Forensic Security Suite

Beyond Mod Analysis

Audit AC combines mod integrity scanning with deep system forensics — detecting cheats at every layer from file hashes to running processes, network adapters, and environment fingerprinting.

12
Detection Layers
5
System Checks
20+
VPN Signatures
Modrinth Coverage
Core

Mod Integrity Analysis

Compares SHA-1 file hashes and sizes against the official Modrinth API and a Megabase cross-reference. Instantly flags verified, tampered, unknown, cheat, and disallowed mods with source attribution.

Critical

JVM Injection Scanning

Inspects live Java Virtual Machine launch arguments across all running Java processes to detect memory injection, unauthorized agents, and ghost client loaders that bypass standard file-based checks.

New

Post-Launch Mod Timestamps

Compares every mod's last-write timestamp against the Minecraft process start time. If any .jar was added or replaced after the game launched, it's immediately flagged as a potential runtime injection.

New

DNS Cache Analysis

Runs ipconfig /displaydns and scans the local DNS resolver cache for known cheat client domains — including Vape, LiquidBounce, Future, Aristois, and 15+ others — revealing prior connections even if software is removed.

New

JNativeHook Detection

Searches temp directories for the JNativeHook DLL/SO, a global keyboard/mouse hooking library used by many cheat clients for macro recording and key-detection bypass. Also checks if it's loaded inside the Minecraft process.

New

Virtual Machine Detection

Queries WMI (Windows) or /sys/class/dmi (Linux) to detect virtualisation indicators across BIOS, GPU, system model, and running service processes — flagging VirtualBox, VMware, Hyper-V, KVM, QEMU, Xen, and Parallels.

New

VPN Detection

Detects active VPN usage via three independent signals: running VPN service processes (NordVPN, ProtonVPN, OpenVPN, etc.), connected network adapters with real inbound/outbound traffic, and public IP cross-referenced against the X4BNet VPN IP database.

Core

Forensic String Extraction

Extracts and deep-scans ASCII and Unicode strings from unknown JAR files, matching against thousands of known cheat signatures, webhook endpoints, obfuscation markers, and malicious Discord invite patterns.

Core

Disallowed Mod Policy

A curated server-policy blocklist flags mods that are not explicitly cheat clients but are banned from competitive play — including X-ray minimaps, freecam, health indicators, and crystal auto-placers.

Performance

Parallelized Scan Engine

The Java client runs mod scanning, API lookups, and system checks concurrently using multi-threaded workers. The entire scan — including Modrinth resolution for 50+ mods — completes in seconds, not minutes.

Security

Obfuscated & Protected Scanner

The PowerShell scanner is AES-256-CBC encrypted and GZip compressed before distribution. Cheat clients cannot read or bypass the scanner logic by inspecting the payload served from the API endpoint.

Core

Secure Session Syncing

One-time 6-digit PIN codes tie each scan result to its authorized staff session. Report telemetry is routed exclusively to the requesting dashboard and expires automatically — no persistent data leakage.

Ready to run a scan?

Launch Audit AC