Aacguard Anti-Cheat

Preparing your project experience…

Changelog

Every update,
in the open.

All notable changes to AACGUARD are listed here. This includes scanner engine updates, new forensic modules, and improvements to the web panel.

v0.0.11 latest release · 2026-10-02
12 releases published
115 documented changes
250 days since v0.0.1 (2026-01-25)

v0.0.11

Latest

External cheat detection, deep Windows forensics, ban-evasion fingerprint, fairer verdicts and a new look

37 changes

Version 0.0.11 is the biggest update so far. AACGUARD now catches external cheats that never touch the disk by name (memory readers, ESP overlays and CS 1.6 proxy DLLs), reads many more Windows records with reliable timestamps, recognises players returning on new accounts through a one-way hardware fingerprint, and explains every verdict with a local scan report.

Verdicts are also fairer: old traces count less, cheats for another game are shown but not counted, and the whitelist can no longer be abused. The desktop app has been redesigned with a dark blue theme that works at any window size.

  • New: game memory access check – While a game is running, AACGUARD lists every other program that has the game's memory open for reading or writing. External ESP and aimbot tools are now caught whatever they are called. Signed Windows, Steam, Discord and antivirus processes are ignored.
  • New: ESP overlay detection – Finds invisible, always-on-top, click-through windows drawn over the screen, the way external ESP overlays work. Known overlays (Steam, Discord, NVIDIA, MSI Afterburner and others) are ignored.
  • New: CS 1.6 proxy DLL & ASI plugin check – Game folders (Half-Life, CS:GO, CS2, including non-Steam CS 1.6 installs) are checked for fake opengl32.dll, d3d9.dll, dinput8.dll, version.dll and similar files, and for .asi plugins. Genuine Windows copies, the original Half-Life sound plugins and ReShade are not counted.
  • New: cheat version labels – Every Counter-Strike finding now shows which game it is for: CS 1.6, CS:GO, CS2 or CS:GO / CS2, based on the cheat name and where it was found.
  • New: hardware fingerprint – One-way salted hashes of the motherboard, BIOS, SMBIOS UUID, system disk, Windows machine ID and network adapter are sent with each report, so banned players returning on a new Steam account can be recognised. Raw serial numbers never leave the PC.
  • New: HWID spoofer detection – Traces of hardware-serial spoofers in activity records, running programs and drivers, plus wired network adapters using a changed MAC address.
  • New: tamper checks – Flags cleared Windows event logs, Prefetch switched off, the clock changed by a program, aacguard.com blocked (hosts file, DNS or firewall) and Windows booted with test-signing or kernel debugging.
  • New: Windows Defender history – Cheat detections that Windows Defender recorded (threat name, file and time) are now part of the scan.
  • New: deleted files – Recently deleted or renamed files are read from the NTFS change journal, so cheats removed just before a scan still leave a trace.
  • New: Windows 11 launch log, DNS cache, services, drivers & scheduled tasks – Programs launched (PCA log), recently visited cheat domains, and cheat services, drivers or tasks registered on the PC are now checked.
  • New: USB traces – Lists every USB storage device the PC has seen, with connect and remove times, and links programs, files and folders used from USB sticks or removed drives back to the device.
  • New: Explorer history, Recent files & Jump Lists – Folders opened in Explorer (ShellBags), recently used files and Jump Lists are read for every Windows user on the PC, including accounts that are not signed in.
  • New: known cheat hashes – Files and AmCache records can be matched against SHA-256 / SHA-1 hash lists from the server, so renamed cheats are still recognised.
  • Bigger cheat lists – Around 100 new names: DMA and hardware cheats (pcileech, KMBox, Captain DMA, Cronus Zen, XIM and others), more CS 1.6, CS:GO and CS2 cheats, plus FiveM, Minecraft and Roblox cheats.
  • AmCache now works – AmCache is read through a temporary Windows shadow copy when Windows has it locked (thousands of records on a normal PC), including file hashes, publisher and compile date.
