Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Detecting the Cheat Engine process

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine
View previous topic :: View next topic  
Author Message
heyimyuuta
Newbie cheater
Reputation: 0

Joined: 14 Sep 2023
Posts: 12

PostPosted: Sat Nov 04, 2023 1:28 pm    Post subject: Detecting the Cheat Engine process Reply with quote

I am currently in the process of reverse engineering various Anticheats to get some insight into their methods of detecting programs like Cheat Engine.
One particular Anticheat that has caught my attention is Xigncode.

Even without loading any Cheat Engine related drivers or opening handles to other games (attaching ce to a process), Xigncode is able to detect Cheat Engine within just one minute.

In my attempts to understand how Xigncode is able to detect it, I have experimented with different approaches.
For example, I have tried suspending the Cheat Engine thread / freezing Cheat Engine, overwriting the entire process memory of Cheat Engine with zeros, closing all handles, and unloading all modules, renaming all Cheat Engine related strings, disableing the output for outputdebugstring...
Despite all of that Xigncode still detects it.

I am aware of the following detection methods such as:
signature/pattern detection,
process/window name detection,
window class and text name detection,
enumerating modules for each process and checking for modules similar to Cheat Engine,
intercepting OutputDebugString calls and searching for blacklisted strings,
ReadDirectoryChangesW.

However, I am curious if there are any other detection vectors that could explain Xigncode's method to detect Cheat Engine even when it is idle, without being attached to any process or performing any actions.
Back to top
View user's profile Send private message
Micke
How do I cheat?
Reputation: 0

Joined: 30 Apr 2016
Posts: 4

PostPosted: Wed Jan 24, 2024 4:11 pm    Post subject: Reply with quote

filename ?
Back to top
View user's profile Send private message
LeFiXER
Grandmaster Cheater Supreme
Reputation: 20

Joined: 02 Sep 2011
Posts: 1069
Location: 0x90

PostPosted: Wed Jan 24, 2024 6:22 pm    Post subject: Reply with quote

It's possible that the anti-cheat could detect the installation of Cheat Engine also.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites