross-process handles, hidden threads, manual-mapped drivers, debuggers, code integrity, heartbeat; ring-buffer IOCTL reports + signed attestation toward [[cs2ac]]/CS2FOW server plugins) complement that server-side behavioral AC with privileged client integrity signals. (source: wiki/sources/descriptions/speedskater1610__CS2KAC.md) MIT-licensed reference OSS AC [[no-mercy]] (mq1n fork; README positions as the open-source AC "gold standard" for engineers building or studying client protection stacks) sits in the same Open Source Anti Cheat System lane. (source: wiki/sources/descriptions/mq1n__NoMercy.md) C++/C OSS AC systems such as [[anti-cheat]] and [[ice9]] (jnastarot; Open Source Anti Cheat System) sit in that lane beside sibling [[shibari]] PE tooling and [[furikuri]] obfuscation. (source: wiki/sources/descriptions/jnastarot__anti-cheat.md) (source: wiki/sources/descriptions/jnastarot__ice9.md) CS:GO-oriented deep-learning AC reference implementations such as [[deep-learning-anti-cheat-csgo]] (gmh5225; memory/code-integrity/process/debugger checks + network packet validation; detection-to-response pipeline; Open Source Anti Cheat System) illustrate end-to-end OSS AC design patterns. (source: wiki/sources/descriptions/gmh5225__anti-cheat.md) CS:GO anti-cheat plugin PoCs such as [[csgo-ac]] (ekknod; C++/C; proof-of-concept anti-cheat plugin + AC research; Open Source Anti Cheat System) complement server-side Source plugins and full OSS pipelines for defensive CS:GO plugin study. (source: wiki/sources/descriptions/ekknod__CSGO-AC.md) ekknod **TestBench** harnesses such as [[anti-cheat-testbench]] (C++/C; AC research + driver development + hooking; Open Source Anti Cheat System; README [TestBench]) extend that OSS AC evaluation lane for defensive engineers. (source: wiki/sources/descriptions/ekknod__Anti-Cheat-TestBench.md) Rust/Bevy multiplayer security testbeds such as [[bevy-personal-test]] (rollback netcode, state hashing, server replay validation, shadow-VM Wasm worker checks, Rhai sandbox VM, memory guards, dedicated validator services; fuzz targets; XX-Batsu) extend that lane with deterministic multiplayer integrity prototyping on the [[bevy]] stack. (source: wiki/sources/descriptions/XX-Batsu__bevy-personal-test.md) Server-authoritative Bevy netcode such as [[lightyear]] (client prediction/rollback, snapshot interpolation, lag compensation, tick-synced inputs; transport-agnostic UDP/WebSocket/Steam/WebTransport; client-server trust-boundary study; cBournhonesque) complements that lane for production netcode design research. (source: wiki/sources/descriptions/cBournhonesque__lightyear.md) Full-engine multiplayer stacks with built-in client integrity such as [[spark-engine]] (Krilliac; C++23 engine; replication, prediction, lag compensation, encryption, packet validation, memory integrity checks; engine-level trust-boundary research; Game Engine / source) complement Bevy netcode libraries for studying integrity design in a complete runtime. (source: wiki/sources/descriptions/Krilliac__SparkEngine.md) Wasm-sandbox platforms such as [[magnetite]] (deterministic authoritative SDK → wasm32-wasip1 / Wasmtime; `ReplayLog` / `verify_replay`; composable `magnetite-anticheat` validators with trust scores) build anti-cheat by construction—clients send inputs only. (source: wiki/sources/descriptions/vul-os__magnetite.md) Open-source protocol stacks such as [[ironwall]] (thin client + Intel SGX/AMD SEV TEE attestation + PLONK ZK human-input proofs + Hedera HCS/XRPL dual-anchored match receipts; Unity/Unreal integrations; Rust launcher with ECDSA module signing) target tamper-evident competitive play and dispute resolution. (source: wiki/sources/descriptions/wflores9__Ironwall.md) Title-specific host-side lobby plugins such as [[wellsanticheat]] (Among Us BepInEx / Harmony; RPC abuse / crash / spam / teleport / task-spoof detection; host-only kick/ban) sit in the lightweight open-source AC moderation lane. (source: wiki/sources/descriptions/somewhatpublicacc__wellsanticheat.md) [[banmod]] (GiannBart; Among Us BepInEx/IL2CPP Harmony; server-synced ban/cheater/teemer lists; AFK/camera/follow detectors; moderator UI; RPC/task abuse and lobby integrity; Anti Cheat) extends that host-moderation lane. (source: wiki/sources/descriptions/GiannBart__BanMod.md) open.mp / SA-MP server components such as [[open.mp-anticheat]] (native C++; client self-memory reads vs cheat signatures; modular detectors + RakNet inspect; configurable kick/ban / Pawn callback) sit in the same server-operator AC lane. (source: wiki/sources/descriptions/ricardoofnl__open.mp-anticheat.md) The MTA:SA client platform [[mtasa-blue]] (C++; built-in anti-cheat + hook/DLL analysis; Direct3D/DirectInput hooks; Lua resources) is the open-source GTA:SA multiplayer stack that research and third-party server AC often targets beside SA-MP/open.mp. (source: wiki/sources/descriptions/multitheftauto__mtasa-blue.md) GTA V in-process mod-menu cheat frameworks such as [[phake]] (ScriptHookV or direct memory access; RAGE engine state manipulation; cheat / `[Mod Menu]`; gmh5225) illustrate the Rockstar open-world client-side modding surface that proprietary Rockstar AC and server-side validation must reason about. (source: wiki/sources/descriptions/gmh5225__pHake.md) Leaked SpookiMystic GTA V online mod-menu source such as [[spookimystic-gta-leak]] (RAGE engine scripting hooks; money drops / teleport / griefing; online modification surface; cheat / `[Menu]`; gmh5225) illustrates the same Rockstar online cheat surface that server-side validation and proprietary AC must detect. (source: wiki/sources/descriptions/gmh5225__SpookiMystic-GTA-Leak.md) alt:V Multiplayer server AC implementation guides such as [[alt-v-anticheat-guide]] (gmh5225; cheat detection, client integrity validation, behavior monitoring, server-side logic hardening; Anti Cheat / guide; `[GTA5 MP servers]`) sit in the same GTA V multiplayer server-operator lane beside SA-MP/open.mp stacks. (source: wiki/sources/descriptions/gmh5225__alt-V-Anticheat-Guide.md) Production client-side AC builds such as [[gvmp-anticheat]] (divodeuxsevres; GVMP.de German roleplay; C++; ENet networking, DirectX hooks, MinHook interception, pattern scanning, process integrity; alt:V integration; Anti Cheat) extend that lane with a concrete reference implementation. (source: wiki/sources/descriptions/divodeuxsevres__gvmp-anticheat.md) Rhythm-game client anti-cheat research such as [[osu-aac]] (gmh5225; osu! auto-play bot / input-simulation / time-manipulation / memory-modification detection or bypass; Anti Anti Cheat) illustrates lightweight managed-client AC beside server-side replay pipelines. (source: wiki/sources/descriptions/gmh5225__osu-aac.md) Minecraft Bedrock MiTM anti-cheat proxies such as [[oomph]] (Go; packet inspect; server-authoritative movement/combat; entity rewind + raycast hits; Dragonfly / PocketMine-MP) extend that proxy/server-operator lane. (source: wiki/sources/descriptions/oomph-ac__oomph.md) Behavior-pack Script API addons such as [[paradox-anticheat]] (Visual1mpact; TypeScript; fly/killaura/reach/autoclicker/scaffold/noclip/xray checks + staff moderation commands; Realms/BDS; no external client install; Anti Cheat / game:minecraft) extend that Bedrock operator lane on native Realms and Bedrock Dedicated Server hosts. (source: wiki/sources/descriptions/Visual1mpact__Paradox_AntiCheat.md) Behavior-pack addons such as [[scythe-anticheat]] (MrDiamond64; JavaScript/JSON; Bedrock Scripting API + command/function files; combat/movement/packet-abuse/chat-spam/scaffold detection + moderation commands and player stats; Realms/worlds/servers; Anti Cheat / game:minecraft) extend that same Bedrock operator lane. (source: wiki/sources/descriptions/MrDiamond64__Scythe-AntiCheat.md) Knight Online Gamesoft server-side ACS such as [[gamesoftacs]] (speed/teleport/damage/inventory checks + client integrity; gameplay-pattern flagging for review) sits in the same custom MMO server-authoritative lane. (source: wiki/sources/descriptions/luisfelipe18__GamesoftACS.md) MapleStory private-server client build/AC frameworks such as [[maplestory-build-framework]] (C/C++; individualized client distribution + rudimentary anti-cheat; related RudiAC) sit in the lightweight custom MMO client-protection lane beside server-side [[maplestory143]] CheatTracker stacks. (source: wiki/sources/descriptions/johnsonjason__MapleStoryBuildFramework.md) Minecraft Java Bukkit/Spigot plugins such as [[avaanticheat]] (movement/combat/autoclick/packet checks; violation counter; Geyser Bedrock leniency) sit in the same Java-server operator AC lane. (source: wiki/sources/descriptions/nsharp-collab__AvAAntiCheat.md) Long-standing Bukkit/Spigot plugins such as [[nocheatplus]] (Java Maven multi-module; modular movement/combat/block/inventory/chat/packet-rate checks; cancel/log/setback actions; reflection-based internals + client-mod MOTD; broad version coverage; Anti Cheat / game:minecraft) are a reference baseline for server-side Minecraft AC design. (source: wiki/sources/descriptions/NoCheatPlus__NoCheatPlus.md) Modular Spigot/Paper plugins such as [[dakotaac]] (ProtocolLib packet inspection + Citizens2 NPCs; combat aimbot/kill aura/reach/velocity, movement, world interaction, and inventory modules; YAML thresholds + automated kick/ban) extend that lane with configurable server-side checks. (source: wiki/sources/descriptions/norbertbaricz__DakotaAC.md) Minecraft Paper plugins such as [[minecraft-anticheatai]] (DeepGuard; movement checks + on-server ONNX Runtime 1D-CNN over look/position/placement sequences; BehaviorRecorder labeled samples + PyTorch training pipeline; scaffold-bridging focus) extend that lane with ML-based detection. (source: wiki/sources/descriptions/llsgllsg__Minecraft_AntiCheatAI.md) Paper **1.21.4+** combat plugins such as [[mlanticheat]] (gravemaulr; Java 21; ensemble neural + logistic models + anomaly detection over combat rotation features; operator-labeled training sets; Shadow Mode alert review; optional PacketEvents packet-level rotation tracking; staff alerts, admin GUI, automatic retraining, floating score tags, combat dummy; per-server adaptive PvP cheat detection) extend that lane with server-specific ML combat scoring. (source: wiki/sources/descriptions/gravemaulr__MLAntiCheat.md) Spigot/Paper/Folia **1.21.x** plugins such as [[guardac]] (PalassCQ; Kotlin; local gameplay monitoring with cloud API aim-check verdicts; alert-only mode; cross-server reputation; punishment ladders; Geyser Bedrock + WorldGuard exemptions; public client only) extend that lane with operator-controlled cloud-inference combat detection beside on-server ML stacks. (source: wiki/sources/descriptions/PalassCQ__GuardAC.md) Paper/Folia plugins such as [[shard]] (KaelusAI; Kotlin Gradle; PacketEvents packet analysis; player tick data to remote inference API for AI cheating checks; SQLite/MySQL/MariaDB + Redis cross-server alerts; monitoring, profiling, violation history, punishment rules, WorldGuard/Geyser integrations; free OSS; Anti Cheat / game:minecraft) extend that cloud-inference Java-server lane with tick-level AI detection beside aim-focused plugins such as [[guardac]]. (source: wiki/sources/descriptions/KaelusAI__Shard.md) Paper/Folia aim-focused plugins such as [[react]] (g4vrk; Java; GCD-error scoring, acceleration-delta tracking, mode-averaged rotation quantization; optional ML inference service; streak-based violation buffering with decay; async PacketEvents; staff alerts not auto-ban; PvP combat aim protection) extend that lane with local heuristic rotation analysis beside cloud-inference and on-server ML stacks. (source: wiki/sources/descriptions/g4vrk__React.md) Paper **1.21** context-aware plugins such as [[uagc]] (no1qq; UltimateAntiGamingChair; Java 21 Gradle; modular movement/combat/interaction/protocol checks—reach, speed, fast break, timer; confidence model weighing legitimate mechanics and server context; exemptions, permission bypass visibility, evidence history, alerts, auto/manual punishments, persistent freeze, trusted-plugin integration API; Anti Cheat / game:minecraft) extend that Java-server operator lane beside heuristic rotation plugins such as [[react]] and cloud-inference stacks such as [[guardac]]. (source: wiki/sources/descriptions/no1qq__UAGC.md) Paper/Spigot **1.8.9** plugins such as [[ycbr-anticheat]] (YcbrYL1; Java 8 Maven; ProtocolLib async→main packet pipeline; 19 combat/movement/protocol checks—KillAura, Reach, Scaffold, Speed, Fly, Velocity, Timer; optional Grim-style physics prediction; offline auth, temp bans, DDoS connection guard, strict-mode thresholds, admin GUI; Anti Cheat / game:minecraft) target legacy 1.8.9 network operators wanting integrated server-side protection. (source: wiki/sources/descriptions/YcbrYL1__YCBR-AntiCheat.md) Spigot/Paper **1.13+** plugins such as [[minecraft-anti-cheat]] (XuanXuan-ZhengGui; UltraAntiCheat; Java 17+ Maven; thirteen movement/combat/block/packet modules—fly, speed, timer, KillAura, reach, auto-clicker, scaffold, phase, velocity, no-slow, bad packets, ground spoof, xray; GCD-based rotation analysis; physics-based movement simulation with confidence scoring; optional ProtocolLib; bridges GrimAC/NoCheatPlus/Vulcan/Matrix/Spartan; browser web dashboard; Anti Cheat / game:minecraft) extend that Java-server operator lane for modern Paper networks. (source: wiki/sources/descriptions/XuanXuan-ZhengGui__Minecraft-Anti-Cheat.md) Paper/Purpur self-contained plugins such as [[antiguard]] (TheMille-Dev; Java; single drop-in JAR; physics-based fly/speed/reach/kill aura/auto-click/no-swing/no-fall/fast-break checks with research-backed low-FP thresholds; embedded SQLite storage or LuckPerms DB reuse; built-in web dashboard + REST API; legacy FastAPI reporting server + reference agent; Anti Cheat / game:minecraft) extend that lane for operators wanting lightweight on-server enforcement without external services. (source: wiki/sources/descriptions/TheMille-Dev__AntiGuard.md) Enterprise-oriented Spigot/Paper/Folia/Purpur Bukkit plugins such as [[windfall-anticheat]] (Java Maven; PacketEvents 2 packet intercept; dozens of configurable combat/movement/packet/inventory checks; lag compensation + movement prediction/simulation; adaptive per-player thresholds; Geyser/Bedrock awareness; public plugin API; Discord alerts + Prometheus metrics; single JAR across Spigot/Paper/Folia/Purpur) extend that Java-server operator lane. (source: wiki/sources/descriptions/enis1enis2__Windfall-AntiCheat.md) Open-source Bukkit/Spigot packet plugins such as [[arrow-anticheat]] (StelGR; Java; PacketEvents; combat—aim assist, autoclicker, kill aura, reach, velocity, hitbox—movement—fly, speed, motion, ground, illegal move—and misc—bad packets, scaffold, timer, inventory; statistical analysis + movement prediction; alerts, verbose mode, logging; Java + Bedrock; AGPLv3; Anti Cheat / game:minecraft) target smaller server operators beside enterprise stacks such as [[windfall-anticheat]]. (source: wiki/sources/descriptions/StelGR__ArrowAntiCheat.md) Fabric server-side mods such as [[windfall-anticheatf]] (Java **1.21.5+**; Fabric Loader/API + Mixins + Brigadier; packet-intercepted combat/movement/packet/inventory checks; vanilla physics prediction + latency compensation; adaptive thresholds + severity punishments; Discord webhooks + optional Prometheus; Geyser/Bedrock compatibility; one-to-one port of [[windfall-anticheat]]) extend that lane to Fabric multiplayer hosts. (source: wiki/sources/descriptions/enis1enis2__WindfallAntiCheatF.md) Fabric client-integrity mods such as [[seiun-ac]] (clementine44613; Java **1.21.11**; Fabric Loader + Mixins; custom client-server packets hash installed mods and resource packs against server whitelists/blacklists/gray lists on join; mid-session resource-pack change detection; kick/warn; Discord webhook alerts; in-game list reload commands; client-mod enforcement beyond gameplay packet checks; Anti Cheat / game:minecraft) complement packet-based Fabric AC such as [[windfall-anticheatf]]. (source: wiki/sources/descriptions/clementine44613__seiun-ac.md) Spigot/Paper/Purpur plugins such as [[cklsit-advanced-anticheat]] (cklsit; Java; **1.8.x–1.21.x**; fly/speed/KillAura/reach/scaffold/ESP checks + violation tracking + severity-based auto-bans; client-check workflow, player reports + admin notifications, bounty sandbox for detection probing; SQLite/H2/MySQL/MongoDB/Redis backends for Velocity/BungeeCord cross-server ban sync) extend that Java-server operator lane. (source: wiki/sources/descriptions/cklsit__AdvancedAntiCheat.md) DayZ server-side ML pipelines such as [[model-anti-cheat]] (mission-script per-second `DATA_LOG` telemetry—position, view direction, weapon state, raycast line-of-sight; Python feature extraction + RandomForest classifier; sample cheater sessions) extend that lane for aimbot/wallhack-style detection on community servers. (source: wiki/sources/descriptions/rafalimma__ModelAnti-Cheat.md) Client-side offensive references such as [[phantom-client]] (Lunar Client 1.8.9 internal DLL; JNI/JVMTI + OpenGL Present hook; evasion-oriented click timing and server-specific AC profiles) and MCP-based Java clients such as [[yuri]] (1.8.9 Gradle/MCP hack client; bundled Java 8 runtime + full assets; Watchdog/Polar/Grim bypass modules; pure-Java cheat architecture) and Fabric mod-loader clients such as [[lenrete-mod]] (Minecraft 26.2; combat/movement/render modules + packet Blinker; fail-soft Mixins; reference for reach/kill-aura/blink detection study), NeoForge/Fabric multi-loader clients such as [[epsilon]] (modular Mixins + event-bus hooks; packet manipulation + rotation systems; addon/Lua extensibility; Lumin/PrismRHI HUD; client-side bypass reference for AC developers; source: wiki/sources/descriptions/NekoyaHouse__Epsilon.md), fall-clutch automation mods such as [[omniclutch]] (1.21+; downward raycast impact detection; hotbar clutch-item selection; Gaussian reaction delays + camera interpolation for AC-aware clutch timing; movement-validation evasion study; source: wiki/sources/descriptions/WeiNaYongQ__OmniClutch.md), and protocol-level mineflayer bots such as [[eafe]] (Autonomous Elytra Flight Engine; vanilla elytra-physics FSM; cubic Bézier look-vector smoothing + Gaussian perturbation + slew-rate limits for movement-validation evasion) illustrate the bypass surface those Java-server plugins must detect. (source: wiki/sources/descriptions/inpeacedTeams__phantom-client.md) (source: wiki/sources/descriptions/unleg1t__Yuri.md) (source: wiki/sources/descriptions/lolizei__Lenrete-Mod.md) Passive client-side Forge **1.8.9** monitors such as [[local-anticheat-1-8-9]] (eleven packet-flow checks—AutoClicker, KillAura, Reach, Speed, Fly, Velocity, NoFall, Timer, FastPlace, FastBreak, Scaffold; monotonic timing + knockback analysis; local-chat flags only; evaluates local and remote players without server reports) give PvP players and researchers on-client cheat awareness where server AC is weak. (source: wiki/sources/descriptions/freezato__LocalAnticheat-1.8.9.md) Windows desktop Minecraft **screenshare** forensics such as [[jaranalyzer]] (Java + JNA; NTFS MFT-walk all drives for JARs; constant-pool blacklist scan without full decompile; obfuscated/encrypted archive heuristics; recycle-bin + running-Java process probes; nested JAR unpack to two levels; GUI/CLI text/JSON/HTML evidence export; Anti Cheat / game:minecraft) and consensual workflow stacks such as NotSkrib/[[error-pc-check]] (signed C#/.NET 8 client agent + React staff panel + Supabase; one-time keys; Prefetch/BAM/USN/registry/Minecraft signature collectors; correlation engine; severity-ranked human-review reports; Anti Cheat / game:minecraft