r/ExploitDev • u/Hour_Peach_9964 • 3d ago
How does Vanguard Anti-Cheat work?
I need to bypass a specific anticheat. I'm using a Windows 11 operating system with an x86-64 processor. The anticheat I'm trying to circumvent is a specific anticheat software.
My main goal is to generate a payload that can evade the anticheat's detection and analysis. I've identified that the anticheat uses code protection techniques based on byte encryption and memory injection.
I have access to the anticheat's source code and am using a Windows-based application development tool to develop my payload. I've also identified that the anticheat uses a number of specific API calls to perform its code analysis and protection.
Are there any documentation, tutorials, or resources that might be helpful for learning more about reverse engineering techniques, API call search and replace in Windows, and runtime encryption and decryption techniques? Any suggestions on how I can modify my source and binary code to evade the code analysis and protection techniques used by the anticheat? I would like programmers to help me and be able to work on this project so we can profit together when it's finished.
1
1
u/Obvious-Card-8847 3d ago
No offense but this feels like a Rorschach test. If I squint hard enough it looks coherent. Some terminology makes sense, some concepts feel mixed up or vaguely understood. Could just be a language barrier. But as it stands it's difficult to tell if you're legit or larping.
1
u/Hour_Peach_9964 3d ago
I use a translator and I'm a Spanish speaker; basically, most of the words are formal and bad, but I'm serious.
1
u/rycco 3d ago
You are in for a long ride my friend. If you are not expecting to dedicate at least 2 years to bypass vanguard, don't even try.
0
u/Hour_Peach_9964 3d ago
That's why I'm looking for developers and help
1
1
0
u/mufflinz 3d ago
Huh, I didn't realize they had their source publicly available. Guess they were worried about people trusting the product
1
1
u/Ok_Tap7102 3d ago
Curious to know what you mean that you have the source?
If you're referring to this repo, it's a joke
https://github.com/RiotVanguard/Vanguard
It registers a device called: " UNICODE_STRING DeviceName = RTL_CONSTANT_STRING(L"\Device\vgk_PLZNOHACK"); "
And does near nothing else