  • Reliable Prefetch, BAM, ShimCache & MUICache – Prefetch files are fully decoded on Windows 10/11 (program path, drive, last 8 run times and run count), BAM/DAM shows the last run per user, ShimCache supports the Windows 7, 8 and 10/11 formats, and MUICache is read for every user.
  • Timestamps everywhere – Every finding now carries an evidence timeline (run, visit, created, modified, deleted, connected times). Browser history matches show the visit count and first / last visit times, which were previously missing.
  • Smarter cfg detection – CS 1.6, CS:GO and CS2 cfg files are analysed for real cheat / HvH settings. Only cfgs identified that way are listed or uploaded; normal player cfgs are no longer flagged.
  • Fairer verdicts – Traces older than 30 days count less (50% up to 90 days, 20% up to a year, 10% after), cheats for another game are reported but not counted (a Roblox executor on a CS scan), informational findings never count, and each cheat site counts once per browser.
  • More precise name matching – Short cheat names (like otc or xeno) only match as whole words, so files like hotcake.exe no longer trigger detections.
  • Whitelist can no longer be abused – A cheat placed in a whitelisted folder or given a whitelisted name is still detected in Downloads, Desktop and Temp, and whitelist entries that are too broad are ignored and shown in the log.
  • Stricter trusted-signer check – Only files signed by an exact, known publisher are treated as legitimate; look-alike company names are no longer trusted.
  • Local scan report – A report window opens after every completed scan (uploaded or not), showing each finding with its location, why it was flagged, how many points it counted and its evidence timeline.
  • Updated Data use & consent – The in-app notice now lists every check the scanner performs and exactly what is sent, including the hardware fingerprint.
  • Redesigned desktop app – New dark blue glass design with a faint CS 1.6 background, translucent cards and subtle animations even before a scan starts.
  • Works at any window size – The layout adapts from small windows to full screen, the window can be resized and maximised without covering the taskbar, and the raw log wraps, can be expanded and copied.
  • Detected Players window – The Detected Players button now opens the full list of today's scans inside the app; the detected list still opens on the website.
  • Removed: over-broad whitelist entries – Entries that trusted entire user, AppData Local and AppData Roaming folders, and entries tied to specific Windows user names, were removed and replaced with paths that work on every PC.
  • Removed: uploading every non-default cfg – Only cfgs with cheat / HvH settings are uploaded now.
  • Fixed: scans reporting CLEAN without rules – When the scan rules cannot be downloaded the scan now stops with an error instead of showing CLEAN.
  • Fixed: wrong verdicts – Corrected how findings were classified and scored, and server information no longer affects the verdict.
  • Fixed: crashes and restarts – Errors inside a single check no longer stop the whole scan, and starting a new scan right after one finished no longer mixes results.
  • Fixed: browser timestamps missing – Visit times from Chromium and Firefox browsers are now converted and shown correctly.
  • Fixed: AmCache, BAM & Run keys – AmCache no longer fails when locked, BAM entries are read for every user with correct times, and Run key entries are parsed correctly.
  • Fixed: USB detection – USB drives reported as fixed disks are now recognised as USB, and anti-cheat files on a USB stick are no longer flagged by loose name matching.
  • Fixed: duplicate and garbled findings – The same keyword is no longer counted twice in a cfg, and Explorer folder names are no longer shown as garbled text.
  • Fixed: unreadable text & layout – Dark text on dark backgrounds is now white, and the status and top info cards are no longer overly rounded when the window is resized.

v0.0.10

Game & server detection, deeper in-game checks, fewer false positives and a redesigned app

12 changes

Version 0.0.10 focuses on context and accuracy: AACGUARD now knows which game a player is running and which server they are connected to, inspects the game process more deeply, and filters out legitimate software that previously caused false positives, all with a cleaner, easier-to-read desktop interface.

  • Automatic game detection – Recognises CS2, CS:GO, CS 1.6, FiveM, Minecraft (Java & Bedrock) and Roblox from running processes, and reports the game at scan start.
  • Connected server detection – For CS 1.6, CS:GO and CS2, the scan now identifies the server the player is on and shows its domain (e.g. go.mortall.ro) when available, otherwise its IP:port.
  • Last played server – If the player is not connected during the scan, AACGUARD shows the last server they played on, clearly marked as LAST instead of LIVE.
  • Deeper module inspection – The game process scan now sees the modules loaded into 32-bit games like CS:GO and CS 1.6, which were previously invisible to the scanner.
  • Injected code detection – New check for cheat code loaded directly into Counter-Strike's memory without a file on disk.
  • Kernel driver check – Flags drivers commonly used by cheat tools and kernel-level cheat loaders.
  • Debugging & memory tool detection – Reports memory editors, debuggers and injectors running during the scan.
  • Far fewer false positives – GPU drivers (NVIDIA, AMD, Intel), overlays (Steam, Discord, OBS, Medal, RivaTuner), antivirus software and other trusted, signed components are now recognised as legitimate and no longer affect the score.
  • Redesigned desktop app – New layout with a colour-coded verdict card, clear score, detection and check counters, dedicated game and server cards, and per-check status pills.
  • Server column on the website – The detected players list and scan pages now show the player's server with LIVE/LAST status and one-click copy.
  • Redesigned scan page – Scan reports are easier to read on desktop and mobile, with a plain-language summary and a clear list of every check performed.
  • General reliability improvements – Scoring thresholds are unchanged, while server information no longer counts as a detection, keeping verdicts fair and consistent.

v0.0.9

Expanded artifact coverage, improved browser handling, stronger VM detection and better forensic review

8 changes

Finalized the 0.0.9 release by expanding AACGUARD’s detection and review coverage across browser traces, system artifacts and usage indicators, while improving reliability and keeping the desktop app workflow lightweight for players and administrators.

  • ShimCache, MUICache and AmCache support – Added handling for additional forensic artifacts, with ongoing AmCache work still limited by the lack of kernel access for full reliability.
  • BAM artifact coverage – Added BAM analysis to improve visibility into execution-related traces.
  • More browser support – Added support for additional browsers and browser backups, including browsers downloaded from the Microsoft Store.
  • Better virtualization finder – Improved VM detection to help identify cases where cheats may have been run inside virtual machines.
  • Improved USB detection – Refined USB artifact handling for clearer device activity review.
  • Better Recycle Bin review – Enhanced Recycle Bin parsing with the last deletion time now shown for faster investigation.
  • Improved AppData coverage – Expanded AppData handling to surface more useful traces during review.
  • General reliability improvements – Continued internal cleanup and workflow refinements to keep scans and review output more useful and consistent.

v0.0.8

Website compliance, smarter log interpretation, community updates and stronger detection workflow

8 changes

Finalized the 0.0.8 release by improving AACGUARD’s public website, legal/compliance pages, moderation ecosystem and internal detection workflow, while keeping the core desktop app behaviour unchanged for players and admins.

  • Cookies module and consent flow – Added and refined the website cookie consent module to better manage necessary, preference, analytics and marketing choices with clearer user control.
  • New Cookies Policy page – Published a dedicated cookies policy covering consent categories, third-party services, analytics usage and how visitors can update their preferences.
  • New GDPR policy page – Added a dedicated GDPR notice with controller details, legal bases, data categories, user rights, retention, transfers and Romania-specific supervisory authority information.
  • AI-assisted log phrasing – Integrated an AI bot powered by TinyLlama to help phrase, summarize and rapidly interpret raw logs into clearer operational context during review.
  • Improved detection quality – Refined internal detection logic and review flow to produce more useful signals and cleaner interpretation without changing the app’s visible workflow.
  • Discord server refresh – Updated the Discord server structure and channels to improve communication, support flow, announcements and community organization.
  • No client-side usage changes – This release does not change how the AACGUARD desktop app is used by players; the improvements are focused on website, compliance, moderation support and ecosystem quality.
  • Host Upgrade – I increased the server plan to one with more resources. Still on ovhcloud.com!

v0.0.8

Beta

Dedicated backend API, remote scan posting and safer data path

5 changes

Split AACGUARD into a proper client–server architecture with a new ASP.NET Core API on your Debian host, moved all scan writes from the desktop into a central MySQL backend, and wired the Windows client to submit scans over HTTP so users never touch the database directly while you keep full control and observability on the server.