screenshare) (source: wiki/sources/descriptions/NotSkrib__error-pc-check.md) complement server-side plugins with offline client artifact triage for staff screenshares. (source: wiki/sources/descriptions/winzysss__JarAnalyzer.md) Paper Minecraft server plugins such as [[antixrayviewer]] (RiseShieldDev; Java 21 Gradle; ore-breaking pattern detection—diamond, ancient debris; configurable threshold alerts; ~3-minute session capture of movement, look direction, block break/place; first-person replay with smooth camera interpolation; list/view/delete/manage commands; evidence-based X-ray investigation; Anti Cheat / game:minecraft) complement heuristic-only mining checks with recorded first-person review for server operators. (source: wiki/sources/descriptions/RiseShieldDev__AntiXrayViewer.md) Complementary **player-side innocence attestation** via [[alibi]] (Sutaigne; read-only PowerShell forensic kit; PC scan for cheat software/DMA artifacts/HWID spoofers + console-rig scan for capture-card stacks/vision aimbots/XIM·Cronus·ReaSnow; verdict-tier text/HTML reports; no install/telemetry; tournament-admin / Discord-mod / lobby-reviewer workflow) supports accused players producing auditable local evidence. (source: wiki/sources/descriptions/Sutaigne__alibi.md) Roblox Luau AC in the script-platform server-operator lane includes server-first [[shprotect-ac]] (Lua/Rojo; server enforcement with lightweight client heartbeat/watchdog; movement/teleport/fly/noclip/fling/infinite-jump + RemoteEvent rate limits; safe-position history; scoring/warnings/rollbacks/kicks via Config; client signals are monitoring-only) (source: wiki/sources/descriptions/sorrelhub__shprotect-ac.md) and client-server [[advanced-anticheat]] (server movement watchdog + client executor/GUI/ESP/FOV detection; remote handshakes, honeypots, ProfileStore persistence; flag or immediate-ban) (source: wiki/sources/descriptions/mastershadow547__Advanced-Anticheat.md), plus modular server-authoritative [[encryptic-roblox-anti-cheat]] (Luau; ServerScriptService drop-in; movement/teleport/fly/noclip/humanoid/physics/godmode/fire-rate/remote/combat guards; strike-based BanManager with whitelist/decay; remote/gun/melee/tool hooks; Studio demo test panel) (source: wiki/sources/descriptions/Longno242__Encryptic-Roblox-Anti-Cheat.md). Private-server behavioral risk and evidence-review platforms such as [[ponytail-risk]] (Rust risk agent + Node.js console; C ABI plugin SDK; read-only DB analysis, plugin events, asset provenance, rule scoring, AI-assisted investigation; default **shadow mode** defers bans/deductions/DB mutations to human review) target operators needing cheat/fraud case workflows without wiring scoring directly into automated enforcement. (source: wiki/sources/descriptions/xihedun-2026__Ponytail-Risk-.md) Self-hosted studio AC stacks such as [[mj-lnir]] (C++ security core + Rust agent; module/overlay/debugger/memory/hook/injection checks; HMAC IPC + optional HTTPS ingest; Rust control plane with kick/ban webhooks; default **observe-only**; optional Tauri dashboard) target Windows studios operating their own detection and enforcement workflows without a third-party cloud AC. (source: wiki/sources/descriptions/nulli83__Mj-lnir.md) Title-specific Palworld UE5 AC research such as [[palworld-anti-cheat]] (C#; shader / rendering / audio) sits in the Anti Cheat → game:palworld lane. (source: wiki/sources/descriptions/shalzuth__PalWorldAntiCheat.md) Palworld UE5 AC PoCs such as [[palanticheat-poc]] (g91; dumped SDK + `PropertyFixup.hpp` `UObject`/`UProperty` integrity checks for memory-tamper detection; Anti Cheat) extend that lane with SDK-level game-state validation. (source: wiki/sources/descriptions/g91__PalAntiCheat-poc.md) Unofficial Palworld dedicated-server binary patches such as [[palworld-server-unoffical-fix]] (VeroFess; memory-leak / CPU mitigation on older Linux/Windows builds; hash-verified patch apply scripts; server-operator stability fixes with early server-side AC experimentation; Server patch) sit in the adjacent Palworld server-operator lane beside [[docker-palworld-dedicated-server]] and [[palworld-server-modding]]. (source: wiki/sources/descriptions/VeroFess__PalWorld-Server-Unoffical-Fix.md) All-in-one Palworld dedicated-server ops consoles such as [[palopsweb]] (CoderYiXin; ASP.NET Core + Vue 3; PalDefender REST/RCON integration for whitelist, bans, version checks, and managed JSON config; native Palworld REST, lifecycle, save indexing, MapLibre maps, backups, webhooks, audit access control; same-host Windows deployment; Server / PalDefender anti-cheat integration) extend that lane with anti-cheat-aware server administration. (source: wiki/sources/descriptions/CoderYiXin__PalOpsWeb.md) Driver-side AC engineering can use user-space unit-test harnesses such as [[wdutf]] (Microsoft C++ unit tests against kernel-driver code). (source: wiki/sources/descriptions/wpdk__wdutf.md) Kernel dynamic-script prototyping via [[ntphp]] (PHP runtime embedded in WDK drivers; mrexodia; Anti Cheat → Dynamic Script) supports rapid AC/driver logic iteration without full rebuild cycles. (source: wiki/sources/descriptions/mrexodia__NtPhp.md) Quake III–style embeddable bytecode VM via [[q3vm]] (single-file `vm.c` interpreter + LCC `.qvm` compiler from C source; Anti Cheat → Dynamic Script) targets the same sandboxed detection-logic prototyping lane for AC engineers. (source: wiki/sources/descriptions/jnz__q3vm.md) AI-assisted AC/driver engineering workbench [[kernforge]] (Go CLI/agent; architecture indexing, security overlays, fuzz reasoning, evidence-backed verification plans, MCP skills, WDM/minifilter/registry-filter/WFP POC scaffolding) helps analyze and validate kernel game-security codebases. (source: wiki/sources/descriptions/kernullist__kernforge.md) Title-specific userspace emulators of kernel anti-tamper drivers such as [[holodori-kernel-bypass]] (holo-emu; fake `usrdrv017964.sys` protocol for Hololive Dreams on native/Wine/Proton without loading the real `.sys`) sit in the `Windows Emulator` / AC-driver analysis lane. (source: wiki/sources/descriptions/redecorate__Holodori-Kernel-Bypass.md) macOS CrossOver/Wine runtime patchers such as [[crossover-patcher]] (Apple Silicon; macOS 14+; version-bound patches to CrossOver Wine/graphics modules after signature/hash validation; separate patched install with rollback; AC-protected titles such as Wuthering Waves; leaves game/AC files and bottles untouched) complement [[are-we-anti-cheat-yet]] crowd-sourced GNU/Linux/Wine/Proton AC compatibility tracking on the macOS host lane. (source: wiki/sources/descriptions/AreWeAntiCheatYet__AreWeAntiCheatYet.md) (source: wiki/sources/descriptions/dazi2011__crossover-patcher.md) Static compatibility references such as [[aclist-github-io]] (HTML/CSS/JS site; conservative manual verification of anti-cheat-protected games on Linux; curated list plus companion-tool guides; Anti-cheat compatibility list) and crowd-sourced [[are-we-anti-cheat-yet]] (Next.js/JSON catalog; Linux AC readiness statuses; EAC/BattlEye listing; table/card/game pages + RSS; TypeScript/React/Mantine; Steam Deck reference) document that interoperability lane for gamers and researchers. (source: wiki/sources/descriptions/aclist__aclist.github.io.md) Official Valve [[proton]] (Wine-based Steam Play layer; build scripts, Docker infra, prefix config, Steam manifests, per-title fixups; upstream GNU/Linux runtime for anti-cheat interoperability study) complements those community compatibility lists. (source: wiki/sources/descriptions/ValveSoftware__Proton.md) Pre-launch PE import triage via [[runexe]] (CDJuaum; Python CLI; flags kernel AC clients such as [[easy-anti-cheat]] and [[battleye]] from imported DLL signatures; Wine compatibility assessment and prefix dependency provisioning for GNU/Linux game runs) offers static blocker detection before attempting protected Windows titles under Wine. (source: wiki/sources/descriptions/CDJuaum__RunEXE.md) Native Linux OSS AC such as [[tlac-modern-local-anti-cheat-reunioned]] (TuncorReUnion; Rust + C eBPF/kernel module + Python ONNX training; user-space signature scan, SHA256 self-integrity, HWID bans, Tokio local IPC; optional eBPF tracepoints; behavioral anomaly detection; MIT-licensed on-device enforcement; Steam Deck / Linux game security; Open Source Anti Cheat System) complements Wine/Proton compatibility tracking with Linux-native client protection. (source: wiki/sources/descriptions/TuncorReUnion__TLAC-MODERN-LOCAL-ANTI-CHEAT-REUNIONED.md) File-lock stress PoCs such as [[lockfile-poc]] (C++; Lock File) sit in the Anti Cheat → Stress Testing lane. (source: wiki/sources/descriptions/rbmm__LockFile-Poc.md) Kernel `MmCopyVirtualMemory` test drivers such as [[cheat-driver]] sit in the same stress-testing lane for studying own-KM cross-process R/W past usermode AC. (source: wiki/sources/descriptions/nkga__cheat-driver.md) Modular coverage-testing frameworks such as [[anti-cheat-testing-framework]] (C/C++; selective process memory R/W, DLL injection, overlay, input simulation, and driver-based kernel ops for detection gap analysis; Testing Framework) sit in the same AC evaluation / stress lane. (source: wiki/sources/descriptions/niemand-sec__AntiCheat-Testing-Framework.md) Universal integratable research kits such as [[quack]] (C++; modular client-side monitoring, game integration examples, docs, and companion red-team tooling for adversarial validation; experimentation-focused—not production deployment) extend that lane toward full-stack AC prototyping. (source: wiki/sources/descriptions/JonathanBerkeley__Quack.md) **Threats defended against:** usermode AC bypass via shatter-attack PoCs such as [[waryasswhe]] (0day shatter → any-AC claim; cheat / RPM research lane) (source: wiki/sources/descriptions/waryas__WaryasSWHE.md); injected code (stress/test harnesses such as [[injectors]] under Injection Testing; Rust DLL injectors such as [[rust-dll-crab]] (multiple methods; Injection Testing; gmh5225) (source: wiki/sources/descriptions/gmh5225__rust-dll-crab.md); large injection-testing corpora such as [[injection]] (many alternative Windows inject vectors; Injection Testing; gmh5225) (source: wiki/sources/descriptions/gmh5225__injection.md); SetWindowsHookExW injection PoCs such as [[setwindowshookex-injector]] (C/C++; hooking / modding; Injection Testing; gmh5225) (source: wiki/sources/descriptions/gmh5225__SetWindowsHookEx-Injector.md); Skengdo [[simple-setwindowshookexw-injector]] (C++; PE parsing + registry helpers + optional cert spoofing; window-class targeting; Injection Testing:SetWindowsHookExW) (source: wiki/sources/descriptions/Skengdo__simple-SetWindowsHookExW-injector.md); MMF User APC + file-mapping injection PoCs such as [[mmf-code-injection]] (shared file mapping into target VA; stealthy DLL load; User APC + File Mapping Testing; gmh5225) (source: wiki/sources/descriptions/gmh5225__MMFCodeInjection.md); broader technique catalogs such as [[windows-process-injection]] — shellcode / syscalls / module stomping / thread-pool·fiber / PPID + stack spoof; multi-technique injection + persistence labs such as [[process-injection-techniques]] (MahmoudZohdy; hollowing/doppelganging/ghosting + IFEO/AppInit_DLLs/AppCertDlls; unified CLI; defensive detection testing; Injection Testing) (source: wiki/sources/descriptions/MahmoudZohdy__Process-Injection-Techniques.md); C# unified CLI inject toolkit [[process-injection]] (3xpl01tc0d3r; vanilla/DLL/hollowing/APC queue/KernelCallbackTable; P/Invoke/D/Invoke/syscalls; shellcode formats, encryption, PPID spoof; detection-engineering validation; Various process injection techniques) (source: wiki/sources/descriptions/3xpl01tc0d3r__ProcessInjection.md); host-based inject technique catalogs such as [[code-injection]] (Fahersto; ~two dozen PE/DLL/shellcode paths incl. hollowing, callbacks, loader abuse; per-technique builds; WoW64/multi-version notes; detection coverage lab) (source: wiki/sources/descriptions/Fahersto__code_injection.md); process-cloning PoCs such as [[process-cloning]] — `NtCreateProcessEx` parent-handle snapshot inheriting target VA space (hollowing / memory analysis / credential dump without direct target access) (source: wiki/sources/descriptions/huntandhackett__process-cloning.md); TpAllocInject loaders with Tartarus' Gate indirect syscalls such as [[tartarus-tp-alloc-inject]]; thread-pool injection corpora such as [[poolparty]] (SafeBreach-Labs; worker-factory overwrite + TP_* queue variants; handle hijacking; red-team / EDR visibility testing; ThreadPool) (source: wiki/sources/descriptions/SafeBreach-Labs__PoolParty.md); NtCreateThreadEx + runtime LdrLoadDll-resolving PIC shellcode injectors such as [[the-perfect-injector]] (can1357; avoids fixed LoadLibrary; WoW64; anti-cheat evasion research) (source: wiki/sources/descriptions/can1357__ThePerfectInjector.md); PE import-table shellcode staging such as [[hintinject]] — splits payload into fabricated Import Directory Hint/Name Table chunks; reconstructs via loader IAT resolution (Hint/Name Table; frkngksl) (source: wiki/sources/descriptions/frkngksl__HintInject.md); user-mode PE manual-map samples such as [[modexmap]] — VirtualAllocEx/WPM + import/reloc/TLS + CreateRemoteThread entry stub; minimal embedded-byte-array manual-map samples such as [[memject]] — danielkrupinski; embeds compiled DLL as raw bytes; user-mode PE map into csgo.exe; optional header/entry erase after `DllMain` (Manual Map) (source: wiki/sources/descriptions/danielkrupinski__MemJect.md); UI manual-map injectors such as [[shtreeba]] — MMap PE copy/reloc/import without LoadLibrary; anti-detection manual-map loaders such as [[wizard-loader]] — section/import/reloc/TLS/VEH mapping + PE header erasure + thread hiding; Xwizard.exe side-load (gmh5225); stealth manual-map injectors such as [[manual-mapping-dll-injector]] (andrew9382; header wipe/fake, PEB unlink, DLL name scramble, handle-hijack process access; thread hijack / NtCreateThreadEx; Manual Map; anti-detection injection study) (source: wiki/sources/descriptions/andrew9382__manual_mapping_dll_injector.md); kernel VAD/PTE concealment injectors such as [[kernel-vad-injector]] — unsigned-driver manual map; `MiAllocateVad`/`MiInsertVad` + post-map VAD removal to evade `NtQueryVirtualMemory` / VAD walks (gmh5225; Hide VAD) (source: wiki/sources/descriptions/gmh5225__Kernel-VAD-Injector.md); Qt GUI multi-method injectors such as [[guided-hacking-injector]] — LoadLibrary/manual map/thread hijack/NtCreateThreadEx/APC/vulnerable-driver KM paths + DLL cloaking (PEB unlink, header erase, TLS, VEH; Injection Testing); C++ inject library [[gh-injector-library]] (Broihon; multi-strategy Ldr/manual-map load + APC/thread-hijack/SetWindowsHookEx/kernel-callback execution; cloaking + .NET assembly load; inject library and tool; AC injection-behavior research) (source: wiki/sources/descriptions/Broihon__GH-Injector-Library.md); managed C# injectors such as [[nativenetsharp]] — Injecting C# code; cheat / guide; runtime JS injectors such as [[positron]] — manual-map + QuickJS/Electron scripting, named-pipe IPC, self-unmap/REPL; **`AppInit_DLLs` startup inject + MinHook** frameworks such as [[appinithook]] — dispatcher DLL + INI per-process module load; exported API / entry-point hooks) (source: wiki/sources/descriptions/toneillcodes__windows-process-injection.md) (source: wiki/sources/descriptions/mrexodia__AppInitHook.md) (source: wiki/sources/descriptions/nettitude__Tartarus-TpAllocInject.md) (source: wiki/sources/descriptions/weak1337__ModExMap.md) (source: wiki/sources/descriptions/mdilai__Shtreeba.md) (source: wiki/sources/descriptions/guided-hacking__GuidedHacking-Injector.md) (source: wiki/sources/descriptions/shalzuth__NativeNetSharp.md) (source: wiki/sources/descriptions/qiufuyu123__Positron.md); kernel APC DLL injectors such as [[injdrv]] (process-create notify → user APC → `LdrLoadDll`; bypasses many UM inject hooks) (source: wiki/sources/descriptions/wbenny__injdrv.md); map + APC kernel inject samples such as [[kinject]] (cheat / injection:windows) (source: wiki/sources/descriptions/w1u0u1__kinject.md); system-wide kernel DLL inject + function-hook drivers such as [[kptnhook]] (every process from early boot; cheat / injection:windows) (source: wiki/sources/descriptions/sum-catnip__kptnhook.md); NTDLL-only Detours ports such as [[detoursnt]] (unmodified Detours; no Win32 deps; hook/trampoline research) (source: wiki/sources/descriptions/wbenny__DetoursNT.md); leaked internal Fortnite cheat samples such as [[fortnite-cheat-leak]] (Waihbe; C++; MinHook + Detours gameplay hooks; no-spread / movement / vehicle / teleport modules; rendering + utility layers; cheat architecture + inline-hook detection-surface RE; cheat / game:fortnite [Internal]) illustrate the offensive hook stack [[easy-anti-cheat]] must reason about on UE clients (source: wiki/sources/descriptions/Waihbe__Fortnite-Cheat-LEAK.md); external Fortnite overlay cheats such as [[interic-fortnite-external-cheat]] (Saxmason; driver-assisted RPM; DX9 ImGui overlay; visibility-aware ESP + hitbox aimbot; KeyAuth + anti-debug/anti-dump/string obfuscation; cheat / game:fortnite [External]) and [[subzero-fortnite-cheat]] (Saxmason; kernel-driver RPM; DX9 ImGui overlay; mesh visibility aimbot; NtUserSendInput + call-stack/library spoofing + XOR obfuscation; cheat / game:fortnite [External]) and leaked hybrid UM+KM samples such as [[godfather-fortnite-cheat-cracked]] (CheaterRehab; C++ DX9 ImGui overlay + kernel driver with callback comm; loader/mapper deployment + detection-status notes; pasted-cheat infrastructure RE; cheat / game:fortnite [External]) illustrate the out-of-process memory + input-evasion stack beside injected internals (source: wiki/sources/descriptions/Saxmason__Interic-Fortnite-External-Cheat.md; wiki/sources/descriptions/Saxmason__Subzero-Fortnite-Cheat.md; wiki/sources/descriptions/CheaterRehab__GodFather-Fortnite-Cheat-Cracked.md); lightweight external Fortnite learning samples such as [[keyzpon-thefluxxx-fortnite-external]] (KeyzpOnTheFluxxx; C++ Visual Studio; offset updates + external process interaction; typical external cheat structure; anti-cheat interaction analysis; cheat / game:fortnite [External]) extend that external lane with a minimal learning scaffold (source: wiki/sources/descriptions/KeyzpOnTheFluxxx__Fortnite-External.md); internal Fortnite cheat bases such as [[keyzp1337-fortnite]] (Keyzp1337; C++ x64 Visual Studio; ESP/aimbot/no recoil + ImGui menu; BYO injection path; offset-dependent UE integration; cheat development + client internals RE; cheat / game:fortnite [Internal]) illustrate the in-process hook/overlay stack [[easy-anti-cheat]] must reason about beside leaked hook samples (source: wiki/sources/descriptions/Keyzp1337__Fortnite.md); modular Detours AC-bypass frameworks such as [[generic-game-detour-api-hook]] (~130 syscalls across 16 hook modules; dinput8.dll proxy; hide/spoof/integrity-bypass + caller-check vs AC modules; NGS/BlackCipher/HackShield/XignCode/GameGuard/TenProtect; cheat / hook research) (source: wiki/sources/descriptions/wesjian__GenericGameDetourAPIHook.md); original x86/x64 PolyHook ([[polyhook]]; C++11 multi-method interface) and C++ PolyHook2 (vcpkg) such as [[polyhook-2-0]] for multi-method hook/trampoline research (source: wiki/sources/descriptions/stevemk14ebr__PolyHook.md) (source: wiki/sources/descriptions/stevemk14ebr__PolyHook_2_0.md); Rust x86 HOOK crates such as [[ilhook-rs]] (function-call intercept → user handlers) (source: wiki/sources/descriptions/regomne__ilhook-rs.md); Windows shellcode build frameworks such as [[scfw]] (cross-platform C++; shellcode engine & tricks lane) (source: wiki/sources/descriptions/wbenny__scfw.md); bad-byte banishment for constrained shellcode encodings such as [[byvalver]] (two usage modes; preserves functionality) (source: wiki/sources/descriptions/umpolungfish__byvalver.md); C++ shellcode factory tooling such as [[shellcode-factory]] (shellcode engine & tricks lane) (source: wiki/sources/descriptions/lainswork__shellcode-factory.md); polymorphic x86/x64 shellcode encoder such as [[shoggoth]] (asmjit JIT; dual encryption layers + randomized decoder stubs; COFF/PE reflective loaders; Polymorphic Encryptor) (source: wiki/sources/descriptions/frkngksl__Shoggoth.md); reflective PE loader + payload generators such as [[amber]] (EgeBalci; Go tooling + ASM loader; EXE/DLL/SYS in-memory execution; encoding, API obfuscation, staged delivery, memory cleanup; offensive + defensive reflective-loading research) (source: wiki/sources/descriptions/EgeBalci__amber.md); Cobalt Strike Beacon reflective loaders such as [[kayn-strike]] (Cracked5pider; thread start-address spoof + loader memory cleanup after beacon entry; C + ASM + Aggressor script; stageless payload builds; in-memory execution / detection-evasion research) (source: wiki/sources/descriptions/Cracked5pider__KaynStrike.md); PE infection / parasitic shellcode loaders such as [[super-mega]] (Cordyceps technique; carrier shellcode integrated into legitimate EXE/DLL; web UI for payloads, anti-emulation, targets; static-analysis evasion; dobin) (source: wiki/sources/descriptions/dobin__SuperMega.md); PE patching/infection framework such as [[peinjector]] (C PE parse/modify core; Python/Java control; multiple infection methods; transfer-time patch generation; web remote config; preserves original behavior; executable research / red-team / PE-tampering defense study; JonDoNym) (source: wiki/sources/descriptions/JonDoNym__peinjector.md); object-to-shellcode generation framework such as [[obj2shellcode]] (C/C++; modding / memory analysis / debugging; shellcode engine & tricks lane) (source: wiki/sources/descriptions/jseclab__obj2shellcode.md); minimal PIC C shellcode micro-framework such as [[tabby]] (cocomelonc; PEB/EAT + FNV-1a API hashing; indirect NT syscalls via ntdll gadgets; Linux mingw-w64/nasm → flat `.bin`; shellcode engine & tricks / teaching lane) (source: wiki/sources/descriptions/cocomelonc__tabby.md); Rust no_std dynamic WinAPI library such as [[rs-ldr]] (alfarom256; salted djb2 PEB/EAT resolution without import table or cleartext API strings; XOR compile-time strings; pluggable syscall SSN resolver; stealth loader / game-security research) (source: wiki/sources/descriptions/alfarom256__rs-ldr.md); modular malware-behavior emulator such as [[peekaboo]] (cocomelonc; safe C2/persistence/lateral-movement emulation; Python CLI/TUI/Flask + C/C++ injection modules; MITRE ATT&CK + Malpedia + Sigma/YARA + VirusTotal dashboard; purple-team / detection-engineering lane) (source: wiki/sources/descriptions/cocomelonc__peekaboo.md); Windows shellcode injection toolkit samples such as [[jektor]] (five execution vectors; GetProcAddress dynamic resolve; XOR-encrypted payloads + NOP sled; Injection/Shellcode Testing; gavz) (source: wiki/sources/descriptions/gavz__Jektor.md); stealthy HTTP-staged shellcode loaders such as [[lucky-spark]] (fiber + JIT decrypt + WinHTTP staging + PEB-walk resolve; Schich; cheat / shellcode loader) (source: wiki/sources/descriptions/Schich__Lucky-Spark.md); callback-API shellcode execution corpora such as [[alternative-shellcode-exec]] (aahmad097; many Visual Studio PoCs; position-independent shellcode without CreateThread; user-mode evasion / Detection:Shellcode study) (source: wiki/sources/descriptions/aahmad097__AlternativeShellcodeExec.md); multi-language shellcode execution corpora such as [[flavortown]] (Wra7h; C/C#/MATLAB; process and memory execution paths; evasion tradecraft for Detection:Shellcode study) (source: wiki/sources/descriptions/Wra7h__FlavorTown.md); Debug API + hardware-breakpoint shellcode injectors such as [[dbgnexum]] (dis0rder0x00; attaches as debugger; file-mapping payload transfer; orchestrates in-target API chain via thread-context manipulation without WPM/RPM/VirtualAllocEx; EDR-evasion research) (source: wiki/sources/descriptions/dis0rder0x00__DbgNexum.md); process-fork reflection injectors such as [[dirty-vanity]] (deepinstinct; `RtlCreateProcessReflection` clone; shellcode written in parent inherited by fork; redirect fork start address; avoids WPM; fork-based EDR-evasion research) (source: wiki/sources/descriptions/deepinstinct__Dirty-Vanity.md); DLL search-order / sideload / phantom-DLL catalogs such as [[windows-dll-hijacking]] and disclosed-opportunity DBs such as [[hijacklibs]] for image-load attack-surface mapping (source: wiki/sources/descriptions/wietze__windows-dll-hijacking.md) (source: wiki/sources/descriptions/wietze__HijackLibs.md); automated search-order discovery via [[dllirant]] (proxy DLL generation + candidate-dir placement) (source: wiki/sources/descriptions/redteamsocietegenerale__DLLirant.md); Sh0ckFR/DLLirant is a historical list placeholder without implementation (source: wiki/sources/descriptions/Sh0ckFR__DLLirant.md); automated DLL hijack workflow tooling such as [[impulsive-dll-hijack]] (source: wiki/sources/descriptions/knight0x07__ImpulsiveDLLHijack.md); proxy-DLL hijack scaffolding such as [[super-dll-hijack]] (anhkgg; export passthrough without manual signature recreation; load-path abuse research) (source: wiki/sources/descriptions/anhkgg__SuperDllHijack.md); enterprise DLL-hijack vulnerability scanners such as [[dllspy]] (CyberArk; missing-dependency / writable-path / unsafe search-order audit reports) (source: wiki/sources/descriptions/cyberark__DLLSpy.md); DLL hijack surface scanners such as [[dllhsc]] (ctxis; load-path / sideload research tooling) (source: wiki/sources/descriptions/ctxis__DLLHSC.md); platform-bypass launchers such as [[mini-launcher]] (Steam API stubs / SteamAppID + DLL/Lua inject without the full client) (source: wiki/sources/descriptions/xan105__Mini-Launcher.md); launcher handle abuse for covert external RPM such as [[launcher-abuser]] (Ricardonacif; hijack Steam/Battle.net game handles via injected launcher shellcode + shared-memory IPC; avoids new cross-process handles; low-footprint interaction / AC evasion tradeoff study) (source: wiki/sources/descriptions/Ricardonacif__launcher-abuser.md); covert Windows socket telemetry evasion via stolen browser handles such as [[idov31-venom]] (Idov31; single-header C++; hidden detached browser + Winsock handle discovery/duplication; networking evasion research) (source: wiki/sources/descriptions/Idov31__Venom.md); ImGui cheat loaders with anti-debug such as [[a-pasted-rust-script]] (Rust/C++; feature modules) for studying offensive anti-debug in loader UX (source: wiki/sources/descriptions/spyder1g__a-pasted-rust-script.md); commercial-style cheat loaders with auth/HWID/license gating such as [[cyber-ant-loader]] (gmh5225; managed injection pipeline; HWID binding + license verification + anti-detection for AC-protected titles) (source: wiki/sources/descriptions/gmh5225__CyberAntLoader.md); CS:GO-focused C++ loaders with PHP auth backends such as [[csgo-loader]] (gmh5225; HWID check + time-based license validation + web panel for injected cheat DLL access; cheat / game:csgo `[Loader]`) (source: wiki/sources/descriptions/gmh5225__CSGO-Loader.md); CS:GO XenForo-backed P2C loaders such as [[csgo-xenforo-loader]] (flowxrc; forum subscription + license verification before DLL delivery/injection; cheat-distribution / loader-auth research) (source: wiki/sources/descriptions/flowxrc__csgo-xenforo-loader.md); CS:GO remote-download inject loaders with anti-detection tradecraft such as [[cozinha-loader]] (b1scoito; process hollowing or manual map; remote module fetch; anti-debug + string encryption + import obfuscation vs AC scanning; cheat / game:csgo `[Injector]`) (source: wiki/sources/descriptions/b1scoito__cozinha_loader.md); win32k syscall kernel exploits such as [[angryorchard]] (gmh5225; **NtUserHardErrorControl** → KernelMode thread elevation + arbitrary kernel R/W without BYOVD; Some Tricks / win32k) (source: wiki/sources/descriptions/gmh5225__ANGRYORCHARD.md); [[byovd]], hypervisor abuse (stress/test refs such as [[vt-debuuger]]; AMD SVM / Rust hacked-hypervisor testing such as [[baresvm]]; AMD SVM hacked-hypervisor feature walkthroughs such as [[aether-visor]] (gmh5225; implementation-focused; `Detection: Hacked Hypervisor Testing AMD`) (source: wiki/sources/descriptions/gmh5225__AetherVisor.md); AMD SVM Type-1 stealth-debug / process-hide stacks such as [[powervm]] (NPT hooks, CPUID hypercall reads, invisible DebugPort; VMProtect/ACE inspection via customized Cheat Engine) (source: wiki/sources/descriptions/not1cyyy__PowerVM.md); minimal VT-x Type-2 learning stacks such as [[hv]]; stealth Type-2 stacks such as [[ophion]] with CPUID cache / CR4.VMXE hide / TSC compensation under hacked-hypervisor detection; educational Intel VT-x UEFI+Windows research HV such as [[minivisorpkg]] (pre-OS inspect + WinDbg-debuggable driver); user-mode detection probes such as [[checkhv-um]] via CPUID / RDTSC / VMCS artifacts / signature match; offensive KVM RDTSC handler patches such as [[rdtsc-kvm-handler]] (WCharacter; Linux kernel C; Intel VMX + AMD SVM guest timestamp intercept; fake delta tuning + QEMU RDTSCP disable; timing-based AC / VM-evasion research); VM-exit timing compensation patches such as [[better-timing]] (SamuelTulach; Linux KVM patch; records VM-exit timing + guest TSC offset; bypass CPU timing / anti-VM checks; cheat / Bypass CPU Timing) (source: wiki/sources/descriptions/SamuelTulach__BetterTiming.md) stress the same Detection:Virtual Environments / hacked-hypervisor timing surface; APIC-based interrupt / timing research such as [[apic]] (xAPIC/x2APIC IPI send; LAPIC register access for monitoring or evasion study) (source: wiki/sources/descriptions/noahware__apic.md); multi-technique C++ detectors such as [[hypervisor-detection]] under the same hacked-hypervisor lane; IDT SIDT/LIDT probes such as [[hv-detect]] (gmh5225; run detections in controlled IDT context then restore; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/gmh5225__hv-detect.md); Go Hyper-V VM environment probes such as [[go-detection-hyper-v]] (CPUID feature checks, timing, hypervisor presence; `[Hyper-v]`; gmh5225) (source: wiki/sources/descriptions/gmh5225__Go-Detection-Hyper-v.md); kernel-mode KPCR/KPRCB Hyper-V guest probes such as [[detection-hyper-v]] (gmh5225; Win10 17763; `PowerState.Hypervisor` / `HvTargetState`; build-specific kernel structure check; `[Hyper-v]`) (source: wiki/sources/descriptions/gmh5225__Detection-Hyper-v.md); ring-0 multi-heuristic hypervisor test driver such as [[detect-hypervisor-detect-ring-0]] (gmh5225; CPUID hypervisor bit + leaf comparisons, TSC/APERF/MPERF VM-exit timing, Intel LBR/DEBUGCTL consistency; manual-map driver prints each check from DriverEntry; Secret Club research lineage; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/gmh5225__Detect-Hypervisor_detect_ring_0.md); Hyper-V hacking framework such as [[voyager]] (backengineering upstream; Win10 x64 AMD & Intel; offensive Hyper-V research; cheat / kernel explorer) (source: wiki/sources/descriptions/backengineering__Voyager.md); UEFI boot-stage Voyager fork [[modded-voyager]] (NurdAlert; pre-OS hypervisor + `bootmgfw`/`winload` hooks; Hyper-V path patches; `Detection: Hacked Hypervisor` / boot-time AC bypass research) (source: wiki/sources/descriptions/NurdAlert__modded-voyager.md); NMI callback kernel driver research such as [[nmi-callback]] (C/C++; Detection: Hacked Hypervisor) (source: wiki/sources/descriptions/helloobaby__Nmi-Callback.md); NMI disable PoCs such as [[nmi-callback-blocker2]] (C++; disable NMI; cheat / windows kernel explorer; gmh5225) (source: wiki/sources/descriptions/gmh5225__NMICallbackBlocker2.md); [[disable-nmi-callbacks]] (KiNmiInterruptStart pattern scan + affinity/NMI-state patch vs NMI stack-walk detections; gmh5225) (source: wiki/sources/descriptions/gmh5225__Disable-nmi-callbacks.md); [[nmi]] (ekknod; C/C++; block NMI interrupts; cheat / windows kernel explorer) (source: wiki/sources/descriptions/ekknod__Nmi.md); NMI register/trigger PoCs such as [[nmi-nmi-callback]] (C/C++; register/use NMI callbacks + cross-CPU context inspection; BattlEye-style hidden-thread detection study; cheat / windows kernel explorer; gmh5225) (source: wiki/sources/descriptions/gmh5225__NMI-nmi_callback.md); NMI enumeration PoCs such as [[nmi-enum-nmi-callback]] (C/C++; enumerate registered NMI callbacks; cheat / windows kernel explorer; gmh5225) (source: wiki/sources/descriptions/gmh5225__NMI-EnumNmiCallback.md); hypervisor VM-detection benchmarking such as [[nohv]] (C/C++ kernel driver; benchmark custom HV against common vm-detections; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/jonomango__nohv.md); user-mode EPT hook detection such as [[ept-hook-detection]] — timing latency, write-and-compare on code pages, cross-thread core consistency (`Detect EPT`) (source: wiki/sources/descriptions/momo5502__ept-hook-detection.md); novel EPT/NPT hook probes such as [[bloodhound]] (Skeletal-Group; C++ user-mode PoC; vectored exception handling + CPU intrinsics + VPGATHER accessibility checks for hypervisor page-state manipulation; executable/readable transition detection; anti-cheat / virtualization security research; Various novel EPT/NPT hook detection mechanisms) (source: wiki/sources/descriptions/Skeletal-Group__Bloodhound.md); REP MOV / ERMSB side-channel EPT probes such as [[ermsb-meme]] (everdox; C; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/everdox__ermsb-meme.md); REP MOVS fault-vs-uninterrupted EPT PoC such as [[rep-mov-ept-detecc]] (JustasMasiulis; Windows C++; overwrite-pattern signal + exception handling; `REP MOV based EPT detection`) (source: wiki/sources/descriptions/JustasMasiulis__rep_mov_ept_detecc.md); STR-exit VMM fault probes such as [[vmdtstr]] (cryotb; nested HVPP test harness; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/cryotb__VmdtStr.md); broad x86-64 HV/VMM detection collection such as [[hvdetecc]] (can1357; processor/PMC/TLB/timing/MSR/interrupt tests; Intel VMX + AMD SVM; Type-1 via SMBIOS/ACPI/PCI; `Detection: Hacked Hypervisor`) (source: wiki/sources/descriptions/can1357__hvdetecc.md); experimental EPT hooking stacks such as [[hypervisor]] (Intel VT-x Type-2; stealth kernel memory hooks via second-level address translation; EPT page hooks + violation watchpoints; integrity-check bypass research) (source: wiki/sources/descriptions/momo5502__hypervisor.md)), hidden/anti-detect PVE/QEMU/VMware guests (e.g. [[proxmox-ve-anti-detection]], [[qemu-anti-detection]], [[qemu-patched]], [[hardened-qemu]] multi-hypervisor artifact masking, [[hypervisor-phantom]] Bash-automated anti-detection VM lab setup (QEMU/EDK2/kernel/VFIO), [[kvm-performance]] host-side ioapic/MSR/split-lock troubleshooting for AC/game VMs on Unraid/Proxmox, [[vmware-hardened-loader]] under virtual-environment detection); Cuckoo sandbox detection demos such as [[anticuckoo]] (`Detection:Virtual Environments`; crash PoCs are demonstration-only) (source: wiki/sources/descriptions/therealdreg__anticuckoo.md); open-source anti-analysis environment tester [[pafish]] (C; modular VM/sandbox/debugger/hook checks; VMware/VirtualBox/QEMU/Wine; reproducible analysis-environment evaluation; a0rtega) (source: wiki/sources/descriptions/a0rtega__pafish.md); compact embeddable VM fingerprinting [[compact-vm-detector]] (LukeGoule; C++; [[pafish]]-derived lightweight anti-virtualization checks; Visual C++ drop-in; minimal footprint; quick environment fingerprinting for security tooling; Detection:Virtual Environments) (source: wiki/sources/descriptions/LukeGoule__compact_vm_detector.md); Windows C++ anti-analysis test suite [[al-khaser]] (LordNoteworthy; CLI-driven anti-debug/anti-VM/anti-dump/anti-disassembly/timing checks; VirtualBox/VMware/QEMU/Wine coverage; validates sandbox/EDR/anti-malware visibility against real-world evasion; Detection lane) (source: wiki/sources/descriptions/LordNoteworthy__al-khaser.md); ML-assisted VM-detection shellcode loader [[t-1]] (0xTriboulet; C++; scikit-learn decision-tree rules exported to native C++; shellcode vs self-removal branch on sandbox/VM detection; Detection / loader research lane) (source: wiki/sources/descriptions/0xTriboulet__T-1.md); Any.Run-style sandbox fingerprint PoC [[anti-sandbox]] (SaadAhla; C++; host artifact checks—folders, processes, user-profile heuristics, services/drivers; multi-indicator match before flagging; sandbox-evasion / malware-analysis research; Detecting AnyRun sandbox) (source: wiki/sources/descriptions/SaadAhla__Anti-Sandbox.md); Windows Sandbox fingerprint library [[wsb-detect]] (LloydLabs; C library + sample; modular sandbox-process/username/device-path/DNS-suffix/registry/timing checks; combinable by false-positive tolerance; anti-analysis / environment-awareness research; Windows Sandbox ("WSB")) (source: wiki/sources/descriptions/LloydLabs__wsb-detect.md); CAPE/Cuckoo dynamic-analysis host provisioning via [[tools]] (doomedraven; KVM/QEMU setup, Windows guest config, Volatility3 plugins; sandbox lab infrastructure) supports the analysis side of that VE lane (source: wiki/sources/descriptions/doomedraven__Tools.md); curated anti-virtualization resource list [[awesome-anti-virtualization]] (source: wiki/sources/descriptions/theo-abel__awesome-anti-virtualization.md); cross-platform header-only VM detection library [[vmaware]] (100+ techniques; CPUID leaves, registry/FS/MAC artifacts, timing side channels, hardware fingerprints, driver signatures; VMware/VirtualBox/Hyper-V/QEMU-KVM; confidence scores; `Detection:Virtual Environments`) (source: wiki/sources/descriptions/kernelwernel__VMAware.md); Linux/Android container·VM probes such as [[conbeerlib]] (cgroup / fs / env / hardware; Docker/LXC/K8s/WSL) (source: wiki/sources/descriptions/su-vikas__conbeerlib.md); Android emulator artifact heuristics such as [[anti-emulator]] (QEMU props / fingerprints / sensors / FS; Java per-check API) (source: wiki/sources/descriptions/strazzere__anti-emulator.md) and Multi-heuristic Android emulator detection such as [[android-emulator-detection]] (gmh5225 Java/Kotlin scoring library; reveny Java/C++ plugin fork) (source: wiki/sources/descriptions/gmh5225__Android-Emulator-Detection.md) (source: wiki/sources/descriptions/reveny__Android-Emulator-Detection.md), [[dma]] AC detection pipeline (PCIe fingerprinting, [[iommu]] containment, TPM attestation), AI visual cheats with hardware input (see [[ai-aimbot-detection]]) (e.g. title-specific YOLO automation such as [[maplestory-worlds-automation]] for MapleStory Worlds / Artale) (source: wiki/sources/descriptions/tingwei1111__maplestory-worlds-automation.md); title-specific TypeScript automation scripts such as [[genshin-impact-script]] (cheat / game:genshin impact) (source: wiki/sources/descriptions/phonowell__genshin-impact-script.md); experimental Genshin AC circumvention such as [[mhynot2]] (research bypass of kernel-driver enforcement; khang06) (source: wiki/sources/descriptions/khang06__mhynot2.md); EasyPeasy / `mhyprot2` bypass samples such as [[genshin-easy-peasy-bypass]] (gmh5225; disables/circumvents `mhyprot2.sys` integrity checks; modified client execution; Anti-Debug Bypass / game:genshin impact) (source: wiki/sources/descriptions/gmh5225__Genshin-EasyPeasy-Bypass.md); in-process Unity IL2CPP/memory gameplay cheats such as [[genshin-cheat]] (gmh5225; god mode / stamina / teleport / speed; must evade miHoYo client AC) (source: wiki/sources/descriptions/gmh5225__genshin-cheat.md); Honkai: Star Rail screen-recognition daily automation such as [[starrailcopilot]] (Python; menu