Home

Awesome

chrysalis

A small client-side user-mode anti-cheat.

DETECTION WISHLIST


SECURITY WISHLIST


DESIGN WISHLIST


HOOK CANDIDATES


[game] hk_BaseThreadInitThunk (Kernel32ThreadInitThunkFunction - ntdll.dll)
[game] hk_D3DXCreateFontA (EAT Hook)
[game] hk_D3DXCreateFontIndirectA (EAT Hook)
[game] hk_D3DXCreateSprite (EAT Hook)
[game] hk_D3DXCreateTextureFromFileInMemory (EAT Hook)
[game] hk_D3DXCreateTextureFromFileInMemoryEx (EAT Hook)
[game] hk_D3DXLoadSurfaceFromMemory (EAT Hook)
[game] hk_Dllmain_mono_dll (Inline Hook)
[game?] hk_LoadAppInitDlls (Inline Hook)
[game? or suspected injector?] hk_LoadLibraryExW_user32 (IAT Hook - user32.dll)
[game? or suspected injector?] hk_LoadLibraryExW_ws2_32 (IAT Hook - ws2_32.dll)
[?] hk_LockResource_kernel32 (IAT Hook - kernel32.dll)
[suspected cheat process] hk_NtCreateFile_kernelbase (IAT Hook - kernelbase.dll)
[suspected cheat process] hk_NtDeviceIoControlFile_mswsock (IAT Hook - mswsock.dll)
[suspected cheat process] hk_NtOpenFile_kernelbase (IAT Hook - kernelbase.dll)
[game & suspected cheat process] hk_NtProtectVirtualMemory_kernelbase (IAT Hook - kernelbase.dll)
[?] hk_NtQueryDirectoryFile_kernelbase (IAT Hook - kernelbase.dll)
[game] hk_NtUserGetAsyncKeyState_user32 (IAT Hook - user32.dll)
[suspected cheat process & game?] hk_NtUserSendInput_user32 (IAT Hook - user32.dll)
[?] hk_QueryPerformanceCounter (IAT Hook - game.exe)
[?] hk_RtlExitUserProcess_kernel32 (IAT Hook - kernel32.dll)
[game & suspected cheat process?] hk_VirtualAlloc_iat_kernel32 (IAT Hook - kernel32.dll)