Guide for reverse engineering protected games and anti-cheat components across user mode, kernel mode, and hypervisor-aware environments. Use this skill when analyzing drivers, IOCTL protocols, callback registration, injected-code artifacts, integrity checks, protected binaries, or debugging security-sensitive game components.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
Guide for reverse engineering protected games and anti-cheat components across user mode, kernel mode, and hypervisor-aware environments. Use this skill when analyzing drivers, IOCTL protocols, callback registration, injected-code artifacts, integrity checks, protected binaries, or debugging security-sensitive game components.
Reverse Engineering Tools & Techniques
Overview
This skill covers reverse engineering workflows for game security research, including protected game clients, anti-cheat user-mode modules, kernel drivers, memory artifacts, and debugging environments that must survive anti-analysis checks.
Treat performance, stealth, coverage, and compatibility claims as
target/version-specific. Record the binary hash, tool version, configuration,
environment, and observed evidence; use
research-rigor for consequential conclusions.
README Coverage
Cheat > Debugging
Cheat > RE Tools
Cheat > Mixed boolean-arithmetic
Cheat > Dynamic Binary Instrumentation
Cheat > Fix VMP
Cheat > Fix Themida
Cheat > Fix OLLVM
Cheat > Virtual Environments
Cheat > Decompiler
Cheat > IDA themes
Cheat > IDA Plugins
Cheat > IDA Signature Database
Cheat > Binary Ninja Plugins
Cheat > Ghidra Plugins
Cheat > Radare Plugins
Cheat > Windbg Plugins
Cheat > X64DBG Plugins
Cheat > Cheat Engine Plugins
Cheat > ROP Finder
Cheat > ROP Generation
Anti Cheat > Anti Debugging
Anti Cheat > Anti Disassembly
Anti Cheat > Dump Fix
Anti Cheat > Sample Unpacker
Anti Cheat > Obfuscation Engine
Anti Cheat > Winows User Dump Analysis
Anti Cheat > Winows Kernel Dump Analysis
Debugging Tools
Windows Debuggers
Cheat Engine: Memory scanner and debugger for games
x64dbg: Open-source x86/x64 debugger
WinDbg: Microsoft's kernel/user-mode debugger
ReClass.NET: Memory structure reconstruction
HyperDbg: Hypervisor-based debugger
Specialized Debuggers
CE Mono Helper: Unity/Mono game debugging
dnSpy: .NET assembly debugger/decompiler
ILSpy: .NET decompiler
frida: Dynamic instrumentation toolkit
Platform-Specific
edb-debugger: Linux debugger
PINCE: Linux game hacking tool
H5GG: iOS cheat engine
Hardware Breakpoint Tools: HWBP implementations
Disassembly & Decompilation
Multi-Platform
IDA Pro: Industry standard disassembler
Ghidra: NSA's reverse engineering framework
Binary Ninja: Modern RE platform
Cutter: Radare2 GUI
Specialized Tools
IL2CPP Dumper: Unity IL2CPP analysis
dnSpy: .NET/Unity decompilation
jadx: Android DEX decompiler
Recaf: Java bytecode editor
Memory Analysis
Memory Scanners
- Cheat Engine: Pattern scanning, value searching
- ReClass.NET: Structure reconstruction
- Process Hacker: System analysis
Dump Tools
- KsDumper: Kernel-space process dumping
- PE-bear: PE file analysis
- ImHex: Hex editor for RE
Concept:
- Replace branch instructions with fault-generating sentinel opcodes
- Catch the resulting exception → emulate the original branch → log → resume
- Full cycle: patch → fault → capture → emulate → record → restore → continue
Sentinel Selection:
- HLT (0xF4) for ret → triggers STATUS_PRIVILEGED_INSTRUCTION
- SALC (0xD6) for jmp/jcc/call → triggers STATUS_ILLEGAL_INSTRUCTION
- Avoids INT3 (0xCC) which anti-debug/integrity checks commonly scan for
- Different sentinels can multiplex branch types
Exception Capture:
- Hooking KiUserExceptionDispatcher can avoid some higher-level VEH/SEH
dispatch overhead, but latency, stability, and detectability must be measured
on the target Windows build
- Assembly stub tail-calls into RtlDispatchException
- Handler dispatches by exception code to custom emulation logic
Branch Emulation Engine:
- Disassemble original (pre-patch) instruction at fault RIP
- jcc: 16-condition lookup table (ZF, SF, CF, OF, PF combinations)
- Direct call: push return address, update RIP
- Indirect branch: resolve effective address (register, memory, SIB, RIP-relative)
- ret: pop return address from stack, handle ret imm16 (extra pop)
- loop/jrcxz: decrement RCX, conditional branch
Instrumentation Strategies:
- Bounded Bulk Patching: scan a window from seed address, patch all branches
→ Simple but detectable by integrity checks
- Branch Chasing: patch only current branch, re-instrument at target on fault
→ Smaller patch footprint, with coverage, race, and detectability tradeoffs
- CFG-Guided Patching: recursive-descent static CFG + chasing for unreached edges
→ Best coverage/safety balance
Integrity Check Evasion:
- PAGE_GUARD + Trap Flag (single-step) instead of direct code patching
- Trigger guard page exception → set TF → single-step through original instruction
- Avoids directly modifying `.text`, but guard state, exception rate, debug
state, and timing can still be detected
Control Flow Tracing (CFT) Applications
- Runtime call graph generation with register context at each edge
- Divergence testing: compare traces across different inputs/environments
→ Quickly locates input validation, anti-debug, anti-tamper trigger points
- Deobfuscation: resolve indirect branches observed under covered executions;
completeness requires additional path exploration or proof
- Hot path analysis, branch coverage measurement