navigation / daily missions / stamina / assignments; no injection; cheat / game:honkai star rail `[Script]`) illustrates out-of-process visual-bot threats beside HoYoverse in-process samples (source: wiki/sources/descriptions/gmh5225__StarRailCopilot.md); anti-cheat-safe UE5 companions such as [[lanternlight]] (Remus3; Python; Mistfall Hunter; game log + UE5 GVAS save parse + passive screen capture; Emberforge build math with provenance/redaction; no injection/RPM/network/asset extraction; build planning + session analysis on kernel-AC titles) contrast that lane with zero-memory out-of-process analysis (source: wiki/sources/descriptions/Remus3__Lanternlight.md); simple Unity in-process hook cheats such as [[starrail-s-gc]] (C/C++; cheat / game:honkai star rail) illustrate the in-guest hooking lane for the same title (source: wiki/sources/descriptions/gmh5225__StarRail-S-GC.md); title-specific Tencent ACE kernel-driver RE such as [[starrail-ace-b]] (gmh5225; protection mechanisms, detection techniques, bypass methods, integrity checks, monitoring for Honkai: Star Rail; explore anticheat) documents the HoYoverse PC ACE stack beside those offensive samples (source: wiki/sources/descriptions/gmh5225__StarRail-ACE-B.md); Honkai Impact 3rd ACE bypass tooling such as [[hi3-ace-b]] (gmh5225; circumvents integrity checks and detection for modified clients / third-party tools; explore anticheat) extends the same HoYoverse ACE lane (source: wiki/sources/descriptions/gmh5225__HI3-ACE-B.md). (source: wiki/sources/descriptions/zoand__Injectors.md) (source: wiki/sources/descriptions/zxd1994__vt-debuuger.md) (source: wiki/sources/descriptions/valium007__BareSVM.md) (source: wiki/sources/descriptions/gmh5225__AetherVisor.md) (source: wiki/sources/descriptions/zer0condition__hv.md) (source: wiki/sources/descriptions/zer0condition__Ophion.md) (source: wiki/sources/descriptions/tandasat__MiniVisorPkg.md) (source: wiki/sources/descriptions/zer0condition__checkhv_um.md) (source: wiki/sources/descriptions/void-stack__Hypervisor-Detection.md) (source: wiki/sources/descriptions/zhaodice__proxmox-ve-anti-detection.md) (source: wiki/sources/descriptions/zhaodice__qemu-anti-detection.md) (source: wiki/sources/descriptions/kila58__qemu-patched.md) (source: wiki/sources/descriptions/batusan__Hardened-qemu.md) (source: wiki/sources/descriptions/SingularityCloud__KVM.Performance.md) (source: wiki/sources/descriptions/hzqst__VmwareHardenedLoader.md) **Platform trust:** DSE, [[patchguard]], [[hvci]]/VBS, Secure Boot; VBS enclave trusted-execution samples such as [[secure-game]] (SamuelTulach; core game logic in Windows VBS enclave; host/enclave split; SDL2; anti-cheat and trusted execution research) illustrate client-side logic isolation within the platform-trust stack; user-space Discord DPI relay such as [[discord-dpi-bridge]] (egeorcun; ByeDPI SOCKS5 + DoH without WinDivert kernel drivers that EAC/Denuvo reject; Some Tricks Ring3) illustrates kernel-driver inventory conflicts for legitimate utility software beside cheat tooling (source: wiki/sources/descriptions/egeorcun__discord-dpi-bridge.md). (source: wiki/sources/descriptions/SamuelTulach__SecureGame.md) **GetRuntimeAttestationReport** runtime driver/hotpatch attestation samples such as [[windows-runtime-attestation-report]] (CodeMaxx; signed Runtime Report Packages; local kernel integrity inspection for AC developers; no remote attestation) complement TPM PCR tooling in the Windows Security Features lane. (source: wiki/sources/descriptions/CodeMaxx__windows-runtime-attestation-report.md) CET/shadow-stack research such as [[cet-research]], Windows 10 CET implementation research such as [[cet-win10]] (gmh5225; shadow stack + IBT; kernel CFI), shadow-stack query PoCs such as [[query-shadow-stack]] (gmh5225; read/mismatch detection; return-address integrity), and stack-spoof detection via [[shadow-stack-walk]] (gabriellandau; `CaptureStackBackTrace` / `StackWalk64` + CET/HSP shadow stack; `Detection:Spoof Stack`) and [[cet-spoofing-detection]] (0xjbb; usermode PoC; hardware shadow stack vs user call stack comparison for missing/mismatched frames; Clang/CMake; `Detection:Spoof Stack`) in the Windows Security Features lane. (source: wiki/sources/descriptions/yardenshafir__cet-research.md) (source: wiki/sources/descriptions/gmh5225__CET-win10.md) (source: wiki/sources/descriptions/gmh5225__QueryShadowStack.md) (source: wiki/sources/descriptions/gabriellandau__ShadowStackWalk.md) (source: wiki/sources/descriptions/0xjbb__cet-spoofing-detection.md) Software-only return-address spoofing detection such as [[rasd]] (cryotb; R5AC/Apex Legends `RtlCaptureStackBackTrace` stackwalk reconstruction; gadget heuristics for jmp/add-rsp/ret spoofers; `Detection:Spoof Stack`) complements CET-backed checks. (source: wiki/sources/descriptions/cryotb__RASD.md) Offensive Linux service hardening for long-running Apex externals such as [[project-tanya]] (XRadius; C# / .NET; process isolation + ptrace restrictions on daemonized memory automation) illustrates cheat-side inspection-resistance patterns opposite ptrace-based debuggers under [[easy-anti-cheat]]. (source: wiki/sources/descriptions/XRadius__project-tanya.md) Early-boot **bootExecute** EDR bypass research such as [[bootexecute-edr]] (executes before Windows services; cheat / hide) stresses service-start timing vs AC/EDR load. (source: wiki/sources/descriptions/rad9800__BootExecuteEDR.md) Leaked-certificate / clock-rollback DSE abuse is illustrated by [[pastdse]] (VeriSign material; temporary date change before revocation window). (source: wiki/sources/descriptions/utoni__PastDSE.md) CI.dll hook / `g_CiEnabled` DSE bypass PoCs such as [[dse-hook]] (gmh5225; patches signature verification to load unsigned drivers; kernel trust-feature research) (source: wiki/sources/descriptions/gmh5225__dse_hook.md). Direct `ci.dll!g_CiOptions` DSE bypass PoCs such as [[dse-patcher-2]] (gmh5225; patches code-integrity options to load unsigned kernel drivers; trust-feature research) (source: wiki/sources/descriptions/gmh5225__Dse-Patcher-2.md). Kernel validation-chain DSE bypass PoCs such as [[disabledse]] (gmh5225; patch `SeValidateImageHeader` via `MiValidateSectionCreate` / `MiValidateSectionSigningPolicy`; unsigned driver load; trust-feature research) (source: wiki/sources/descriptions/gmh5225__DisableDSE.md). Signed-driver DSE bypass PoCs such as [[dsedodge-signed-kernel-driver]] (gmh5225; legitimately signed driver certificate loads kernel code without triggering DSE validation; PTT-based defeat research; trust-feature research) (source: wiki/sources/descriptions/gmh5225__DSEDodge-Signed-Kernel-Driver.md). CPU-Z vulnerable-driver DSE bypass such as [[cpuc-dsefix]] (SamLarenN; exploits CPU-Z driver to patch CI globals and load unsigned kernel drivers; anti-cheat bypass experimentation; cheat / CPU-Z) (source: wiki/sources/descriptions/SamLarenN__CPUZ-DSEFix.md). BYOVD-backed reflexive DSE-bypass driver loaders such as [[capcomlib]] (gmh5225; custom PE loader; default `Capcom.sys`; modular other exploitable signed drivers; trust-feature research) (source: wiki/sources/descriptions/gmh5225__CapcomLib.md). Signing with leaked certificates for AC/sign-tool study is illustrated by [[magic-signer]] (admin required; can break TLS/HTTPS while active). (source: wiki/sources/descriptions/namazso__MagicSigner.md) Black-signature kernel driver development such as [[black-signature-driver]] (gmh5225; driver dev + networking; Anti Cheat → Black Signature lane) (source: wiki/sources/descriptions/gmh5225__BlackSignatureDriver.md). Expired-cert Authenticode signing via `signtool.exe` DLL sideload is illustrated by [[sign-expired]] (XmlLite.dll hijack; in-memory patch of `CertVerifyTimeValidity` and `GetSystemTimeAsFileTime` to bypass expiry without changing system clock). (source: wiki/sources/descriptions/mathisvickie__sign-expired.md) Detours-based `signtool` import-hook expiry bypass is illustrated by [[fuck-cert-verify-time-validity]] (LordPE import into signtool/DSignTool/CSignTool; hooks `CertVerifyTimeValidity` + optional `-fuckyear` on `GetLocalTime`; Sign Leaked Cert). (source: wiki/sources/descriptions/hzqst__FuckCertVerifyTimeValidity.md) Detours DLL hooking of Windows code-signing utilities via [[hooksigntool]] (Jemmy1228; C++; intercepts certificate validity and timestamp signing APIs; configurable custom timestamp endpoints and modified signing-time behavior; Sign Leaked Cert). (source: wiki/sources/descriptions/Jemmy1228__HookSigntool.md) Leaked/expired-cert Authenticode signing without timestamp spoofing is illustrated by [[signtoolex]] (Sign Leaked Cert; anti-cheat / sign-tools defensive research). (source: wiki/sources/descriptions/hackerhouse-opensource__SignToolEx.md) PE Authenticode signature theft (transplant `certTable` onto unsigned binaries for weak AV CA/presence checks) is illustrated by [[sigthief]] (Some Tricks / Windows Ring3). (source: wiki/sources/descriptions/secretsquirrel__SigThief.md) C++ PE security-directory Authenticode blob copy via [[stealing-signatures]] (Sentient111; duplicates `WIN_CERTIFICATE` metadata without valid trust—verifier/tamper-detection edge-case testing). (source: wiki/sources/descriptions/Sentient111__StealingSignatures.md) CLI Authenticode signature removal from PE/COFF binaries (EXE/DLL/SYS) via [[unsign]] (SV-Foster; strips security-directory data and handles PE header edge cases for re-signing; RE / malware analysis / security testing). (source: wiki/sources/descriptions/SV-Foster__UnSign.md) Header-only C++ signature theft with registry-hook certificate-trust patching is illustrated by [[signature-kid]] (`WIN_CERTIFICATE` security-directory copy; system-level verification bypass; code-signing / signature-trust robustness research). (source: wiki/sources/descriptions/dslee2022__SignatureKid.md) Comprehensive Authenticode manipulation toolkit [[trustmebro]] (KriyosArcane; Python + C++; signature steal/clone, PKCS#7 payload embed via SigStash, SIP provider hijack across 19 file types, WinVerifyTrust FinalPolicy bypass, Smart App Control evasion on Windows 11, SIPExec lateral movement, FormatGhost analyst-triggered persistence; ships YARA/Sigma detection rules, SigStash extraction, and Impacket remote-registry orchestration; authorized red-team / trust-control research). (source: wiki/sources/descriptions/KriyosArcane__TrustMeBro.md) Fake-certificate Authenticode signing with zero external dependencies (Microsoft devkit binaries only) is illustrated by [[lazy-sign]] (Fake Cert; Some Tricks / Windows Ring3). (source: wiki/sources/descriptions/jfmaes__LazySign.md) Go CLI domain-metadata cert synthesis and PFX signing via [[limelighter]] (Tylous; spoofed cert material from domain metadata; external signing utilities; optional valid cert signing; red-team trust/EDR detection research; Fake Cert) extends that lane. (source: wiki/sources/descriptions/Tylous__Limelighter.md) Fake Authenticode presence-only signing that crafts non-cryptographically-valid certificate structures passing superficial PE verification is illustrated by [[fakesign]] (gmh5225; Fake Cert; Some Tricks / Windows Ring3). (source: wiki/sources/descriptions/gmh5225__FakeSign.md) CVE-2020-0601 Windows CryptoAPI ECC root-spoof / ChainOfFools PoC tooling is illustrated by [[chainoffools]] (Python `gen-key.py` + OpenSSL; forge rogue CA matching trusted P-384 root public key; CVE / Fake Cert). (source: wiki/sources/descriptions/gmh5225__chainoffools.md) In-place Authenticode certificate-table patching that preserves signature validity is illustrated by [[sigflip]] (SigInject + SigLoader; Some Tricks / Ring3). (source: wiki/sources/descriptions/med0x2e__SigFlip.md) Legitimate Linux UEFI Secure Boot PE-COFF signing/verification (Authenticode/PKCS#7; NSS) is illustrated by [[pesign]]. (source: wiki/sources/descriptions/rhboot__pesign.md) Cross-platform Authenticode signing without Windows `signtool` is illustrated by [[osslsigncode]] (OpenSSL/cURL; PE/CAB/CAT/MSI/APPX/scripts; PKCS#11, RFC 3161 timestamp, page hash, nested signatures, catalog files; Anti Cheat → Sign Tools). (source: wiki/sources/descriptions/mtrojnar__osslsigncode.md) Windows-native `signtool` GUI workflow tooling is illustrated by [[signtoolgui]] (Windows Forms; cert store thumbprint, PFX, Azure Trusted Signing; batch sign, validation, PowerShell CI/CD export; Anti Cheat → Sign Tools). (source: wiki/sources/descriptions/michaelmsonne__SignToolGUI.md) Low-level PE Authenticode digest computation for sign/verify tooling is illustrated by [[pedigest]] (C library; hash-exclusion algorithm; BCrypt SHA-1/256/384/512; kernel + usermode; Anti Cheat → Calculating the authenticode digest). (source: wiki/sources/descriptions/mihaly044__pedigest.md) Legitimate Microsoft WHQL/Attestation submission automation via [[sdcm]] (Partner Center REST CLI; signed driver download; Windows Update shipping labels) contrasts with abusive signing paths above. (source: wiki/sources/descriptions/microsoft__SDCM.md) User-mode Windows Defender control GUIs such as [[defender-control]] (C#; registry/service toggles for real-time / Tamper Protection / sample submission) and integrated UAC-bypass + SYSTEM escalation tooling such as [[disable-windows-defender-]] (gmh5225; COM-based UAC bypass + token manipulation → real-time + Tamper Protection disable) sit in the AV/EDR-control research lane adjacent to kernel paths like [[windefctl]]. (source: wiki/sources/descriptions/qtkite__defender-control.md) (source: wiki/sources/descriptions/gmh5225__Disable-Windows-Defender-.md) Kernel exploitation frameworks such as [[trinity]] (cpz; modular C/C++ pipeline chaining driver vulns, memory corruption, and priv-esc primitives → arbitrary kernel code execution; README fully disables & removes Windows Defender) extend that lane. (source: wiki/sources/descriptions/cpz__trinity.md) **Obfuscation tooling:** [[shredder-rs]] — x86_64 polymorphic instruction shredding (context-preserving) for AC/obfuscation-engine research. (source: wiki/sources/descriptions/zx0CF1__shredder-rs.md) Python x64 opcode-equivalent substitution: [[beatrice-py]] — pattern-match / replace with semantically identical but byte-different encodings for AV/AC signature-evasion study. (source: wiki/sources/descriptions/raskolnikov90__Beatrice.py.md) Radare2 metamorphic transform: [[r2morph]] — r2pipe-based binary mutation for obfuscation-engine / signature-mutation study (Cheat → Radare Plugins). (source: wiki/sources/descriptions/seifreed__r2morph.md) Polymorphic PE rewriter: [[morphkatz]] — mimikatz-targeted mutation engine (disassembly, CFG analysis, register renaming, junk insertion, equivalent substitution, data-flow obfuscation; semantically identical Windows x64 PE variants for signature-evasion study). (source: wiki/sources/descriptions/0xMohammedHassan__morphkatz.md) Cheat-side signature mutation: [[lumina-cheat]] — internal CS:GO sample that mutates to keep a changing signature (VAC-facing research lane). (source: wiki/sources/descriptions/whereisr0da__Lumina-Cheat.md) Engine-side data hiding: [[static-variables-obfuscator-ue4]] obfuscates UE4 static variables against Cheat Engine–style scans (`Game Engine Protection:Unreal`). (source: wiki/sources/descriptions/zompi2__Static-Variables-Obfuscator-UE4.md) UE4 Secure-Client plugin [[unreal-engine-protection]] (SCUE4; SafeGameInstance + encrypted Blueprint Safe Types + Game-Guard external scanner with in-game fallback; `Game Engine Protection:Unreal`). (source: wiki/sources/descriptions/gmh5225__UnrealEngine-Protection.md) Alternate SCUE4 module listing [[ue-plugin-scue4-plugin]] (integrity checks, variable memory protection, packet encryption, binary tamper detection; C++ UE4 game module). (source: wiki/sources/descriptions/gmh5225__UE-Plugin-SCUE4-Plugin.md) Title-integrated UE5 multiplayer horror sample [[ue5-multiplayer-project]] (gmh5225; networked template tagged with anti-cheat in README) illustrates AC in a full replicated UE5 title beside drop-in plugins. (source: wiki/sources/descriptions/gmh5225__UE5MultiplayerProject.md) Large-scale UE5 Mass Entity simulation sample [[projectm]] (LeroyTechnologies; tens-of-thousands combined AI/player battles; command workflows and large-map architecture; informs multiplayer security and anti-abuse design; UE5 FPS Game) complements title samples by focusing on high-scale entity simulation patterns. (source: wiki/sources/descriptions/LeroyTechnologies__ProjectM.md) Unity runtime variable/prefs encryption via [[usecurity]] (PlayerPrefs storage encryption + typed runtime encrypt/decrypt API; `Game Engine Protection:Unity`). (source: wiki/sources/descriptions/ls9512__USecurity.md) Unity C# obfuscation/protection: [[obfuz]] (open-source commercial-grade Unity code protection; actively developed; `Game Engine Protection:Unity`). (source: wiki/sources/descriptions/focus-creative-games__obfuz.md) Alternate Unity C# obfuscator: [[unity3d-obfuscator]] (bmjoy; Unity/debugging-oriented managed protection; `Game Engine Protection:Unity`). (source: wiki/sources/descriptions/bmjoy__Unity3D_Obfuscator.md) Godot sandboxed modding via [[godot-sandbox]] (all platforms; Plugins:Godot; isolates mod code for safe player extensions; `Game Engine Protection:Godot`). (source: wiki/sources/descriptions/libriscv__godot-sandbox.md) Binary Packer lane: [[pe32-password]] — C/C++ PE32 password packing for packed/modded client study. (source: wiki/sources/descriptions/ytk2128__pe32-password.md); [[packer]] — C/C++ PE X86 compress+encrypt packer (decompression stub; import/relocation/TLS restore; `[X86]`). (source: wiki/sources/descriptions/longqun__Packer.md); [[pe-packer]] — C/C++ PE X86 binary packer (`[X86]`; czs108). (source: wiki/sources/descriptions/czs108__PE-Packer.md); [[ares-framework]] — C++/C# modding, hooking, and debugging framework (Anti Cheat → Binary Packer; craids). (source: wiki/sources/descriptions/craids__AresFramework.md); [[x64-exe-packer]] — PE X64 packing. (source: wiki/sources/descriptions/xsj3n__x64-EXE-Packer.md); [[pepacker]] — C++ PE X64 packer (asset pipeline; `[PE X64]`). (source: wiki/sources/descriptions/hid3rx__PEPacker.md); [[atom-pe-packer]] — Windows PE X64 compress+encrypt packer (decompression stub; import/relocation/TLS restore; `[PE X64]`; gmh5225). (source: wiki/sources/descriptions/gmh5225__AtomPePacker.md); [[hm-pe-packer]] — tutorial-oriented C++ x64 PE packer/protector (Visual Studio; load-time wrap/protect; PE structures, packing stubs, protection mechanics; security learners / RE practitioners; `[PE X64]`; TheAenema). (source: wiki/sources/descriptions/TheAenema__hm-pe-packer.md); [[pe-protector]] — Windows C++ x86 PE protection framework (instruction mutation, built-in x86 assembler pipeline, configurable stub logic, binary compression; CMake build + tests; software protection / anti-tamper / packer-style defense research; `[X86]`; ATsahikian). (source: wiki/sources/descriptions/ATsahikian__pe-protector.md); [[polyengine]] — polymorphic PE packer/crypter (junk code, instruction substitution, XTEA, RunPE process hollowing, stack spoofing, module stomping, Hell's Gate syscalls; CTF / Windows low-level security education; in-memory execution; `[PE]`; LongWayHomie). (source: wiki/sources/descriptions/LongWayHomie__PolyEngine.md); [[win32-nebula]] — PoC packed/protected module loader framework (C++; lightweight loader library + builder patches/encrypts/packs binaries; SDK-style APIs, dynamic service manager; software protection / loader architecture / anti-analysis research; `[PE X64]`; Lima-X). (source: wiki/sources/descriptions/Lima-X__Win32.Nebula.md); [[exe-packer]] — C/C++ x86/x64 PE packer (Huffman-compressed payload section; custom stub with NTDLL/KERNEL32 resolution, import-name