Beyond Mod Analysis
Audit AC combines mod integrity scanning with deep system forensics — detecting cheats at every layer from file hashes to running processes, network adapters, and environment fingerprinting.
Mod Integrity Analysis
Compares SHA-1 file hashes and sizes against the official Modrinth API and a Megabase cross-reference. Instantly flags verified, tampered, unknown, cheat, and disallowed mods with source attribution.
JVM Injection Scanning
Inspects live Java Virtual Machine launch arguments across all running Java processes to detect memory injection, unauthorized agents, and ghost client loaders that bypass standard file-based checks.
Post-Launch Mod Timestamps
Compares every mod's last-write timestamp against the Minecraft process start time. If any .jar was added or replaced after the game launched, it's immediately flagged as a potential runtime injection.
DNS Cache Analysis
Runs ipconfig /displaydns and scans the local DNS resolver cache for known cheat client domains — including Vape, LiquidBounce, Future, Aristois, and 15+ others — revealing prior connections even if software is removed.
JNativeHook Detection
Searches temp directories for the JNativeHook DLL/SO, a global keyboard/mouse hooking library used by many cheat clients for macro recording and key-detection bypass. Also checks if it's loaded inside the Minecraft process.
Virtual Machine Detection
Queries WMI (Windows) or /sys/class/dmi (Linux) to detect virtualisation indicators across BIOS, GPU, system model, and running service processes — flagging VirtualBox, VMware, Hyper-V, KVM, QEMU, Xen, and Parallels.
VPN Detection
Detects active VPN usage via three independent signals: running VPN service processes (NordVPN, ProtonVPN, OpenVPN, etc.), connected network adapters with real inbound/outbound traffic, and public IP cross-referenced against the X4BNet VPN IP database.
Forensic String Extraction
Extracts and deep-scans ASCII and Unicode strings from unknown JAR files, matching against thousands of known cheat signatures, webhook endpoints, obfuscation markers, and malicious Discord invite patterns.
Disallowed Mod Policy
A curated server-policy blocklist flags mods that are not explicitly cheat clients but are banned from competitive play — including X-ray minimaps, freecam, health indicators, and crystal auto-placers.
Parallelized Scan Engine
The Java client runs mod scanning, API lookups, and system checks concurrently using multi-threaded workers. The entire scan — including Modrinth resolution for 50+ mods — completes in seconds, not minutes.
Obfuscated & Protected Scanner
The PowerShell scanner is AES-256-CBC encrypted and GZip compressed before distribution. Cheat clients cannot read or bypass the scanner logic by inspecting the payload served from the API endpoint.
Secure Session Syncing
One-time 6-digit PIN codes tie each scan result to its authorized staff session. Report telemetry is routed exclusively to the requesting dashboard and expires automatically — no persistent data leakage.
Ready to run a scan?
Launch Audit AC