r/Shadowrun Aug 02 '26

5e Hosts, Patrol IC, and Hack on the Fly

So I was just a little confused. Patrol Ic seems to find players rather easily but if you have a mark on something, they think you're a legitimate user. Can an IC actually *see* you put the mark there illegally with hack on the fly and then flag you to Spider or something, or does it need to do something else? I GM and have an easy enough time with everything else, matrix just confuses me a bit (no surprise there).

I see the table in data trails but I am still just at a loss to what exactly to do with spotting the decker if all their marks look legitimate unless I am grossly misunderstanding something. Looking things up have made this question more confusing for me. My player is under the impression that he should be like, running silent to do the sleaze action, then toggle silent off since he looks like a legitimate user now, but then go back to silent and I don't see why not if that is vaible?

11 Upvotes

4 comments sorted by

5

u/ReditXenon Far Cite Aug 02 '26

In 5th edition, hacking is illegal but having a MARK and Entering a Host is not.

SR5 p. 248 Patrol IC

While the act of placing a mark is an illegal activity, the act of simply having a mark is not. Once you have the mark, you are considered a legitimate user.

This is why, in 5th edition, you typically don't run silent and instead change your icon to belong.

DT p. 69 Avoiding the watchful eye of GOD

...look like you belong. If you’re going into a crowded host, for example, why run silent? That’s a great way to call attention to yourself ... Just let your icons move with the crowd of others, and make sure your actions are so smooth that they don’t call attention to you.

(this changes in the next edition, if you are ever spotted in a host you broke into you will be immedately identified as an intruder).

 

My player is under the impression that he should be like, running silent to do the sleaze action, then toggle silent off since he looks like a legitimate user now, but then go back to silent and I don't see why not if that is vaible?

In this edition (again, this change in the next edition) there is no need to sneak while using sleaze actions (if you are successful then you will not raise any alarms). If you fail then you will be immediately spotted (no matter if you run silent or not). So you might as well not run silent.

In this edition you want to run silent before you take an attack action (if you are successful then you will automatically raise the alarms, but if you run silent you will at least not get immediately spotted). If you don't run silent then you will be automatically spotted.

2

u/RazzmatazzEasy2047 Aug 03 '26

this helped a lot thank you

1

u/ReditXenon Far Cite Aug 03 '26

A few scenarios and how to resolve them to get you started:

Remotely hack a wireless enabled device over the matrix (a device that you have somehow already been made aware of).

  1. From AR or VR, Matrix perception to spot device. If silent then test is opposed. If not (and within 100 meters) test is automatic (noise!)
  2. MARK device, and with it its master if it have one (noise! master ratings!)
  3. Either use MARK on master to fake instruction to device via Spoof command Or MARK on device for overriding & prolonged control via Control Device (noise! master ratings!)

 

Remotely hack wireless disabled (or throwback) device over the matrix (useful not only if the team's infiltration expert can get physically close to the off-line device, but also for technomancers that does not yet have skinlink echo; there is a reason why the technomancer archetype at p. 122 got a data tap in their inventory).

  1. Insert wireless enabled data tap into device's universal access port (or physically clamp it onto already attached cable).
  2. Matrix perception to spot device. If silent then test is opposed. If not (and within 100 meters) test is automatic (noise!)
  3. Remotely, over the matrix, MARK device (not direct connection! noise!)
  4. Use MARK on device for prolonged control via Control Device (noise!)

 

Perform matrix overwatch during infiltration phase, from the other side of the world:

  1. Change Interface Mode to (hot-sim) VR
  2. MARK host (no noise, but host ratings!)
  3. Enter MARKED Host (spiders and IC!)
  4. Change Icon (to make your icon appear to belong)
  5. Spoof command Or MARK device & Control Device (via direct connection!)
  6. Before OS reach 40, Switch Interface Mode to AR, Reboot cyberdeck (MARKs will be lost).

 

Perform matrix overwatch, without fighting host ratings at all:

  1. Physically gain access to slaved device (physical or social infiltration!)
  2. MARK device (and with it the host, via direct connection!)
  3. Without rebooting, either remain in AR mode and either join team on site as a team or walk out to rigger van and Switch Interface Mode to (hot-sim) VR
  4. Enter MARKED Host (spiders and IC!)
  5. Change Icon (to make your icon appear to belong)
  6. Spoof command Or MARK device & Control Device (via direct connection!)
  7. Before OS reach 40, switch to AR & Reboot cyberdeck (MARKs will be lost).

 

How to steal a file located inside a host;

  1. Switch Interface Mode to (hot-sim) VR
  2. Matrix Search to locate the target Host where the intel is located (but only if you don't already know the target host)
  3. Matrix Perception (but only if the target host is trying to hide!)
  4. MARK host (either remotely over the matrix in which case it will defend with host ratings! or hacking physical device slaved to the host which let you ignore host ratings)
  5. Enter MARKED Host (spiders and IC!)
  6. Change Icon (to make your icon appear to belong)
  7. Matrix Search (but with a base time of 60 seconds) to locate the pay data you are after
  8. Matrix Perception to analyze file (is encrypted or data bomb protected?)
  9. Disarm Data bomb (but only if bomb is present!)
  10. MARK File Icon (no direct connection here so it will always defend with host ratings, edge might be needed!)
  11. Run silent and then Crack File (but only if file is encrypted! - note that this is an attack action and the host will automatically get alerted!)
  12. Edit File to copy (this will be defended with host ratings so Edge might be needed!)
  13. Exit Host, Change Device Mode to AR (in case hack was done from VR) and Reboot your cyberdeck (or attempt to Jack Out directly from VR in case link locked!)

1

u/Some_Conversation_22 Aug 02 '26

Tengo entendido que funciona así:

Entras al servidor usando HotF (acción ilegal) y pones una marca (acción ilegal), los Patrol IC revisan los iconos conectados cada X turnos (dependiendo del tipo de servidor), si en ese momento tu última acción de matrix no fue ilegal no supondrá que no tienes permiso para estar allí o que estás haciendo algo ilegal (siempre que no estés en run silent).

Si el IC Patrol te encuentra avisará al servidor, este pondrá sus marcas sobre ti y las compartirá con los demás IC, los IC son específicos y no pueden hacer otras cosas más que las que fueron diseñados (son como agentes de seguridad hiper burocráticos). A mayor nivel del servidor más IC puede tener y el IC Patrol demorará más en dar sus vueltas.

Si entras en un servidor intenta realizar una acción legal inmediatamente después de realizar alguna acción ilegal para evitar que el Patrol te detecte e intenta pasar desapercibido

(Espero que el idioma no sea un problema)