decrypt, section map/relocs/imports, OEP jump; andrew9382). (source: wiki/sources/descriptions/andrew9382__exe_packer.md); [[eronana-packer]] — basic Win32 x86 PE packer (Eronana; C++ + companion compression; Visual Studio solution + CLI usage; self-validation extension branch; PE packing / binary protection / unpacking research education; Anti Cheat → Binary Packer `[PE X86]`). (source: wiki/sources/descriptions/Eronana__packer.md) [[packer-tutorial]] — educational step-by-step guide to writing a PE packer from scratch (PE format, section manipulation, import/relocation rebuild, compression stub, entry-point redirect; `[Packer]`). (source: wiki/sources/descriptions/gmh5225__packer-tutorial.md); [[huan]] — encrypted PE loader generator (per-run encryption keys; payload embedded in new loader section; PE structure/loading study; Anti Cheat → Binary Packer). (source: wiki/sources/descriptions/frkngksl__Huan.md); [[awesome-executable-packing]] — curated awesome list of packers, protectors, unpackers, analysis tools, papers, and tutorials (PE/ELF/Mach-O; Executable File Packing). (source: wiki/sources/descriptions/gmh5225__awesome-executable-packing.md); curated obfuscation tooling index [[awesome-obfuscations]] — binary-code / compile-time / LLVM-GCC obfuscators (C/C++/Go/Rust/x86 assembly + VM protectors; Obfuscation Engine). (source: wiki/sources/descriptions/killvxk__awesome-obfuscations.md); [[2pack]] — Rust PE & shellcode packing (EXE/DLL + raw shellcode). (source: wiki/sources/descriptions/xM0kht4r__2Pack.md); [[oxide]] — Rust PE packer (`exe-rs` rewrite; compressed payload + TLS-callback unpack stub; x86/x64 NASM; extensible anti-RE passes; `[Written by Rust]`). (source: wiki/sources/descriptions/frank2__oxide.md); [[wrappe]] — cross-platform Rust packer bundling executable + resource directory into one self-contained binary (Zstandard; parallel pack/unpack; streaming decompression; metadata/resource transfer; portable desktop deployment; `[Rust]`). (source: wiki/sources/descriptions/Systemcluster__wrappe.md); [[shellcode-entropyfix]] — English-word substitution / padding to lower Shannon entropy of shellcode and packed payloads while preserving execution (AV/EDR entropy-based detection evasion). (source: wiki/sources/descriptions/gmh5225__shellcode-EntropyFix.md); [[entropy-reducer]] — PE section padding / data-distribution manipulation to lower Shannon entropy and evade AV/AC heuristic flags on packed or encrypted executables. (source: wiki/sources/descriptions/gmh5225__EntropyReducer.md); [[woody-woodpacker]] — ELF packing (outputs “woody”). (source: wiki/sources/descriptions/vsteffen__woody_woodpacker.md); [[elfuck]] — ELF pack/protect (NRV2E / password / anti-debug / SMC). (source: wiki/sources/descriptions/timhsutw__elfuck.md); [[elfloader]] — Java ELF loader for ps5-jar-loader (PS5 kernel/modding / SDK generation; PlayStation `[ELF]` load path). (source: wiki/sources/descriptions/cryonumb__elfloader.md); [[sloader]] — alternative ELF dynamic loader replacing `ld-linux.so` (modern C++; library loading + symbol resolution; loader design trade-offs; Linux linker-internals research; Binary Packer `[ELF]`). (source: wiki/sources/descriptions/akawashiro__sloader.md); [[stelf-loader]] — Linux x64 ELF→self-loading shell script packer/loader (Python + NASM shellcode; map segments, restore protections, jump to entry; compressed/base64/one-liner modes; payload delivery / ELF runtime loading research; Binary Packer `[ELF]`). (source: wiki/sources/descriptions/DavidBuchanan314__stelf-loader.md); [[m0dern-p4cker]] — C/C++ ELF packing (`[ELF]`). (source: wiki/sources/descriptions/n4sm__m0dern_p4cker.md); [[elfpacker]] — ELF32 `.text` XOR pack + prepend decrypt stub (ELF header/PHDR/SHDR inject; `[ELF]`). (source: wiki/sources/descriptions/mix64__ELFpacker.md); [[kiteshield]] — Linux x86-64 ELF packer/protector (GunshipPenguin; layered RC4 encryption + custom user-space loader; ptrace keeps only active call-stack functions decrypted; anti-debug checks; C + asm; binary obfuscation / anti-analysis education; Binary Packer `[ELF X64]`). (source: wiki/sources/descriptions/GunshipPenguin__kiteshield.md); [[pakkero]] — educational Go binary packer (89luca89; wraps executables/scripts in protected launcher; compression + AES-256-GCM + padding + obfuscation; in-memory execution; optional UPX + metadata mutation; anti-reversing tradeoff study; Binary Packer `[ELF]`). (source: wiki/sources/descriptions/89luca89__pakkero.md); [[elfcrypt]] — ELF `.text` RC4 encrypt + embedded decrypt stub (`mprotect` + decrypt before entry; mmap/section headers; `[ELF]` RC4). (source: wiki/sources/descriptions/droberson__ELFcrypt.md); [[papaw]] — permissively-licensed Linux ELF packer (LZMA/zstd/miniz; statically-linked binaries; self-replacement on disk; optional anti-debug; papawify/unpapawify; `[ELF]` LZMA). (source: wiki/sources/descriptions/dimkr__papaw.md); [[midgetpack]] — ELF packer for untrusted hosts (password + Curve25519 challenge-response; AES-128/HMAC-SHA256; Linux/FreeBSD x86/x86-64/ARM cross-arch; controlled-assessment hardening; `[ELF]`). (source: wiki/sources/descriptions/arisada__midgetpack.md); [[ward]] — simple ELF runtime packer for stealthy droppers (Go/C; modding / memory analysis; Anti Cheat → Binary Packer `[ELF]`). (source: wiki/sources/descriptions/ex0dus-0x__ward.md); [[harmless]] — ARM64/AArch64 ELF pack + in-memory loader (encrypt; custom stub; fileless `memfd_create`; Linux `[ELF]`). (source: wiki/sources/descriptions/litemars__hARMless.md); [[embuche]] — ELF anti-reversing technique collection (Binary Packer / anti-RE study; `[ELF]`). (source: wiki/sources/descriptions/magnussen7__Embuche.md); [[petoy]] — PE-focused packing (C/C++ + JS; `[PE]`). (source: wiki/sources/descriptions/r0ngwe1__petoy.md); [[greym]] — PE-focused C/C++ debugging/packing (`[PE]`). (source: wiki/sources/descriptions/greyb1t__GreyM.md); [[shibari]] — links multiple PE/PE+ files into one output (C++/C modding; Binary Packer / PE merge). (source: wiki/sources/descriptions/jnastarot__shibari.md); [[pezor]] — C++/C PE packing with a hooking-oriented surface. (source: wiki/sources/descriptions/phra__PEzor.md); [[xorpacker]] — C# PE XOR cipher packing (all PE; debugging-oriented). (source: wiki/sources/descriptions/nqntmqmqmb__xorPacker.md); [[hxor-packer]] — C++ PE pack/unpack (Huffman + XOR; compression-only/encryption-only/both CLI; self-unpacking stub runs payload from memory without disk drop; PE internals / runtime loading / packer behavior study; `[PE XOR]`). (source: wiki/sources/descriptions/akuafif__hXOR-Packer.md); [[silent-packer]] — pure C ELF/PE packer (section insertion, code caves, text-section infection; XOR/AES encryption; low-level loader + asm runtime unpack; RE practice / obfuscation experiments / defensive packed-binary research; Binary Packer). (source: wiki/sources/descriptions/SilentVoid13__Silent_Packer.md); [[pepacker-samlarenn]] — simple C++ PE packer (`.text` XOR encrypt + appended decrypt stub; custom PE section parse/rewrite; packer development / basic obfuscation RE; Binary Packer). (source: wiki/sources/descriptions/SamLarenN__PePacker.md); [[evader]] — Windows PE packer/crypter (KooroshRZ; C++ packer + unpack stub; configurable key size/keyspace; runtime key recovery + in-memory payload execution; payload obfuscation, resource embedding, staged decryption; packer development / evasion-focused RE; Binary Packer `[PE]`). (source: wiki/sources/descriptions/KooroshRZ__Evader.md); [[fatpack]] — Windows x64 PE packer (Fatmike-GH; C++ LZMA compression + custom loader stub; resource/section packing; icon/manifest; relocation/import/TLS processing; helper tooling for stub embed + post-build integration; executable protection research / manual-map loader experimentation; Binary Packer). (source: wiki/sources/descriptions/Fatmike-GH__Fatpack.md); [[encryptix-crypter]] — Windows GUI PE crypter/packer (Ezmatehw; C# .NET Framework 4.8; AES/XOR encryption + configurable stub template; RegAsm/RegSvcs/MSBuild LOLBin runtime injection; optional persistence, anti-VM, sleep delays, assembly metadata cloning; dnlib obfuscator with randomization; build-time stub compile + KeyAuth license gating; crypter construction / evasion research; Binary Packer). (source: wiki/sources/descriptions/Ezmatehw__Encryptix-Crypter.md); [[netcrypt]] — C# .NET PE packer (encrypted/compressed managed assembly in loader stub; CLR-only runtime decrypt/decompress; near-zero unpacking delay; SimplePacker WinForms GUI; Anti Cheat → Binary Packer / `.NET`). (source: wiki/sources/descriptions/friedkiwi__netcrypt.md); [[origami]] — .NET assembly packer (compressed managed payload in PE debug directory or `.origami` section; RelocLoader runtime decompress/execute; PE format abuse study; Anti Cheat → Binary Packer / `.NET`). (source: wiki/sources/descriptions/dr4k0nia__Origami.md); [[tinyload]] — minimal PE manual-map loader + packer/crypter (custom VM compress/encrypt → self-extracting stub; import/reloc/entry without standard loader APIs; Binary Packer). (source: wiki/sources/descriptions/iamsopotatoe-coder__TinyLoad.md); [[debug-remover]] — C/C++ strip debug info from binaries (Binary Packer / anti-RE hardening). (source: wiki/sources/descriptions/iArtorias__debug_remover.md); browser WASM DIE via [[die-engine-web]] (PE/ELF/Mach-O format / packer / compiler ID for packed-client triage). (source: wiki/sources/descriptions/t0asts__DIE-engine-web.md) Static CLI packer fingerprinter [[packpeek]] (marker scan + entropy; UPX/ASPack/Themida/VMProtect; JSON/YARA/SARIF for CI triage; defensive packed-client assessment). (source: wiki/sources/descriptions/cognis-digital__packpeek.md) Binary pattern/trait extractor [[binlex]] (function-level disassembly patterns; JSON for YARA and similarity correlation; defensive signature research). (source: wiki/sources/descriptions/c3rb3ru5d3d53c__binlex.md) LLVM pass-plugin obfuscation/anti-tamper: [[kagura]] (CFG/string/data passes + anti-debug runtime; NDK/iOS/Unity/Unreal). (source: wiki/sources/descriptions/ykus4__kagura.md) Lightweight LLVM IR pass obfuscator (insn sub / CFF / string encrypt; ELF/Mach-O): [[the-poor-mans-obfuscator]]. (source: wiki/sources/descriptions/romainthomas__the-poor-mans-obfuscator.md) Security-oriented C23 compiler toolchain via [[neverc]] (NeverSight; custom LLVM backend; pure C23 + integrated linker; compile-time string encryption/hash builtins + mimalloc; DynCode PIC runtime codegen incl. kernel mode; extensible plugin API across 130+ compiler phases; PE/ELF/Mach-O; Windows/Linux/Android user-mode EXE/DLL, Windows kernel drivers, Android kernel modules; AI-friendly security research; NeverC & NeverD / Compiler). (source: wiki/sources/descriptions/NeverSight__NeverC.md) LLVM 18 IR obfuscation for manual-map DLL injection payloads: [[dll-ollvm]] (sub/bcf/fla/trim; strips global ctors; tess-obf preset; evades allocation/table pattern scans; R7flex) (source: wiki/sources/descriptions/R7flex__dll-ollvm.md) Rust LLVM pass plugin [[amice]] (fuqiuluo; `clang -fpass-plugin`; string encrypt / CFF / bogus CFG / MBA / indirect calls+branches / BB split-shuffle / instruction-level VMP; llvm-plugin-rs + inkwell; LLVM 11–22; Android NDK; C/C++/Rust IR; Obfuscation Engine) (source: wiki/sources/descriptions/fuqiuluo__amice.md) Mobile LLVM native obfuscator (Android/iOS; CFF / insn sub / string encrypt / opaque predicates / MBA): [[dprotect]]. (source: wiki/sources/descriptions/open-obfuscator__dProtect.md) Java bytecode virtualizer (Gradle/ASM CLI; pure-Java VM interpreter; dispatch/threaded/polymorphic/register/FSM architectures; encrypted operands + shuffled CFG; educational Java hardening): [[bytecodevm]] (NHCM-dev; Anti Cheat → Obfuscation Engine). (source: wiki/sources/descriptions/NHCM-dev__BytecodeVM.md) Android DEX bytecode-to-native method protector [[nmmp]] (Nativ Method Map Protector; JNI bridges; interpreter/JIT-like ARM/x86 emit; Anti Cheat → Dex / Obfuscation Engine). (source: wiki/sources/descriptions/maoabc__nmmp.md) Hassle-free LLVM pass-plugin for C/C++/ObjC/Swift (13 passes; ObjC metadata / anti-debug·hook / string encrypt / CFF; Darwin-strong): [[obscura]]. (source: wiki/sources/descriptions/nkhmelni__Obscura.md) Obfuscation Engine lane: [[wprotect]] — C/C++ WProtect research reference (xiaoweime). (source: wiki/sources/descriptions/xiaoweime__WProtect.md) Windows PE VM virtualizer: [[dedf-wprotect]] — DeDf; selected native blocks→custom VM bytecode; jump stubs + appended PE section; AsmJit/udis86; anti-tamper / protection research. (source: wiki/sources/descriptions/DeDf__WProtect.md) WProtect SDK generation: [[wprotectsdk]] — C/C++ SDK tooling for obfuscation-engine integration. (source: wiki/sources/descriptions/jokerNi__WProtectSDK.md) C/C++ obfuscation engine: [[furikuri]] — jnastarot PE protect/obfuscate research reference (Anti Cheat → Obfuscation Engine). (source: wiki/sources/descriptions/jnastarot__furikuri.md) PE relocation attack research: [[relocbonus]] — Attack Reloc (DEF CON 26; AC / obfuscation-engine study). (source: wiki/sources/descriptions/nickcano__RelocBonus.md) ELF JMPREL relocation obfuscation: [[rel-fuscate]] — manipulates jmprel `r_offset` to mislead static import display while preserving runtime behavior (partial RELRO; caprinux). (source: wiki/sources/descriptions/caprinux__rel-fuscate.md) .NET assembly obfuscator: [[obfuscar]] — open-source minimalistic rename/string-hide for .NET/Mono (NuGet/global tool). (source: wiki/sources/descriptions/obfuscar__obfuscar.md) .NET application protector: [[confuserex]] — open-source Confuser successor for managed assemblies (Binary Packer / page/CLR protection). (source: wiki/sources/descriptions/mkaring__ConfuserEx.md) Defensive CLR loading control: [[clrguard]] — monitors/blocks .NET CLR assembly loading via ClrHook DLL hooks; logs PE metadata and hashes; optional Windows service (blue-team / .NET attack detection). (source: wiki/sources/descriptions/endgameinc__ClrGuard.md) ConfuserEx IDA deobfuscation: [[confuserex-idapython]] — Python IDAPython script to recover protected .NET from ConfuserEx (cheat / IDA Plugins; pairs with [[confuserex]] protector study). (source: wiki/sources/descriptions/govcert-ch__ConfuserEx_IDAPython.md) .NET obfuscation technique demos: [[obfuscation-methods]] — C#/dnlib modular protections (CFF / anti-dump / anti-de4dot·dnSpy / rename / encrypt / junk / invalid metadata). (source: wiki/sources/descriptions/nak0823__ObfuscationMethods.md) .NET await-based control-flow obfuscator: [[awaitfuscator]] — bin2bin rewrites method bodies into long await chains via custom awaiters and GetAwaiter/GetResult transforms; decompiler-resistant CFG PoC CLI (Washi1337; Obfuscation Engine / `.NET`). (source: wiki/sources/descriptions/Washi1337__AwaitFuscator.md) Post-compile x64 PE obfuscator: [[alcatraz]] — ImGui GUI; mutation / CFF / anti-disasm junk / IAT obfuscation (Zydis + AsmJit). (source: wiki/sources/descriptions/weak1337__Alcatraz.md) (source: wiki/sources/descriptions/gmh5225__Alcatraz.md); PE import-table call obfuscation: [[call-obfuscator]] — decoy IAT entries + load-time shellcode resolves real APIs via PEB→Ldr export parsing (INI config; Call Obfuscation; d35ha) (source: wiki/sources/descriptions/d35ha__CallObfuscator.md); PE same-DLL IAT swap + TLS restore: [[iat-obfuscation]] — C++ Windows import obfuscation; swaps IAT entries within the same DLL and restores correct imports via TLS callback before main; static API-sequence obfuscation / malware-analysis workflow research (MahmoudZohdy; README IAT Obfuscation) (source: wiki/sources/descriptions/MahmoudZohdy__IAT-Obfuscation.md); kernel-proxied runtime API obfuscation: [[apicallproxy]] — C/C++ framework routing file/process/memory/registry/network actions through a kernel driver's DeviceIoControl IOCTL handlers instead of direct usermode APIs; sample APC-injection/driver-load/socket clients; API monitoring evasion + behavioral-analysis hardening research (MahmoudZohdy; README Windows API Call Obfuscation) (source: wiki/sources/descriptions/MahmoudZohdy__APICallProxy.md); Win32/x64 PE obfuscation framework: [[nb-obfuscator]] — Capstone/udis86 disassembly + polymorphic stub/dead-code passes (PSC-Engine; Obfuscation Engine; cxxrev0to1dev) (source: wiki/sources/descriptions/cxxrev0to1dev__nb_obfuscator.md); x86 PE instruction-expansion obfuscator: [[perses]] — replaces selected instructions with larger semantically equivalent sequences (Anti Cheat → Obfuscation Engine). (source: wiki/sources/descriptions/mike1k__perses.md) x32 PE full-rebuild mutator: [[milfuscator]] — Zydis + AsmJit; CS:GO P2C-inspired mutation (Anti Cheat → Obfuscation Engine). (source: wiki/sources/descriptions/nelfo__Milfuscator.md) Android ELF import hide/retrieve: [[android-native-import-hide]] (C++; hooking/debugging; Compile Time lane). (source: wiki/sources/descriptions/reveny__Android-Native-Import-Hide.md) Dual-mode protector with virtualization / flatten / anti-tamper (PE/DLL/SYS + .NET): [[vxlang-page]]. (source: wiki/sources/descriptions/vxlang__vxlang-page.md) Bin2bin x86-64 PE code virtualizer: [[nocturne]] — SDK markers, 30+ polymorphic VM handlers, junk / register map / PDB-guided rewrite. (source: wiki/sources/descriptions/nodiuus__nocturne.md) Rust x86-64 code/PE virtualizer: [[guardian-rs]] — three-component VM obfuscation toolchain (Anti Cheat → Obfuscation Engine `[VM]`). (source: wiki/sources/descriptions/felix-rs__guardian-rs.md) Rust toy x86-64 virtualizing obfuscator: [[x64-virtualizer-rs]] — iced-x86 lift to stack-machine bytecode; runtime JIT vmenter/vmexit bridges; educational VM internals study (`[VM]`; cursey). (source: wiki/sources/descriptions/cursey__x64-virtualizer-rs.md) x86 code virtualizer: [[phantasm-x86-virtualizer]] — static-link or manual VM-runtime embed for program protection (`[VM]`). (source: wiki/sources/descriptions/layerfsd__phantasm-x86-virtualizer.md) x86-64 stack-VM code virtualizer: [[covirt]] — PE MinGW + ELF; MBA + self-modifying code passes; marker-delimited protected regions (`[VM]`; dmaivel). (source: wiki/sources/descriptions/dmaivel__covirt.md) Open-source bin2bin x86-64 code virtualizer: [[binary-shield]] — lifts common x86-64 instructions into custom bytecode executed by a purpose-built VM (`[VM]`; connorjaydunn). (source: wiki/sources/descriptions/connorjaydunn__BinaryShield.md) Process-independent PIVM obfuscation engine: [[mk-pivm]] — lifts x86/x64 (incl. shellcode) into custom IR, emits polymorphic VM bytecode with encrypted handlers, embeds dispatcher into PE executables (`[VM]`; D7EAD). (source: wiki/sources/descriptions/D7EAD__mkPIVM.md) ARM64 ELF VM code protector: [[vmpacker]] (LeoChen-CoreMind; Go; native→custom bytecode; indirect dispatch, chained encryption, CRC integrity, function-split obfuscation; demo programs; binary protection / VM obfuscation RE; Anti Cheat → Obfuscation Engine `[VM]`). (source: wiki/sources/descriptions/LeoChen-CoreMind__VMPacker.md) Win32 VM-based PE protector: [[cerberus]] — ChaosVm x86 bytecode virtualization; disassembler/assembler, PE patcher, CRC32 integrity, Qt GUI (`[VM]`). (source: wiki/sources/descriptions/gmh5225__cerberus.md) RISC-V VM payload obfuscation workshop: [[riscy-workshop]] — **riscvm** interpreter, llvm-mingw transpile chain, liveness + insn mutation; red-team shellcode / host-API / anti-analysis exercises. (source: wiki/sources/descriptions/mrexodia__RiscyWorkshop.md) Bin2bin x64 PE obfuscator (no new section): [[binprotect]] — custom asm/disasm on binwrite; BB-level rewrite; exception dirs / RTTI / relocs / jump tables. (source: wiki/sources/descriptions/noahware__binprotect.md) x86 binary rewrite / obfuscation: [[stitch]] — function relocation, global reference patching, complex