- Exception-per-branch designs can be orders of magnitude slower; benchmark the
exact target and account for timing checks and session timeouts
- Portable to other architectures: ARM (UDF), RISC-V (illegal instruction)
User-Mode Hypervisor-Assisted Tracing
Concept:
- Use Windows Hypervisor Platform (WHP) API to run guest code in user mode
- No kernel driver required — standard user-mode process hosts the hypervisor
- Map host memory pages into guest address space
- Configure page-level traps (read/write/execute permissions per page)
- Guest execution triggers VM exits on configured events
Trap-Driven Execution:
- Page fault traps: set per-page R/W/X permissions via EPT-equivalent API
→ Execute fault = code coverage, Write fault = memory write monitoring
→ Read fault = data access tracking
- CPUID interception: guest executes CPUID → VM exit → host decides response
→ Useful for fingerprinting guest environment queries
- Syscall interception: guest executes syscall → VM exit → host emulates
→ Controlled experiments without real kernel interaction
Workflow:
1. Prepare initial CPU state (registers, segments, control registers)
2. Map target code + data pages with desired permissions
3. Enter guest execution loop
4. On VM exit: inspect reason, handle trap, optionally modify state
5. Resume or terminate guest
Advantages:
- Pure user-mode: no driver signing, no PatchGuard concerns
- Controlled: host controls modeled guest memory and CPU state; external timing,
concurrency, devices, and unmodeled OS behavior can introduce nondeterminism
- Composable: combine with disassemblers/emulators for hybrid analysis
- Debuggable: host process can be debugged normally
Limitations:
- Requires hardware virtualization support (VT-x/AMD-V)
- Windows-specific (WHP API is Windows 10+)
- The lightweight workflow described here is suited to snippets/functions;
booting a full OS is possible only with substantially more platform and device
modeling
- Nested virtualization considerations when host is already a VM
Anti-Analysis Bypass
Techniques
Anti-debug detection bypass
VM/Sandbox evasion
Timing attack mitigation
PatchGuard circumvention
Tools
TitanHide: Anti-debug hiding
HyperHide: Hypervisor-based hiding
ScyllaHide: Anti-anti-debug plugin
Game-Specific Analysis
Unity Games
Locate GameAssembly.dll (IL2CPP) or managed DLLs
Use IL2CPP Dumper for structure recovery
Apply dnSpy for Mono games
Hook via Unity-specific frameworks
Unreal Engine Games
Identify UE version from signatures
Use SDK generators (Dumper-7)
Analyze Blueprint bytecode
Hook UObject/UFunction systems
Native Games
Standard PE analysis
Import/export reconstruction
Pattern scanning for signatures
Runtime memory analysis
Workflow Best Practices
Initial Analysis
1. Identify protections (packer, obfuscator, anti-cheat)
2. Determine game engine and version
3. Collect symbol information if available
4. Map out key modules, callbacks, and trust boundaries
The README's MCP server section and RE tool ecosystem now include
AI-assisted reverse engineering through Model Context Protocol:
- IDA MCP: AI agent controls IDA Pro (rename, annotate, navigate)
- Ghidra MCP: AI agent queries Ghidra decompilation and PCODE
- Binary Ninja MCP: AI agent interacts with Binary Ninja API
- radare2 MCP: AI agent drives r2 sessions via r2pipe
- x64dbg MCP: AI agent controls live debugging sessions
Workflow: LLM ↔ MCP server ↔ RE tool, enabling natural-language
queries like "find all functions calling CreateRemoteThread" or
"rename this function based on its decompiled logic"
Binary Diffing
Tools for comparing binary versions (patch analysis, vulnerability research):
- BinDiff (Google): graph-based structural comparison
- Diaphora: IDA plugin, best open-source binary diff
- ghidriff: Ghidra-based diffing, command-line and scriptable
- DarunGrim: patch analysis focused differ
- turbodiff: lightweight IDA diffing plugin
Use cases in game security:
- Tracking anti-cheat driver updates between versions
- Identifying patched vulnerabilities in game clients
- Comparing obfuscated builds to isolate logic changes
The main README contains thousands of curated links organized by category. When users ask for specific tools, projects, or implementations, retrieve and reference the appropriate sections from this source.
2. Repository Code Details (Archive)
For detailed repository information (file structure, source code, implementation details), the project maintains a local archive. If a repository has been archived, always prefer fetching from the archive over cloning or browsing GitHub directly.
Identify the GitHub repository the user is asking about (owner and repo name from the URL).
Construct the description URL: replace {owner} with the GitHub username/org and {repo} with the repository name.
Fetch the description file — it contains a short, human-readable summary of the repository's purpose and contents.
If the fetch returns a 404, the description has not been generated yet; fall back to the README entry or the archive.
Priority order when answering questions about a specific repository:
Description (quick summary) — fetch first for concise context
Archive (full code snapshot) — fetch when deeper implementation details are needed
README entry — fallback when neither description nor archive is available
Compiled wiki
Prefer the compiled domain overview at wiki/overviews/reverse-engineering.md (see wiki/index.md and wiki/AGENTS.md) before re-deriving synthesis from raw README/archive material.