Memory, read the hard way
Javaw heap sweeps, injected-module listings, executable paths pulled out of service process memory — every string cross-checked against your signature set, every hit kept verbatim for the file.
Anti-cheat forensics · user-mode
Memory strings, deletion records, unsigned binaries, registry traces — a suspect's machine keeps evidence better than most witnesses. Avenge collects it, files it, and hands you the verdict.
$ avenge --pin ******+ [+] meta ............... AKSHAY / win 10! [!] vm-detect .......... FLAGGEDprocess: vmware-authd.exe+ [+] processes .......... 275 enumerated+ [+] javaw memory ....... not running+ [+] recent execution ... 41 exes3 unsigned, 1 invalid sig+ [+] usn journal ........ C:\ sweptdeleted this boot .. 17! [!] unsigned exe deleted this bootC:\Users\...\cl.exe
Filed automatically · report #45dba3e1
CheatEvidence inventory
Javaw heap sweeps, injected-module listings, executable paths pulled out of service process memory — every string cross-checked against your signature set, every hit kept verbatim for the file.
NTFS change journals sorted deletions-first, prefetch runs within thirty days, Run-key and Uninstall walks, browser history parsed straight off disk. Deleted-after-the-fact is still on the record.
Every executable recovered gets an Authenticode check with catalog fallback. Unsigned binaries deleted this boot are called exactly what they are — cleanup.
Workflow
Every step is logged against the PIN that opened it. No gaps, no guesswork.
Six digits, 24-hour expiry, bound to one hardware ID.
Portable exe or plain client. No driver, no install, under a minute.
Detections, journal forensics, signature status. Flag, ban, or clear.
Pricing
Rolling retainer · cancel anytime
Single payment · never expires
Intel
Running processes and window titles, javaw memory strings, loaded non-system modules, recent executables recovered from system-process memory with their signing status, prefetch entries, registry Run/RunOnce/Uninstall values, browser history hits, recording tools, and the NTFS change journal with full path resolution for deletions. The exact contents of every scan are visible in the sample report below the pricing.
They run one portable executable. Everything happens in user mode on their own session; nothing persists after the scan finishes.
Each scan submits a hardware identifier derived from the machine's Cryptography MachineGUID. PINs are single-use and expire in 24 hours. Banning a report blocks that hardware ID from scanning again.
Yes — compile a scanner build with the PIN baked in from the dashboard, send the file, and the report lands on your desk when it runs.