transforms, branch handling (CMake examples). (source: wiki/sources/descriptions/badhive__stitch.md) Bin2bin x86 PE protector/obfuscator: [[ryujin]] — research-grade Bin2Bin transformation explorer (`[X86 PE BIN2BIN]`). (source: wiki/sources/descriptions/keowu__Ryujin.md) Cheat Compiler lane: [[compiled-protection]] — C/C++ cheat-compiler research sample (CS:GO-adjacent offensive AC study). (source: wiki/sources/descriptions/razixNew__CompiledProtection.md) Compile-time / runtime C++17 library: [[obfusk8]] — logic/data obfuscation for AC compile-time research. (source: wiki/sources/descriptions/x86byte__Obfusk8.md) Compile-time string encryption: [[sbox]] — C++ constexpr AES-128 / S-box macros (Obfusk8 spin-off; binary-safe). (source: wiki/sources/descriptions/x86byte__sbox.md) C++17 compile-time string encryption via [[xorstr]] (JustasMasiulis; SSE/AVX vectorized inline decrypt; compile-time keys; keeps string data out of normal read-only sections; AC String Crypter). (source: wiki/sources/descriptions/JustasMasiulis__xorstr.md) SIMD compile-time string/integer xorstr: [[mystic-xorstr]] — C++17 header-only; AVX/SSE/NEON decrypt + optional junk/opaque-predicate decompiler clutter. (source: wiki/sources/descriptions/wufhex__Mystic-xorstr.md) C++20 header-only compile-time variable obfuscation: [[obfuscxx]] — AVX2/SSE2/NEON runtime decrypt (MSVC+WDM/LLVM/GCC; x86-64/ARM; AC Encrypt Variable). (source: wiki/sources/descriptions/nevergiveup-c__obfuscxx.md) Runtime polymorphic in-memory variable obfuscation via [[polymorphic-engine]] (Nou4r; C++; stack/heap transforms for primitives and strings; optional SIMD; LLVM/Clang-primary with experimental MSVC; software protection / anti-analysis research; AC Encrypt Variable). (source: wiki/sources/descriptions/Nou4r__Polymorphic-Engine.md) C++17 kernel driver protect/obfuscate library: [[kernelcloak]] — advanced library for protecting/obfuscating kernel drivers (driver development / modding; AC Encrypt Variable / obfuscation-engine research; ck0i). (source: wiki/sources/descriptions/ck0i__Kernelcloak.md) Compile-time XOR string crypter: [[skcrypter]] — header-only constexpr/template XOR encrypt at compile, decrypt at runtime (String Crypter). (source: wiki/sources/descriptions/skadro-official__skCrypter.md) Header-only C++14 compile-time string literal obfuscation: [[obfuscate]] — constexpr encrypt with randomized keys, macro-wrapped runtime decrypt; reduces trivial static string extraction (String Crypter). (source: wiki/sources/descriptions/adamyaxley__Obfuscate.md) Header-only portable C++14 compile-time obfuscation library: [[obfusheader-h]] — string/constant encryption, import/call hiding, control-flow mutation, anti-decompiler techniques; Windows/Unix (Obfuscation Engine). (source: wiki/sources/descriptions/ac3ss0r__obfusheader.h.md) Macro-only C compile-time obfuscation header: [[obfus-h]] — DosX-dev; TCC-oriented Windows x86/x64; function-call obfuscation, control-flow mutation, string hiding, anti-debug, anti-decompilation, fake signature insertion, optional virtualized math; single-header include + preprocessor flags (Obfuscation Engine / Compile Time). (source: wiki/sources/descriptions/DosX-dev__obfus.h.md) String crypter: [[xorlit]] — encrypts string literals; single-argument use defaults key to `xorlit::seed` (AC Compile Time / String Crypter). (source: wiki/sources/descriptions/igozdev__xorlit.md) C++17 XOR data obfuscation framework: [[xordata]] — compile-time and runtime-style obfuscation of constants, variables, and strings; helper structures and example outputs; software hardening / anti-analysis experiments (AC Compile Time / Obfuscation Engine). (source: wiki/sources/descriptions/Sherman0236__XorData.md) Zig compile-time static string obfuscation: [[static-string-obfuscation]] — build-time randomized XOR keys; stripped x86_64 Windows executables; lightweight runtime decrypt; RE resistance / anti-analysis hardening (AC String Crypter). (source: wiki/sources/descriptions/Reijaff__static_string_obfuscation.md) C++23 compile-time PIC string/array obfuscation: [[malstring]] — template-metaprogrammed XOR stack/call strings and callable byte arrays; per-string keys; decrypt-on-use; reduces plaintext binary artifacts (AC String Crypter / Compile Time). (source: wiki/sources/descriptions/ManulMap__malstring.md) Rust compile-time string obfuscation: [[obfstr]] — `obfstr!`/`obfcstr!`/`obfbytes!`/`wide!`/`random!` macros embed obfuscated constants with local runtime decode; lightweight source integration and reproducible build-time randomness rather than strong secret protection (AC String Crypter). (source: wiki/sources/descriptions/CasualX__obfstr.md) C++20 compile-time string/number obfuscation: [[crystr]] — XOR keys from compile-time math, timestamps, and counters; inline or virtual decrypt; per-char/per-value key variation (AC String Crypter). (source: wiki/sources/descriptions/android1337__crystr.md) C++20 header-only compile-time string obfuscation: [[vm-str-hpp]] — Mowokuma; compile-time obfuscation bytecode schema + stack-based VM runtime reconstruct; narrow/wide string macros; keeps plaintext out of static program data; software hardening / RE resistance (AC String Crypter). (source: wiki/sources/descriptions/Mowokuma__vm_str.hpp.md) C++14+ compile-time call obfuscation: [[crycall]] — lambda/virtual-dispatch wrappers hide real callees and argument flow at call sites (AC Compile Time). (source: wiki/sources/descriptions/android1337__crycall.md) Header-only MSVC x64 Hex-Rays decompiler breakage: [[brkida]] — `BRKIDA` macro + compile-time stubs and crafted stack-access patterns that intentionally break IDA Hex-Rays decompilation on protected functions (AC anti-tamper / software protection). (source: wiki/sources/descriptions/android1337__brkida.md) Platform-agnostic compile-time constant encryption: [[oxorany]] — obfuscated any-constant encrypt at build, decrypt at runtime (C/C++; AC Compile Time). (source: wiki/sources/descriptions/llxiaoyuan__oxorany.md) Go string crypter: [[obfuscatxor]] — generates encrypted string variables for use in Go code (AC Compile Time / String Crypter). (source: wiki/sources/descriptions/redskal__obfuscatxor.md) Go build-time obfuscator: [[garble]] — wraps the Go toolchain to build/test/run with hashed identifiers, stripped build/module/debug metadata, optional string/literal obfuscation, tiny mode, and experimental control-flow obfuscation; `garble reverse` maps stack traces when source is available (AC Obfuscation Engine). (source: wiki/sources/descriptions/burrowers__garble.md) Swift string crypter: [[swift-string-obfuscator]] — String Crypter for Swift (AC Compile Time; two-file split also noted). (source: wiki/sources/descriptions/pykaso__Swift-String-Obfuscator.md) Compile-time direct syscall invocation: [[syscalls-cpp]] — C++20 header-only modular library for advanced direct syscalls (AC Compile Time). (source: wiki/sources/descriptions/sapdragon__syscalls-cpp.md) Inline direct-syscall libraries: [[inline-syscall]] — header-only C++ macro-based inline generation on x64 Windows without import-table usage (JustasMasiulis; anti-hooking / game-security research) and simple x86/x64 compile-time wrappers (gmh5225; AC Compile Time). (source: wiki/sources/descriptions/JustasMasiulis__inline_syscall.md) (source: wiki/sources/descriptions/gmh5225__inline-syscall.md) Indirect syscall invocation with dynamic SSN resolve and `ntdll` gadget return-address spoof: [[doom-syscalls]] (SilentisVox; userland hook / RIP-return evasion; AC Compile Time). (source: wiki/sources/descriptions/SilentisVox__DoomSyscalls.md) Header-only C++ syscall invocation [[ebyte-syscalls]] (EvilBytecode; runtime PEB/ntdll SSN resolve; direct + indirect syscall trampolines; VEH guard-page/INT3 byte-switching call obfuscation without memory/asm allocation; AC Compile Time / hook-bypass research) (source: wiki/sources/descriptions/EvilBytecode__Ebyte-Syscalls.md) Compile-time SHA-2/SHA-3 hashing: [[cthash]] — constexpr digest library with `cthash::literals` hash_value suffixes (AC Compile Time). (source: wiki/sources/descriptions/hanickadot__cthash.md) Compile-time regular expressions: [[compile-time-regular-expressions]] — C++ CTRE library (cmake `ctre` target; constexpr regex parse/match; AC Compile Time). (source: wiki/sources/descriptions/hanickadot__compile-time-regular-expressions.md) Compile-time random constants: [[compile-time-random]] — C++11 header-only constexpr FNV/Murmur3-style generator; 32/64-bit macros without runtime RNG; lightweight obfuscation / AC Compile Time research. (source: wiki/sources/descriptions/Deniskore__CompileTimeRandom.md) Kernel-mode lazy import resolution: [[kli]] — header-only C++ alternative to user-mode [[lazy-importer]] for WDK drivers (Anti Cheat / Lazy Importer). (source: wiki/sources/descriptions/hypervisor__kli.md) Extended fork [[kli-ex]] (gmh5225; random seeds, resolve caching, hidden globals, pluggable hash/encryption) extends the same Lazy Importer lane. (source: wiki/sources/descriptions/gmh5225__kli-ex.md) Runtime zero-IAT kernel resolver [[noimportz]] (Th3Spl; C++17 header; LSTAR→ntoskrnl backward scan, `PsLoadedModuleList` module walk, PE export parse like `MmGetSystemRoutineAddress`; template variadic calls + optional hash-map cache; custom mem routines avoid compiler imports; sample KMDF driver for `ntoskrnl`/`ndis.sys`; manually mapped import-free KM code; Anti Cheat / Lazy Importer). (source: wiki/sources/descriptions/Th3Spl__NoImportz.md) Canonical user-mode lazy import: [[lazy-importer]] — header-only C++ runtime module/export resolution without static IAT entries or plaintext strings; safe, cached, and forwarded resolve modes; per-build randomized hashes; minimal codegen (JustasMasiulis; Anti Cheat / Lazy Importer). (source: wiki/sources/descriptions/JustasMasiulis__lazy_importer.md) User-mode lazy import resolution: [[blitz]] — header-only C++ library to dynamically resolve modules and exports with direct call syntax (Anti Cheat / Lazy Importer; emlinhax). (source: wiki/sources/descriptions/emlinhax__blitz.md) Direct syscall tooling such as [[higu-ntcall]] (jnastarot; Some Tricks / Windows Ring3; ENUM-backed calls with parameter-conversion instability) complements compile-time stub libraries for AC bypass / instrumentation research. (source: wiki/sources/descriptions/jnastarot__HIGU_ntcall.md) API hammering via C++20 folds (no explicit loops): [[bloatedhammer]]. (source: wiki/sources/descriptions/rad9800__BloatedHammer.md) Encrypt Variable (scalar) header-only: [[encrypted-value]] — C++ in-app scalar encryption vs memory scanners (AC Encrypt Variable). (source: wiki/sources/descriptions/serge-14__encrypted_value.md) XOR float encrypt sample: [[xor-float]] — C++ XOR-based float/value hiding (AC Encrypt Variable). (source: wiki/sources/descriptions/obama-gaming__xor-float.md) Single-header pointer/value encryption via [[xv]] — C++ `xval` per-variable algorithm randomization; no external deps (AC Encrypt Variable). (source: wiki/sources/descriptions/emlinhax__xv.md) Homomorphic encrypted compute via [[e3]] — Encrypt-Everything-Everywhere; C++ FHE backend wrappers + encrypted variable types/operators for privacy-preserving game-state / variable-protection research (MoMA Lab, NYU Abu Dhabi). (source: wiki/sources/descriptions/momalab__e3.md) Source+binary C++ obfuscation experiments: [[obfcoder]] — CMake/OpenSSL demos of transformation techniques for anti-RE study. (source: wiki/sources/descriptions/ssyuqixe__obfCoder.md) JavaScript/Node.js script protection: [[javascript-obfuscator]] — TypeScript CLI + Node API (rename / string arrays / CFF / self-defending / domain lock; browser games + client logic; AC Obfuscation Engine). (source: wiki/sources/descriptions/javascript-obfuscator__javascript-obfuscator.md) Analyst-side JavaScript bundle SAST + deobfuscation via [[omega-sast]] (Black0ffR; Node.js; taint tracking, obfuscator fingerprinting, string-array/CFF recovery; client-side vuln + hidden-logic RE for game/AC web assets) (source: wiki/sources/descriptions/Black0ffR__omega-sast.md) Analyst-side Node.js runtime tracing via [[nodejs-tracer]] (CheckPointSW; preload core-module instrumentation; log API usage, spoof anti-analysis checks, preserve dropped artifacts; obfuscated Node.js malware / script RE) (source: wiki/sources/descriptions/CheckPointSW__Nodejs-Tracer.md) Browser-game client-integrity bypass samples such as [[krunker-loader]] (JavaScript userscript; local anti-tamper token + Quirify-style license/heartbeat emulation; Krunker.io study) illustrate offensive countermeasures to client-side script integrity and key validation opposite [[javascript-obfuscator]] self-defending protections. (source: wiki/sources/descriptions/levifrsn63__krunker-loader.md) Browser-game **anti-bot gate bypass** such as [[glotus-client]] (TypeScript/Bun Tampermonkey; Moomoo.io; Altcha proof-of-work solver via Web Workers before WebSocket connect; combat/bot automation; Cheat / Debugging) stresses server-side PoW/challenge verification opposite in-browser hooking. (source: wiki/sources/descriptions/Murka007__Glotus-Client.md) Python script protection: [[pyarmor]] — CLI obfuscator (rename / C-convert hot functions; machine bind + expiry; optional Themida; Python 2/3; AC Obfuscation Engine). (source: wiki/sources/descriptions/dashingsoft__pyarmor.md) Luau/Lua VM-based script protection: [[lua-obfuscator-clyde-protection]] — TypeScript AST + stack/register VM (opaque predicates / opcode shuffle / LZMA bytecode; Roblox-oriented). (source: wiki/sources/descriptions/sfr-development__Lua-Obfuscator-Clyde-Protection.md) **VEH-based protection RE:** [[veh]] implements a VEH software debugger (breakpoints / single-step / AVs without the Debug API; CE plugin for manual-mapped VEH DLLs) useful when studying processes that block conventional debuggers. (source: wiki/sources/descriptions/user23333__veh.md) [[veh-dumper]] surgically dumps VectoredException/Continue handlers as IDA-ready PE64 modules for studying VEH-backed AC / anti-tamper logic. (source: wiki/sources/descriptions/xxFURYWOLFxx__veh-dumper.md) [[val-exception-handler]] PoCs [[vanguard]] kernel exception dispatch (hardware exceptions / VEH; `ZwRaiseException` dump) for code-exec or evasion research. (source: wiki/sources/descriptions/lil-skies__val-exception-handler.md) [[dump-val-exception-handler]] dumps Valorant exception handler registration and VEH chains (`RtlpCallVectoredHandlers` dump; gmh5225) for Vanguard runtime protection RE. (source: wiki/sources/descriptions/gmh5225__Dump-val-exception-handler.md) PAGE_NOACCESS + VEH trampoline / single-step re-protect sample: [[no-access-protection]] (external scanners AV; legitimate exec resumes via VEH). (source: wiki/sources/descriptions/weak1337__NO_ACCESS_Protection.md) Hardened console sample in the same VEH + `PAGE_NOACCESS` lane: [[bincon]] (vs memory scans / mods / debuggers). (source: wiki/sources/descriptions/saveme712__BinCon.md) Memory-analysis sample [[veh-hide-memory]] (C++; page-protection / anti-tamper RE). (source: wiki/sources/descriptions/gmh5225__veh_hide_memory.md) x86 PAGE_NOACCESS on-access decryption: [[no-access-protection-x86]] (software protection / anti-dump RE). (source: wiki/sources/descriptions/gmh5225__no-access-protection-x86.md) VEH + `PAGE_GUARD` code-hiding research: [[voidmaw]] (AV/AC page-protection lane). (source: wiki/sources/descriptions/vxCrypt0r__Voidmaw.md) Defensive runtime integrity library [[memory-guard]] (gmh5225; monitors critical regions via page guards and VEH; Page Protection) sits in the same exception-driven lane. (source: wiki/sources/descriptions/gmh5225__MemoryGuard.md) Defensive **EAT** integrity monitoring PoC [[eat-guard]] (connormcgarr; VEH + PAGE_GUARD on Export Address Table pages; detects hooking of exported function pointers). (source: wiki/sources/descriptions/connormcgarr__EATGuard.md) Defensive **function-pointer / vtable** integrity PoC [[pointer-guard]] (charliewolfe; C/C++; hardware breakpoints or PAGE_GUARD on critical pointer slots; detects cheat/exploit redirection of execution flow). (source: wiki/sources/descriptions/charliewolfe__PointerGuard.md) Self-remapping code anti-tamper PoC [[self-remapping-code]] (changeofpace; C; multiple virtual mappings of same physical pages—execute from one view while integrity-checking another; section-backed file mappings; anti-patching / anti-debug via memory aliasing). (source: wiki/sources/descriptions/changeofpace__Self-Remapping-Code.md) x64dbg ForcePageProtection plugin [[force-page-protection]] (changeofpace; force-set page protection on mapped views when NtProtectVirtualMemory fails—SEC_NO_CHANGE, incompatible initial protection; remaps views with desired protection; fpp commands; Bypass Remap Memory; anti-patching bypass for dynamic analysis). (source: wiki/sources/descriptions/changeofpace__Force-Page-Protection.md) Offensive Page Guard hook samples such as [[pghooker]] (C++; cheat / hook) sit in the same `PAGE_GUARD` exception-driven lane. (source: wiki/sources/descriptions/nelfo__PGHooker.md) Non-invasive VEH + `PAGE_GUARD` printf/output interception without byte patches: [[veh-printf-hook]] (VEH function-interception RE). (source: wiki/sources/descriptions/gmh5225__veh-printf-hook.md) Custom VEH registration via `RtlpCallVectoredHandlers` hook: [[custom-veh]] (faster handlers that dispatch before vanilla VEH chain; Ring3 callback-order research). (source: wiki/sources/descriptions/gmh5225__custom-VEH.md) Stealth VEH registration by direct `LdrpVectorHandlerList` manipulation: [[ghostveh]] (EvilBytecode; C++ PoC; `RtlEncodePointer`/`RtlDecodePointer` + `LdrProtectMrdata` MRDATA unlock; bypasses `RtlAddVectoredExceptionHandler`; VEH chain internals / anti-debug research) (source: wiki/sources/descriptions/EvilBytecode__GhostVEH.md) Alternative **`KiUserExceptionDispatcher`** hooking via ntdll `.mrdata` pointer patch such as [[ki-user-exception-dispatcher-hook]] (brew02; `Wow64PrepareForException` + `LdrProtectMrdata` + Zydis; avoids VEH chain manipulation; stealth UM exception-dispatch research) (source: wiki/sources/descriptions/brew02__KiUserExceptionDispatcherHook.md) ROP-only / PIC Gargoyle-style sleep-hide (no APCs): [[deepsleep]] (x64; page-protection research). (source: wiki/sources/descriptions/thefLink__DeepSleep.md) Cyclic shellcode encrypt/decrypt + RW/NoAccess↔RX protection fluctuation PoC: [[shellcode-fluctuation]] (mgeeky; in-memory evasion vs memory scanners). (source: wiki/sources/descriptions/mgeeky__ShellcodeFluctuation.md) Concealed shellcode in randomized RW buffers before RX flip: [[shellcode-plain-sight]] (LloydLabs; C demo; oversized random-filled region, payload at random offset, post-exec zero cleanup; memory-analysis / AC detection testing). (source: wiki/sources/descriptions/LloydLabs__shellcode-plain-sight.md) GPU-resident payload staging PoC [[gpu-shellcode]] (H1d3r; C/C++ Windows; CUDA APIs + MinHook on Sleep/VirtualAlloc; copies payload to NVIDIA GPU memory during idle, repopulates executable pages on wake via VEH; memory hiding vs process memory scanners; shellcode / page-protection research). (source: wiki/sources/descriptions/H1d3r__GPU_ShellCode.md) Educational in-memory data polymorphism: [[in-memory-mutation-demo]] — C++23 `ProtectedData` decrypt/use/re-encrypt with `VirtualProtect`/`mprotect` page alignment, position-dependent XOR + dynamic key rotation, permission restore, and secure wipe (alekzandren; binary mechanics / defense-in-depth). (source: wiki/sources/descriptions/alekzandren__in-memory-mutation-demo.md) PE `.reloc`-backed allocation hiding via [[memory-relocalloc]] (gmh5225; unconventional Windows/Android allocs to evade heap/VAS memory scanners) (source: wiki/sources/descriptions/gmh5225__memory-relocalloc.md) Thread-terminate/restore sleep obfuscation PoC: [[death-sleep]] (janoglezcampos; page protection during no-execution + hide execution thread). (source: wiki/sources/descriptions/janoglezcampos__DeathSleep.md) ROP-based Rust sleep obfuscation crate [[shelter]] (Kudaes; AES-128 in-memory/whole-PE encrypt; strips execute permission while sleeping; ROP resume; stack spoofing + indirect syscalls; avoids timer/APC patterns; assembly stubs; in-memory evasion research). (source: wiki/sources/descriptions/Kudaes__Shelter.md) Dynamic runtime-protection analysis framework [[dynsec]] (gmh5225; instrumentation + monitoring for anti-tamper, anti-debug, integrity checks; AC / runtime protection RE). (source: wiki/sources/descriptions/gmh5225__Dynsec.md) Lazy decrypt-on-first-access page protection: [[page-no-access]] (C++; modding; pages decrypted on very first access; Anti Cheat → Page Protection). (source: wiki/sources/descriptions/hotline1337__page_no_access.md) Byfron/Hyperion-style VEH + `PAGE_NOACCESS` anti-tamper PoC [[page-no-access-not-byfron]] (not-byfron DLL + `LoadLibrary` tester; page guards vs scan/patch; gmh5225). (source: wiki/sources/descriptions/gmh5225__PAGE_NO_ACCESS-not-byfron.md) Offensive PE reconstruction against the same protection class via [[vulkan]] (atrexus; C++; iterative NOACCESS page resolution + import fixup; Hyperion/Theia; Roblox/The Finals; Dump lane) complements defensive PoCs. (source: wiki/sources/descriptions/atrexus__vulkan.md) **Disk / file forensics:** recover deleted on-disk artifacts (payloads, logs, dumps) via tools such as [[file-recovery-tool]] (NTFS/FAT32/ExFAT MFT/USN + carving; Information System & Forensics lane). (source: wiki/sources/descriptions/wesmar__FileRecoveryTool.md) macOS command-line disk imaging packages such as [[ftk-imager-osx]] (MrMugiwara; FTK Imager CLI wrapper/guide; acquisition, split outputs, MD5/SHA1 hash verification, E01/SMART formats, fragmentation/compression/evidence metadata; IS forensics / IR on macOS; Forensics Tools For MAC OS X). (source: wiki/sources/descriptions/MrMugiwara__FTK-imager-OSX.md) Curated anti-forensic technique catalogs such as [[anti-forensics]] (ashemery; README-indexed data hiding, log tampering, registry/FS artifact manipulation, virtualization evasion; DFIR tradecraft study; not executable tooling) document the offensive evidence-obscuration side of the same lane. (source: wiki/sources/descriptions/ashemery__Anti-Forensics.md) Executable Windows anti-forensics utilities such as [[forensia]] (PaulNorman01; C++; file shredding, event-log/prefetch suppression, USN journal handling, timestamp cleanup, shell/cache artifact removal, Defender quarantine clearing, self-removal; post-exploitation trace reduction; red-team simulation and defensive IR validation) implement that tradecraft in tooling opposite collectors like [[dfirtriage]]. (source: wiki/sources/descriptions/PaulNorman01__Forensia.md) Locked-file / running-executable self-deletion PoCs such as [[delete-self-poc]] (LloydLabs; C; rename primary data stream then SetFileInformationByHandle file disposition; handle sequencing and locked-file removal edge cases; anti-forensics / secure cleanup / defensive detection engineering). (source: wiki/sources/descriptions/LloydLabs__delete-self-poc.md) Bootable Linux media sanitization via [[shredos-x86-64]] (PartialVolume; Buildroot nwipe environment; DoD/Gutmann/PRNG/verification; multi-drive BIOS/UEFI IMG/ISO; optional wipe certificates/logs; pre-disposal disk erasure; Disk Eraser / IS forensics) complements artifact recovery and Windows anti-forensics utilities in the same lane. (source: wiki/sources/descriptions/PartialVolume__shredos.x86_64.md) NTFS structure / encryption / USN inspection via [[ntfstool]] (MBR/VBR/MFT, BitLocker, EFS; AC forensics). (source: wiki/sources/descriptions/thewhiteninja__ntfstool.md) USN↔MFT↔`$LogFile` timeline correlation via [[ntfs-linker]] (full-path create/modify/rename/delete reconstruction). (source: wiki/sources/descriptions/strozfriedberg__ntfs-linker.md) Python NTFS forensic parser suites such as [[ntfs-parse]] (NTFSparse; MFT/$LogFile/$UsnJrnl linking; CLI export, transaction parsing, timeline PoC; parsed text/CSV; DFIR / filesystem research). (source: wiki/sources/descriptions/NTFSparse__ntfs_parse.md) Focused NTFS USN / change-journal tooling such as [[usn]] (C++; AC / IS forensics). (source: wiki/sources/descriptions/rbmm__USN.md) NTFS change-journal viewers such as [[ntfs-journal-viewer]] (C; `$UsnJrnl` inspection; AC / IS forensics). (source: wiki/sources/descriptions/mgeeky__ntfs-journal-viewer.md) Same-author SearchEx tooling such as [[searchex]] (C++; hooking / memory analysis; AC / IS forensics). (source: wiki/sources/descriptions/rbmm__SearchEx.md) Live Windows DFIR triage collectors such as [[dfirtriage]] (process/network/registry/event-log/prefetch/browser history → structured output) support rapid IR evidence preservation in the same lane. (source: wiki/sources/descriptions/travisfoley__dfirtriage.md) Bundled Windows forensics training toolkit [[pwf]] (Personal Windows Forensics; artifact collection, timeline generation, registry analysis, streamlined IR evidence preservation; AC / Windows Forensics Training) targets practitioner DFIR workflows in the same lane. (source: wiki/sources/descriptions/bluecapesecurity__PWF.md) Structured Windows artifact reference guides such as [[windows-forensic-artifacts]] (Psmths; Markdown documentation across execution/account/file/network/persistence/user-activity domains; artifact locations, parsing options, investigative timeline correlation; complements [[anti-forensics]] offensive tradecraft catalog; IS forensics study) document where to find and how to interpret host evidence in the same lane. (source: wiki/sources/descriptions/Psmths__windows-forensic-artifacts.md) Read-only AC footprint scanners such as [[anticheat-scanner]] (PickAngE; Python 3.10+; drivers/processes/services/registry/tasks/FS + BAM/Prefetch/MUICache; O(1) sig index + rapidfuzz + PE/Authenticode; ACE/EAC/BattlEye/EA AC/HoYoProtect; privacy/education lane) enumerate third-party anti-cheat presence and execution traces on a local Windows host. (source: wiki/sources/descriptions/PickAngE__AntiCheat-Scanner.md) Graphics-mod deploy manager [[dlssg-30s-manager]] (BUNNY-19C; WPF .NET 8; RTX 30 `dlssg_for_sm86` proxy for `nvngx_dlssg.dll`; kernel AC filename/directory fingerprinting for EAC/BattlEye/Vanguard/ACE/NEAC/HoYoKProtect blocks unsafe installs and surfaces quarantined proxy DLLs; Authenticode/SHA-256 verified mod downloads; DirectX Compatibility + AC-interaction research) (source: wiki/sources/descriptions/BUNNY-19C__DLSSG-30s-manager.md) illustrates consumer-side awareness of proxy-DLL quarantine beside defensive scanners. Standalone C volatile-state collectors such as [[volatile-data-collector]] (handles, kernel modules, sessions, drivers, ICMP, registry; per-artifact utilities) complement scripted triage for targeted live acquisition in the same IS forensics lane. (source: wiki/sources/descriptions/gtworek__VolatileDataCollector.md) Proactive pre-modification backup copies via [[minivers]] (monitored files copied before change/delete/rename; AC / backup-file defensive research). (source: wiki/sources/descriptions/guidoreina__minivers.md) Windows kernel driver backup/restore such as [[ez-drv-bak]] (gmh5225; preserve or roll back driver store state during AC/driver development and defensive forensics) (source: wiki/sources/descriptions/gmh5225__ezDrvBAK.md) AD domain host enumerators such as [[netview]] (`-d` current or specified domain) help map enterprise endpoints during cheat-investigation or IR triage. (source: wiki/sources/descriptions/mubix__netview.md) Host credential harvesters such as [[pillager]] (Go static binary; browser passwords/cookies/Wi-Fi/chat data decrypt-export) illustrate post-compromise collection surfaces that AC/IR forensics may need to attribute. (source: wiki/sources/descriptions/qwqdanchun__Pillager.md) Telegram channel/chat OSINT collectors such as [[teleparser]] (Python/Telethon; JSON/CSV/MongoDB + NLTK lemmatization; cheat-marketplace / community message analysis; IS forensics) complement host-side harvest when investigating distribution channels. (source: wiki/sources/descriptions/artmih24__TeleParser.md) In-place VM snapshot / virtual-disk credential extractors such as [[vmkatz]] (LSASS, SAM/LSA, cached creds, NTDS.dit without bulk image exfil) sit in the same AC / IS forensics lane. (source: wiki/sources/descriptions/nikaiw__VMkatz.md) Linux offline RAM dump filesystem mounting via [[memnixfs]] (C++17; AVML/LiME/raw/kdump → browse processes/modules/sockets/timelines with standard tools; MemProcFS-style Linux memory forensics for AC engineers / threat hunting). (source: wiki/sources/descriptions/MemNixFS__MemNixFS.md) Linux live RAM capture via [[dumpit-linux]] (MagnetForensics; Rust; `/proc/kcore` → ELF core; optional tar.zst; gdb/crash/drgn; no custom LKM; IR / Linux memory forensics). (source: wiki/sources/descriptions/MagnetForensics__dumpit-linux.md) ## Related concepts [[input-provenance]] · [[detector-operations]] · [[network-environment-evidence]] · [[kernel-pool-scanning]] · [[ai-aimbot-detection]] · [[research-rigor]] · [[kernel-callbacks]] · [[byovd]] · [[hvci]] · [[bootexecute-edr]] · [[pastdse]] · [[dse-hook]] · [[dse-patcher-2]] · [[disabledse]] · [[dsedodge-signed-kernel-driver]] · [[cpuc-dsefix]] · [[capcomlib]] · [[magic-signer]] · [[sigthief]] · [[defender-control]] · [[disable-windows-defender-]] · [[windefctl]] · [[trinity]] · [[cet-research]] · [[cet-win10]] · [[query-shadow-stack]] · [[shadow-stack-walk]] · [[cet-spoofing-detection]] · [[dma]] · [[iommu]] · [[present-hook]] · [[hook-buster]] · [[hook-detector]] · [[hookhunter]] · [[patch-finder]] · [[integrity-experiments]] · [[integrity]] · [[memory-guard]] · [[ghostbusters]] · [[weird-anti-cheat-ideas]] · [[aho-corasick]] · [[xmalhunter]] · [[byfron-bypass]] · [[vac3-inhibitor]] · [[vac3-dumper]] · [[vac-module-dumper]] · [[vac-dumper]] · [[dumpvac]] · [[vacation3-emu]] · [[vac-emulator]] · [[prevent-vac]] · [[vackeyretrieval]] · [[vook]] · [[vac-hooks]] · [[vac-bypass]] · [[como-funciona-vac]] · [[unmapper]] · [[fix-arxan]] · [[android-unpacker]] · [[pandora]] · [[kiroshi]] · [[anti-cheat-amateur]] · [[ricochet-deobfuscator]] · [[aurum-re]] · [[ricochet-disabler]] · [[x14-08-coverstory-blizzard]] · [[xigncode3-blackdesert]] · [[xign-poc-april-2026]] · [[xigncode3-bypass-alternative]] · [[xigncode3-bypass]] · [[waryasswhe]] · [[veh]] · [[veh-dumper]] · [[no-access-protection]] · [[no-access-protection-x86]] · [[bincon]] · [[veh-hide-memory]] · [[veh-printf-hook]] · [[custom-veh]] · [[page-no-access]] · [[voidmaw]] · [[pghooker]] · [[deepsleep]] · [[shellcode-fluctuation]] · [[memory-relocalloc]] · [[death-sleep]] · [[file-recovery-tool]] · [[ntfstool]] · [[ntfs-linker]] · [[usn]] · [[ntfs-journal-viewer]] · [[searchex]] · [[dfirtriage]] · [[pwf]] · [[volatile-data-collector]] · [[netview]] · [[pillager]] · [[vmkatz]] · [[hv]] · [[ophion]] · [[hypervisor]] · [[minivisorpkg]] · [[checkhv-um]] · [[hypervisor-detection]] · [[hv-detect]] · [[go-detection-hyper-v]] · [[detection-hyper-v]] · [[ept-hook-detection]] · [[ermsb-meme]] · [[rep-mov-ept-detecc]] · [[vmdtstr]] · [[hvdetecc]] · [[vt-debuuger]] · [[baresvm]] · [[aether-visor]] · [[proxmox-ve-anti-detection]] · [[qemu-anti-detection]] · [[qemu-patched]] · [[hardened-qemu]] · [[hypervisor-phantom]] · [[vmware-hardened-loader]] · [[anticuckoo]] · [[makin]] · [[anti-debugging]] · [[adbg]] · [[umium]] · [[page-no-access]] · [[ttd-anti-debugging]] · [[blackhat2012]] · [[hint-break]] · [[awesome-anti-virtualization]] · [[vmaware]] · [[conbeerlib]] · [[anti-emulator]] · [[android-emulator-detection]] · [[shredder-rs]] · [[beatrice-py]] · [[r2morph]] · [[csgosimple]] · [[osiris]] · [[osiris-and-extra]] · [[dainsleif]] · [[sensum]] · [[gamesneeze]] · [[csgo-linux-cheat-sdk]] · [[heck-csgo-external]] · [[csgo-cheat-external]] · [[csgo-backtrack-patch]] · [[lumina-cheat]] · [[static-variables-obfuscator-ue4]] · [[usecurity]] · [[pe32-password]] · [[packer]] · [[packer-tutorial]] · [[huan]] · [[x64-exe-packer]] · [[pepacker]] · [[exe-packer]] · [[2pack]] · [[oxide]] · [[shibari]] · [[woody-woodpacker]] · [[elfpacker]] · [[elfcrypt]] · [[papaw]] · [[midgetpack]] · [[ward]] · [[embuche]] · [[elfuck]] · [[m0dern-p4cker]] · [[petoy]] · [[greym]] · [[pezor]] · [[xorpacker]] · [[hxor-packer]] · [[die-engine-web]] · [[kagura]] · [[the-poor-mans-obfuscator]] · [[dprotect]] · [[nmmp]] · [[obscura]] · [[wprotect]] · [[wprotectsdk]] · [[furikuri]] · [[rel-fuscate]] · [[relocbonus]] · [[obfuscar]] · [[obfuscation-methods]] · [[alcatraz]] · [[perses]] · [[milfuscator]] · [[nocturne]] · [[riscy-workshop]] · [[binprotect]] · [[stitch]] · [[compiled-protection]] · [[android-native-import-hide]] · [[vxlang-page]] · [[obfusk8]] · [[sbox]] · [[xorstr]] · [[mystic-xorstr]] · [[obfuscxx]] · [[polymorphic-engine]] · [[skcrypter]] · [[xorlit]] · [[obfuscatxor]] · [[garble]] · [[swift-string-obfuscator]] · [[syscalls-cpp]] · [[inline-syscall]] · [[doom-syscalls]] · [[ebyte-syscalls]] · [[kli]] · [[higu-ntcall]] · [[bloatedhammer]] · [[encrypted-value]] · [[xor-float]] · [[e3]] · [[obfcoder]] · [[javascript-obfuscator]] · [[lua-obfuscator-clyde-protection]] · [[blindeye]] · [[be-shellcode]] · [[battleye-region-walking]] · [[arma3beclient]] · [[scfw]] · [[byvalver]] · [[injdrv]] · [[kinject]] · [[kptnhook]] · [[detoursnt]] · [[polyhook]] · [[polyhook-2-0]] · [[ilhook-rs]] · [[lsass-extend-mapper]] · [[revert-mapper]] · [[nullmap]] · [[known-driver-mappers]] · [[kdmapper]] · [[kdmapper-rs]] · [[saturn-mapper]] · [[etw-explorer]] · [[etw-watcher]] · [[bamboozledr]] · [[disable-threat-tracing]] · [[tietwagent]] · [[threat-intelligence-consumer]] · [[fibratus]] · [[openprocmon]] · [[kernelmon]] · [[readdirectorychanges]] · [[minivers]] · [[tracee]] · [[wazuh]] · [[certael]] · [[sentinelac]] · [[no-mercy]] · [[anti-cheat]] · [[ice9]] · [[magnetite]] · [[wellsanticheat]] · [[banmod]] · [[open.mp-anticheat]] · [[mtasa-blue]] · [[oomph]] · [[avaanticheat]] · [[arrow-anticheat]] · [[minecraft-anticheatai]] · [[windfall-anticheatf]] · [[ycbr-anticheat]] · [[local-anticheat-1-8-9]] · [[model-anti-cheat]] · [[advanced-anticheat]] · [[encryptic-roblox-anti-cheat]] · [[ponytail-risk]] · [[mj-lnir]] · [[palworld-anti-cheat]] · [[palanticheat-poc]] · [[anticheat-poc]] · [[basic-anti-cheat]] · [[d-process]] · [[darken-anticheat]] · [[lockfile-poc]] · [[cheat-driver]] · [[anti-cheat-testing-framework]] · [[anti-cheat-testbench]] · [[quack]] · [[bevy-personal-test]] · [[lightyear]] · [[spark-engine]] · [[faultline]] · [[cveac-2020]] · [[instrumentation-callback-syscall-logger]] · [[hooking-via-instrumentation-callback]] · [[etwti-syscall-hook]] · [[hidden-syscall-monitoring]] · [[function-collections]] · [[injectors]] · [[windows-process-injection]] · [[modexmap]] · [[shtreeba]] · [[positron]] · [[windows-dll-hijacking]] · [[hijacklibs]] · [[dllirant]] · [[impulsive-dll-hijack]] · [[super-dll-hijack]] · [[mini-launcher]] · [[a-pasted-rust-script]] · [[zero-thread-kernel]] · [[covert-thread]] · [[kernel-codecave-poc]] · [[wdutf]] · [[crossover-patcher]] · [[holodori-kernel-bypass]] · [[nvidiaapi]] · [[nvidia-gpu-spoof]] · [[detect-tpm-spoofing]] · [[tpm-spoofer]] · [[tpm-mmio]] · [[spoofer-amidewin]] · [[hwidspoofer]] · [[hwid-spoofer-for-fortnite-and-valorant]] · [[wizard101-spoofer]] · [[hwid-spoofer]] · [[hwid-spoofer-eac-be]] · [[hwid-eclipsed-spoofer-eac-be]] · [[hwid-kernel-spoofer]] · [[hwid-permanent-hwid-spoofer]] · [[full-hwid-spoofer-v6]] · [[hwid-pasted-hwid-spoofer]] · [[hwid-spoofer-ud-fortnite-warzone-apex-rust-escape-from-tarkov-and-all-eac-be-games-imgui-loader-base]] · [[imgui-spoofer-leaked]] · [[hwid-spoofer-eac]] · [[theordernarkoz-hwid-spoofer]] · [[hwid-steam-spyware-terminator]] · [[precision-spoofer-cpp]] · [[hdd-serial-spoofer]] · [[skotschia-hwid-spoofer]] · [[windows-spoofer]] · [[windows-hardware-info]] · [[hwid-checker-mg]] · [[openhardwaremonitor]] · [[libre-hardware-monitor]] · [[hwinfo]] · [[query-gpu-name-rs]] · [[osx-cpu-temp]] · [[return-address-spoofer]] · [[loudsunrun]] · [[nocturneldr]] · [[cedetector]] · [[scyllahidedetector2]] · [[magisk]] · [[magiskdetector]] · [[detection]] · [[android-native-root-detector]] · [[keyattestation]] · [[keybuster]] · [[droidshield]] · [[antifrida]] · [[free-rasp-android]] · [[free-rasp-ios]] · [[free-rasp-unity-poc]] · [[com-sipvlib-anticheat]] · [[free-rasp-reactnative]] · [[free-rasp-capacitor]] · [[free-rasp-cordova]] · [[free-rasp-flutter]] · [[free-rasp-kmp]] · [[trustdevice-android]] · [[trustdevice-ios]] · [[waldo]] · [[osanticheat]] · [[cs2-tracker]] · [[cs2ac]] · [[anticheatsystem]] · [[sac-the-server-anticheat]] · [[cs2guard]] · [[deepaimdetector]] · [[aimbot-detection-prototype]] · [[r6-intel]] · [[delbot-mouse]] · [[laneguard]] · [[dlac]] · [[mousedetection]] · [[etw-keyboard-detection]] · [[human-mouse-movement]] · [[windmouse]] · [[pine]] · [[maplestory-worlds-automation]] · [[genshin-cheat]] · [[genshin-impact-script]] **Minecraft catalog:** Cross-platform anticheat index [[minecraft-anticheat-list]] (Kotlin/JS + Gradle; hundreds of validated JSON entries; searchable platform/version/pricing/maintenance table; GitHub + Spigot API enrichment; Bukkit/Sponge/Fabric/Forge/Nukkit/PocketMine; Java + Bedrock) for server operators and AC researchers comparing server-side cheat detection. (source: wiki/sources/descriptions/ManInMyVan__Minecraft-Anticheat-List.md) **Paper/Spigot movement simulation AC:** [[grim]] (GrimAnticheat; Java/Kotlin; open-source Minecraft anticheat for modern server versions and protocol combinations; detailed movement simulation, world replication, latency-aware validation; heavily asynchronous multithreaded architecture to scale checks and reduce false positives; server-side cheat detection for actively maintained Java communities; Anti Cheat / game:minecraft). (source: wiki/sources/descriptions/GrimAnticheat__Grim.md) **Version-neutral AC foundation:** [[inertia]] (InertiaOrg; Java; version-neutral player-behavior engine; movement/packet/world/collision contracts, evidence accumulation with confidence/decay and false-positive context; version profiles + movement-prediction skeleton; `inertia-api`/`inertia-core`/`inertia-testkit`; scenario tests without live server; Anti Cheat / game:minecraft). (source: wiki/sources/descriptions/InertiaOrg__Inertia.md) **Fabric mod/resource-pack whitelist AC:** [[faircount]] (XuJun05; Java Fabric mod; join-time client mod inventory incl. nested jar-in-jar; SHA-256 hash verification against server whitelists; disconnects clients missing FairCount or carrying unauthorized mods; external resource-pack whitelist/hash checks; auto-permits Fabric API modules; admin commands + localized kick messages; Anti Cheat / game:minecraft) for competitive PvP and vanilla-fair hosts beside hash-tier mods such as [[seiun-ac]]. (source: wiki/sources/descriptions/XuJun05__FairCount.md) **Fabric client+server AC:** [[the-dreamers-guards]] (IamFriendly0242u; Java Fabric mod; encrypted join-time network payloads; mod blacklist scanning; progressive four-phase suspension; anti-evasion logout-bypass checks; operator kick/ban/pardon/trust commands; Discord webhook alerts; Anti Cheat / game:minecraft) for Fabric administrators needing combined client-integrity verification and automated server-side enforcement. (source: wiki/sources/descriptions/IamFriendly0242u__The-Dreamers-Guards.md) **NeoForge client+server mod integrity AC:** [[katapult-anticheat]] (Gitex68; Java NeoForge **1.21.1** mod; SHA-256 checksums on client mod JARs and resource