EasyAntiCheat built an entire CPU emulator inside their kernel driver. They emulate NtCreateUserProcess to intercept the CR3 write before any process creation callback can even see it. Cheaters used to grab the real CR3 from callbacks. That no longer works.
The emulation engine runs inside their custom VM obfuscator, selectively emulates or executes subroutines, and sets the return address to NULL to stop execution at the end.
All of this traced using EPT hooks from a hypervisor debugger.
https://t.co/hJxEf28xch
Author: 0avx
#AntiCheat #ReverseEngineering #InfoSec
Researchers reverse engineered BattlEye's entire client protocol and emulated it from scratch.
The result: playing BattlEye-protected games online without BattlEye even installed. Live debugging the game while connected to real servers. Cheat Engine running in Escape from Tarkov. All because the packet encryption was static and contextless.
The post is from 2020 but the techniques still apply. Protocols get emulated. Integrity checks get bypassed. Encryption gets broken. This is what anti-cheat engineers face every single day.
Every layer gets reverse engineered. The arms race never stops.
https://t.co/8JZrVG4oGy
https://t.co/n5UcGTtH3u
Author: @vm_call
#AntiCheat #ReverseEngineering #InfoSec
1/3 According to open sources, Russians have developed a jammer for Starlink satellites: "The countermeasure system is named "Volna Kupol Garant." This EW complex consists of an array of sat antennas and targets eight communication channels, each with a bandwidth of 62.5 MHz." https://t.co/LICal1hLdS
If you’ve been on the internet over the past five years, you’ve probably seen these “aesthetics” go viral before.
What you may not know is that all of these terms have one common origin point.
[Informational Thread]
The World Cup: Spud Edition 🏆
1- England - Chippy Tea
2- Argentina - Steak
3- France - Mussels
4- USA - Surf n Turk
Hard to pick a winner here! 😲
📸 https://t.co/e0GovLIGih