Anti-cheat forensics · user-mode

The cheater
wrote it all
down for you.

Memory strings, deletion records, unsigned binaries, registry traces — a suspect's machine keeps evidence better than most witnesses. Avenge collects it, files it, and hands you the verdict.

HWID-bound PINs < 60s turnaround No kernel driver
live scan transcript
$ avenge --pin ******
+ [+] meta ............... AKSHAY / win 10
! [!] vm-detect .......... FLAGGED
process: vmware-authd.exe
+ [+] processes .......... 275 enumerated
+ [+] javaw memory ....... not running
+ [+] recent execution ... 41 exes
3 unsigned, 1 invalid sig
+ [+] usn journal ........ C:\ swept
deleted this boot .. 17
! [!] unsigned exe deleted this boot
C:\Users\...\cl.exe

Filed automatically · report #45dba3e1

Cheat
User-mode only — no kernel driver touchedReport turnaround < 60 secondsSingle-use PIN · HWID-bound

Evidence inventory

Every scan opens a full case file.

MEMORY

Memory, read the hard way

Javaw heap sweeps, injected-module listings, executable paths pulled out of service process memory — every string cross-checked against your signature set, every hit kept verbatim for the file.

DISK FORENSICS

The machine's paper trail

NTFS change journals sorted deletions-first, prefetch runs within thirty days, Run-key and Uninstall walks, browser history parsed straight off disk. Deleted-after-the-fact is still on the record.

SIGNATURES

Signatures, not vibes

Every executable recovered gets an Authenticode check with catalog fallback. Unsigned binaries deleted this boot are called exactly what they are — cleanup.

Workflow

One scan. Three moves.

Every step is logged against the PIN that opened it. No gaps, no guesswork.

  1. Issue a one-time PIN

    STAFF

    Six digits, 24-hour expiry, bound to one hardware ID.

  2. Run the scanner

    SUSPECT

    Portable exe or plain client. No driver, no install, under a minute.

  3. Read the report, call the verdict

    STAFF

    Detections, journal forensics, signature status. Flag, ban, or clear.

Pricing

Pick your loadout.

Monthly

Rolling retainer · cancel anytime

$14.99/ MO

  • Unlimited scans & PINs
  • Full forensic report access
  • Flag & HWID-ban workflow
Get monthly
Best value

Lifetime

Single payment · never expires

$79.99

  • Everything in monthly
  • Pay once, scan forever
  • Priority build queue
Get lifetime

Intel

Questions, answered.

What does the scanner actually collect?

Running processes and window titles, javaw memory strings, loaded non-system modules, recent executables recovered from system-process memory with their signing status, prefetch entries, registry Run/RunOnce/Uninstall values, browser history hits, recording tools, and the NTFS change journal with full path resolution for deletions. The exact contents of every scan are visible in the sample report below the pricing.

Does the suspect install anything?

They run one portable executable. Everything happens in user mode on their own session; nothing persists after the scan finishes.

How is a report tied to a machine?

Each scan submits a hardware identifier derived from the machine's Cryptography MachineGUID. PINs are single-use and expire in 24 hours. Banning a report blocks that hardware ID from scanning again.

Can I hand out builds instead of PINs?

Yes — compile a scanner build with the PIN baked in from the dashboard, send the file, and the report lands on your desk when it runs.