packs against server whitelists; real-time join/reload pack monitoring incl. renamed X-ray textures; hot-reloadable config, whitelist regeneration, live re-validation commands; Gson whitelist management; Anti Cheat / game:minecraft) for NeoForge modded-server operators needing file-integrity enforcement beyond gameplay packet checks. (source: wiki/sources/descriptions/Gitex68__Katapult-AntiCheat.md) **Headless protocol stress testing:** [[ghostjoin]] (KuryCat; pure Python stdlib Minecraft Java client; connects and stays online without rendering; full modern login/configuration/play flow with compression and Keep Alive; protocol ~773–776; authorized anti-bot/anti-cheat probe tool for offline-mode servers you own or have permission to test; Anti Cheat / game:minecraft) complements server-side plugins indexed by [[minecraft-anticheat-list]] for evaluating bot-connection defenses. (source: wiki/sources/descriptions/KuryCat__GhostJoin.md) **Fabric client-side AC QA:** [[anticheat-qa]] (u8012146108-bit; Java Fabric **1.21.11** client mod; ClickGUI/HUD monitors for reach/movement/rotation/CPS/velocity/ping; ESP/tracers/FreeCam visualization; test simulator + Y-Level Probe for server-side data-stripping validation; observes and simulates detections without enabling cheats; Anti Cheat / Stress Testing / game:minecraft) for engineers validating server AC behavior from a dedicated QA client. (source: wiki/sources/descriptions/u8012146108-bit__anticheat-qa.md) **Kernel AC telemetry simulation:** [[anti-cheat-emulator]] (ApexLegendsUC; C++ kernel driver; system-thread/stack-trace/BigPool/PiDDB/dispatch-table/physical-memory-handle heuristics plus hypervisor/mapping checks; emulates practical anti-cheat telemetry pipelines for authorized researcher testing; Anti Cheat / Stress Testing / Driver Unit Test Framework) complements usermode testbenches such as [[anti-cheat-testbench]] and open-source kernel AC samples such as [[kernel-anti-cheat]]. (source: wiki/sources/descriptions/ApexLegendsUC__anti-cheat-emulator.md) **Kernel syscall fuzzing:** [[ntcall64]] (Windows NT x64 syscall fuzzer for ntoskrnl and optional win32k Shadow SSDT; randomized parameters, INI blacklists, per-syscall pass counts, LocalSystem elevation; kernel stability and vulnerability research; Anti Cheat / Driver Unit Test Framework) complements Application Verifier DynFault injection such as [[vfdynf]] and Go anti-cheat analysis workbenches such as [[kernforge]]. (source: wiki/sources/descriptions/hfiref0x__NtCall64.md) **Paper/Folia rule enforcement:** [[icuac]] (Lazyzouo; Java 21 Gradle; modular server-side command/inventory/combat integrity checks—blocked commands, tab-complete hiding, game-mode isolation, coordinate limits, death-drop control, banned materials, NBT/enchantment validation, stack/potion limits, end-crystal cooldowns; bilingual CN/EN; Folia-aware scheduling; SHA-256-verified updater; lightweight anti-abuse controls rather than full client-side AC; Anti Cheat / game:minecraft) for administrators needing transparent policy enforcement. (source: wiki/sources/descriptions/Lazyzouo__ICUAC.md) **Starfish Lua heuristic AC:** [[hexze-anticheat]] (Hexze; Cheater Detector; Lua Starfish plugin; configurable NoSlow/AutoBlock/Eagle/Scaffold/Tower/LagRange/NoBreakDelay checks; movement/equipment/animation/metadata/block-break timing; violation thresholds, alert cooldowns, optional sound alerts; staff monitoring for Minecraft-style worlds; Anti Cheat / game:minecraft) for Starfish server operators needing plugin-side cheat-pattern flagging. (source: wiki/sources/descriptions/Hexze__anticheat.md) **Nukkit Bedrock prediction AC:** [[ghost-anticheat]] (GhostNgEnd; Java Gradle Nukkit plugin; ECS architecture simulating BDS movement, collision, and physics; latency-compensated packet checks for phase, no-slow, anti-knockback, reach, hitbox abuse, invalid block breaking, elytra flight anomalies, bad packets, and multi-action violations; server-side cheat detection for Bedrock Nukkit operators; Anti Cheat / game:minecraft). (source: wiki/sources/descriptions/GhostNgEnd__Ghost-AntiCheat.md) **GeyserMC pre-translation Bedrock AC:** [[astrox-anticheat]] (Eangly99; Java Maven GeyserMC extension; intercepts raw Bedrock UDP/RakNet packets at the Netty channel layer before Java translation; sub-ms detection off main server tick; movement/combat/inventory/packet heuristics—reach, hitbox backtracking, flight, autoclicker, device spoofing, crash-packet firewall; Bedrock-native kinematics, input-mode-aware reach, latency backtracking, leaky-bucket timer; Discord webhooks + admin commands; Anti Cheat / game:minecraft) for GeyserMC operators beside MiTM proxies such as [[oomph]] and Nukkit prediction plugins such as [[ghost-anticheat]]. (source: wiki/sources/descriptions/Eangly99__AstroX-AntiCheat.md) **Bedrock behavior-pack ScriptAPI AC:** [[blarion-anticheat]] (StarBloomMinecraft; JavaScript Bedrock ScriptAPI behavior pack; 40+ real-time combat/movement/inventory/packet modules—fly, killaura, speed, reach, noclip, autoclicker, xray; configurable thresholds/punishments; admin inventory scan + `/flag` API for WebSocket/proxy integration; vanilla/BDS/LiteLoader worlds without server plugins; Anti Cheat / game:minecraft) for Bedrock world hosts beside behavior-pack addons such as [[paradox-anticheat]] and [[scythe-anticheat]]. (source: wiki/sources/descriptions/StarBloomMinecraft__BlarionAntiCheat.md) **Fabric server-side moderation AC:** [[cheatcheck]] (EliGamer154; Java Fabric **26.1.x** mod; `/cheatcheck` spectate menu + safemode stealth watching; freeze/vanish/inventory/radar staff tools; `/report` flags plus reach/x-ray-style ore mining/speed heuristics; configurable offense presets, temp bans, pardons, persistent world storage; no client mod required; vanilla-client-compatible enforcement for Fabric server administrators; Anti Cheat / game:minecraft). (source: wiki/sources/descriptions/EliGamer154__CheatCheck.md) **NeoForge server-side MC AC:** [[sentinel-anticheat-neoforge]] (Charlie328402; Java NeoForge mod; tick- and event-based movement/combat/world checks—speed, flight, water-walking, reach, killaura, autoclicker, x-ray mining—without mixins or packet interception; JSONL violation log + Python Discord bot with cumulative violation-level staff pings, relational DB history, optional FTP mirroring; alert-only, no automatic bans/kicks; Anti Cheat / game:minecraft) for NeoForge server operators beside integrity-focused mods such as [[katapult-anticheat]] and physics-prediction AC such as [[grim]]; distinct from HEEAAP [[sentinel-anti-cheat]] usermode daemon. (source: wiki/sources/descriptions/Charlie328402__Sentinel-Anti-Cheat.md) **PowerNukkitX Bedrock prediction AC:** [[amethyst]] (NaySurGithub; Java PowerNukkitX plugin; per-tick Bedrock physics replay from player input; compares simulated vs client-reported positions for unexplained movement rather than threshold-only speed checks; authoritative movement/vehicle simulation, client world-state acknowledgment gating, combat prediction with entity rewind; fly/reach/kill aura/scaffold/inventory/backtrack/malformed-packet checks; server-side movement correction and violation alerting; Anti Cheat / game:minecraft) for PowerNukkitX operators beside Nukkit prediction plugins such as [[ghost-anticheat]] and GeyserMC interceptors such as [[astrox-anticheat]]. (source: wiki/sources/descriptions/NaySurGithub__Amethyst.md) **Paper/Folia heuristic AC:** [[bs-anticheat]] (BoondockSulfur; Java Paper **1.21.10+** plugin; full Folia support; movement/combat/world-interaction/inventory/vehicle/packet checks—speed, fly, reach, killaura, nuker, autoclicker, x-ray mining; transaction-based lag compensation; configurable violation-level punishments with optional setbacks; SQLite logging; PacketEvents, Discord webhooks, PlaceholderAPI, and LuckPerms integrations; false-positive-conscious tunable heuristics for server administrators; Anti Cheat / game:minecraft) for Paper/Folia operators beside physics-prediction AC such as [[grim]] and alert-focused NeoForge mods such as [[sentinel-anticheat-neoforge]]. (source: wiki/sources/descriptions/BoondockSulfur__BS-AntiCheat.md) **Paper custom-SMP AC (Hyphon):** [[larping-anti-cheat]] (realkyx29-design; Java 21 Paper **1.21+** plugin; modular movement/combat/world checks—fly, speed, reach, kill aura, scaffold, fast break; server-authoritative physics snapshots; per-player violation tracking with decay; honeypot/ESP decoy entities + optional packet-layer fake bases; capability analyzer for custom modifiers/enchantments on modded SMP; low false-positive focus; server-side only; Anti Cheat / game:minecraft) for custom SMP operators beside heuristic Paper plugins such as [[bs-anticheat]] and physics-prediction AC such as [[grim]]. (source: wiki/sources/descriptions/realkyx29-design__LarpingAntiCheat.md) **Paper survival AC + anti-dupe:** [[ultimate-meteor-anticheat]] (EpicLizard05013; Java Paper **1.21.11** plugin; combat checks—reach, autoclicker, aim-modulo—plus movement fly/speed/nofall/jesus and world fastplace/scaffold modules; inventory transaction auditing, nested-container restrictions, and packet desync mitigation for common item-duplication vectors; configurable violation escalation with whitelisting, admin commands, and optional Discord webhooks; server-side cheat and exploit prevention for survival hosts; Anti Cheat / game:minecraft) beside heuristic Paper plugins such as [[bs-anticheat]] and custom-SMP plugins such as [[larping-anti-cheat]]. (source: wiki/sources/descriptions/EpicLizard05013__UltimateMeteorAntiCheat.md) **Paper freecam mitigation:** [[petal-anti-freecam]] (boggymc; Java Paper/CanvasMC **1.21** plugin; PacketEvents outgoing chunk masking; ChunkMasker replaces underground sections with air below configurable hide-Y for players above cutoff; tile-entity filtering; per-tick refresh budget; runtime reload; optional CanvasMC async teleport visibility listeners; server-side anti-freecam/wallhack without client mods; Anti Cheat / game:minecraft) for operators needing packet-layer terrain stripping beside investigation plugins such as [[antixrayviewer]] and QA clients such as [[anticheat-qa]]. (source: wiki/sources/descriptions/boggymc__PetalAntiFreecam.md) **Vintage Story server-side:** [[serverguard]] (trevorftp; C# Harmony server-networking patches; conceals enclosed ore + injects ore/creature decoys; server-side entity raycast filtering for occluded creatures/optional players; ModConfig tuning; `/serverguard` admin command; Open Source Anti Cheat System / game:vintage story) for Vintage Story hosts needing x-ray/wallhack mitigation without client mods beside Minecraft packet-layer plugins such as [[petal-anti-freecam]]. (source: wiki/sources/descriptions/trevorftp__ServerGuard.md) **Forge peer-mod detection:** [[crispy-wafer-anti-cheat-assistant-waferaca]] (sodium-CrispyWafer; Java Forge **1.20.1** client mod; server-cooperative FML mod-list extraction + custom network packets, or client-only aimbot heuristics from rotation smoothness/flick/tracking; public cheat alerts and per-player mod commands/key bindings; Open Source Anti Cheat System / game:minecraft) for Forge multiplayer operators needing lightweight peer cheat-mod visibility beside integrity mods such as [[katapult-anticheat]]. (source: wiki/sources/descriptions/sodium-CrispyWafer__CrispyWafer-Anti-Cheat-Assistant-WaferACA.md) **Cross-platform MC client AC:** [[pacc4-0]] (EPOTATOTV; PACC; Bedrock/Java player-side anti-cheat; on-device memory/process/HID inspection, Python AI behavior scoring, Rust signed event pipeline with encrypted persistence, full-screen red-screen warnings, remote PTV admin backend without game-server ban integration; native probes + kernel/agent modules on Windows/Linux/Android/iOS/HarmonyOS; Open Source Anti Cheat System / game:minecraft) for operators studying client-resident MC cheat deterrence beside server-side plugins such as [[grim]] and QA clients such as [[anticheat-qa]]. (source: wiki/sources/descriptions/EPOTATOTV__PACC4_0.md) **Android APK/game packer:** [[hyapk]] (beto2-dev; Kotlin CLI + C native runtime; per-method HyVm VMP or Dex2C, ChaCha20-Poly1305 opcode encryption, smali renaming, resource encryption, signature/dex integrity, anti-tamper/anti-debug, anti-Frida/root/emulator heuristics; Binary Packer / game protection) for studying mobile shielding cost beside [[obfuscapk]] and [[appsealing-reversal]] research. (source: wiki/sources/README-categories.md) (source: wiki/sources/descriptions/beto2-dev__Hyapk.md) **BONELAB LabFusion server-side:** [[fusion-anti-cheat]] (FusionGuard; C# MelonLoader .NET 6 mod; Harmony patches on LabFusion network actions—item spawn/despawn, teleport, avatar change, message floods; crash-barcode blocklist, rate limits, movement/score cheat detection, SteamID allow/deny lists, Discord webhooks, in-game admin panel; Open Source Anti Cheat System / game:bonelab) for BONELAB server hosts beside other title-specific server mods such as [[7dtd-anticheatmod]] and [[tshock]]. (source: wiki/sources/descriptions/irembo337__Fusion-AntiCheat.md) **Terraria server-side:** [[tshock]] (Pryaxis; C# .NET Terraria Server API plugin; **Bouncer** packet/action anti-cheat; permissions, regions, warps, item bans; SQLite/MySQL/PostgreSQL + REST + plugin system; protocol guards for known Terraria networking flaws; Open Source Anti Cheat System / game:terraria) for dedicated-host operators needing server-authoritative cheat prevention beside other title-specific server mods such as [[7dtd-anticheatmod]]. (source: wiki/sources/descriptions/Pryaxis__TShock.md) **Meteor Litematica printer (offensive):** [[dino-printer]] (Gingerbeard5773; Java Fabric Meteor Client addon; auto-builds Litematica schematics with BlockState property matching for stairs, slabs, and rotatable blocks; multi-point raytracing for line-of-sight placement checks; hack rotation; configurable delay/range/sneak/inventory; built from scratch to adapt placement timing to strict/anarchy server rules rather than bypass detection; cheat / game:minecraft) illustrates client-side automation that conforms to server placement validation targeted by scaffold/fast-break modules in plugins such as [[hexze-anticheat]], [[larping-anti-cheat]], and [[grim]]. (source: wiki/sources/descriptions/Gingerbeard5773__dino-printer.md) ## README map `Anti Cheat` (~734 links): guides (incl. [[rce-shield]] RCE hardening for launchers/mod loaders/overlays/peripherals + hawkeye-Leo/[[hawkeye]] Windows kernel AC research console (`!probe`, `!etw`, `!kernel_region`, `!analyze` scored reports) (source: wiki/sources/descriptions/hawkeye-Leo__hawkeye.md) + structured AC architecture / Windows kernel / VT-x·EPT / graphics-integrity research index xhscfq/anti-cheat-research-index + thexin7/kernel-cve-analysis defensive kernel CVE lane + Minecraft Java/Bedrock anticheat catalog [[minecraft-anticheat-list]] + [[are-we-anti-cheat-yet]] GNU/Linux/Wine/Proton AC compatibility tracking + IZxMD/[[ac-compat-research]] vendor-agnostic Linux kernel AC hosting feasibility study (LSM/signing/isolation/ABI; non-virtualized architecture dossier) (source: wiki/sources/descriptions/IZxMD__ac-compat-research.md) + LordeTyrael/[[pokealliance-anti-cheat-analysis]] PokeAlliance OTCv8 client audit), stress/unit-test harnesses (incl. [[anti-cheat-emulator]] kernel AC telemetry simulation + [[ntcall64]] NT x64 ntoskrnl/win32k syscall fuzzer (source: wiki/sources/descriptions/hfiref0x__NtCall64.md) + [[anticheat-qa]] Fabric MC AC QA client mod + [[ghostjoin]] headless protocol probe), packers (incl. ATsahikian/[[pe-protector]] x86 instruction-mutation PE protection framework), page/CLR protection, encrypt-variable / lazy-importer tricks (incl. [[noimportz]] kernel zero-IAT LSTAR→ntoskrnl walk + PsLoadedModuleList export resolve; Th3Spl + [[zeroimport]] ntoskrnl hash export walk without cleartext API strings; 1hAck-0), obfuscation engines, open-source / analysis-framework AC samples (incl. [[blc-gamesec-lab]] authorized validation/regression orchestration + [[void-engine]] Godot 4.x WhiteVoid AntiCheat plugin + [[dot-server-security]] Godot 4 dedicated-server rule-engine AC + [[shinobix]] browser MMORPG server-authoritative auth/reward-integrity patterns with debugger/process/window detection, honeypot integrity checks, and HWID ban enforcement + [[cobra-snake]] web Snake HMAC game sessions, score plausibility checks, and rate-limited leaderboard submission AC (Anti-Cheat Programming) + hybrid CS2-style proposals with Glicko-2 judge ratings, honeypot entities, and shadow monitoring; [[cs2guard]] ML behavioral CS2 demo parsing/feature engineering toward server-side AC (source: wiki/sources/descriptions/Driw0x__CS2Guard.md); Paper/Folia heuristic MC plugins such as [[bs-anticheat]] + [[ultimate-meteor-anticheat]] Paper 1.21.11 survival AC/anti-dupe + [[petal-anti-freecam]] chunk-packet freecam masking + [[serverguard]] Vintage Story ore/entity decoy + raycast filtering + Terraria server-side [[tshock]] Bouncer + Linux kernel AC research such as [[linux-anticheat]] + FiveM server-side Lua resources such as [[dead-anticheat]] + offline PC-check tooling such as [[aeterna-rongroi]] (Rust/Tauri; YAML rules engine; Found/NotFound/Unmeasured cheat-trace evidence without clean/guilty verdicts; screenshare self-check) (source: wiki/sources/descriptions/aeterna__aeterna-rongroi.md) + consensual MC Java screenshare workflow NotSkrib/[[error-pc-check]] (signed C# client agent + React staff panel + Supabase; forensic collectors + correlation engine; severity-ranked human-review reports) (source: wiki/sources/descriptions/NotSkrib__error-pc-check.md) + [[fusion-anti-cheat]] server-side LabFusion/BONELAB MelonLoader AC (source: wiki/sources/descriptions/irembo337__Fusion-AntiCheat.md), engine protection (Unreal/Unity/Source), and a wide `Detection:*` tree (hook, memory integrity, shellcode, attach, triggerbot & aimbot, hide, vulnerable driver, hacked hypervisor, virtual environments, HWID, speedhack, injection, stack spoof, ESP, DMA, wall hack, obfuscation, Android root (incl. SloMR/[[rootect]] zero-dependency Android RASP with native syscall probes, Frida/Xposed/repack/emulator evidence, and optional Key Attestation); plus Screenshot incl. TheCruZ/nvidiaCapture NVIDIA scanout via undocumented `NvAPI_D3D11_WksReadScanout` below usermode Present/BitBlt hooks (source: wiki/sources/descriptions/TheCruZ__nvidiaCapture.md) + vmguard/dwm-window-capture focused-window capture via DWM redirect surfaces and D3D11 staging readback (source: wiki/sources/descriptions/vmguard__dwm-window-capture.md)). Cross-links `Windows Security Features` (~10; CET/TPM/IOMMU/HVCI attestation), Cheat (~2811) PatchGuard/DSE + Launcher Abuser + QEMU/KVM/PVE/VBOX lanes (incl. lsxll666/AntiCheatToggle — ACE/Perfect World kernel drivers blocking VirtualBox VERR_INVALID_NAME (-104); temporary driver disable with restore; virtualization-lab troubleshooting) (source: wiki/sources/README-categories.md) (source: wiki/sources/descriptions/lsxll666__AntiCheatToggle.md), adjacent `Game Tools` (~8; RCE hardening for PC gamers such as [[rce-shield]] — detect/prevent/remediate RCE in launchers, mod loaders, overlays, voice chat, and peripherals) (source: wiki/sources/descriptions/bad-antics__rce-shield.md), `Game Testing` (~19; high-PC-uptime sandbox signals such as [[uptime-faker]] (CookiePLMonster; Detours timing hooks; INI-configured uptime/timer API redirection; diagnose high-uptime game bugs + AC uptime-signal testing) (source: wiki/sources/descriptions/CookiePLMonster__UptimeFaker.md)), and `Windows Emulator` (~7; user-space + WHP trap-driven guests + hybrid KDemu kernel-driver stacks for AC analysis). (source: wiki/sources/README-categories.md)