  • Upgraded scan flow – Cleaned up how scans run and finish so every session now produces a consistent status, score and detection count without changing how players use the app.[web:7]
  • Richer evidence per scan – Standardized what AACGUARD records (game process, exit state, browser checks, operations JSON and detailed logs) so each scan has clearer, more useful history behind it.[web:7]
  • Advanced cheat detection logic – Refined and extended existing detection code to better catch loaders, injected modules and suspicious behaviour patterns while staying focused on cheats instead of harmless background apps.[web:7]
  • Secure API-backed saving – Moved all database writes behind a dedicated ASP.NET API, removing direct DB access from the client and making stored scans harder to spoof or tamper with.[web:7]
  • More robust error handling – Improved how the app reacts when saves fail or the backend is unreachable, showing clearer messages instead of low-level database errors.[web:7]

v0.0.7

Integrity‑checked client, clearer scan output

7 changes

Refined the desktop UI with a new footer, legal copy and upgrade controls, added a server-backed self-integrity gate, enforced admin-only startup, and introduced a detailed post-scan summary so every run ends with a clear, auditable report.

  • Server‑driven integrity JSON – New IntegrityHelper downloads aac_hash.json, computes the running EXE’s SHA‑256, and only considers the client valid when it matches the hash configured on the AACGUARD backend.
  • Integrity‑gated DB writes – SaveScanToDatabase now calls VerifySelfIntegrity() before version checks or inserts, aborting scans with a clear “executable modified or corrupted” message instead of silently proceeding.
  • Admin‑only startup gate – The WPF App class checks for elevation on OnStartup and shuts down immediately with guidance if AACGUARD is launched without Administrator rights.
  • End‑of‑scan popup report – After a successful transaction commit, the client now shows a detailed MessageBox summarizing player info, final status, total checks, detections, score, and every OperationResult entry.
  • Cfg file listing in summary – The new report also lists all captured cfg files per scan and marks userdata configs, making it easier to connect suspicious cfg evidence with concrete file names on the client side.
  • Legal-aware footer – The main window now includes a compact footer with inline links to Terms, Privacy Policy and the EULA, keeping legal context visible without cluttering the primary scan surface.
  • Quick access links – Dedicated buttons for the AACGUARD website, upgrade/download page and official Discord are exposed directly in the UI, so users can update, read docs or get support without hunting for URLs.

v0.0.6

Smarter signals, fewer false positives

6 changes

Tightened AmCache/ShimCache, AppData and shortcut heuristics to focus on real cheat loaders and cfg evidence while aggressively suppressing noisy system/runtime artifacts.

  • AmCache focus – Amcache scanning now extracts the filename and only flags hits when it matches exact cheat or loader names, ignoring generic paths and benign Java/OpenJDK entries.
  • ShimCache focus – ShimCache/AppCompatCache parsing was aligned with AmCache: filenames are matched against the same cheat/injector lists and are skipped entirely if they fall under whitelisted paths.
  • AppData hardening – The AppData walker normalizes paths before whitelist checks and adds specific rules for Autodesk Inventor/ODIS temp DLLs, dramatically reducing “Suspicious file in AppData” noise.
  • Shortcut sanity – Shortcut scanning now works on the base .lnk name with the central cheat-name matcher instead of raw substrings, so legit apps like Shotcut no longer trigger weak detections.
  • Cfg evidence – The cfg inspector reports all matching cheat, search, and HVH keywords per file instead of stopping at the first hit, giving admins a fuller picture of how a config was tuned.
  • Scoring hygiene – Internal scoring and whitelist use were refactored so system DLLs, game launchers, Java runtimes and other known-safe components stop inflating scores or flipping scans to CHEAT DETECTED on their own.

v0.0.5

CFG forensics, IP privacy and user scan history

8 changes

Extended the admin panel with deep CS:GO cfg inspection, safer IP masking for screenshots/logs, and a per-user scan history view to make manual triage much faster.

  • CFG browser – Scan view now lists all collected CS:GO cfg files split into default and unknown/non-default sets, mirroring the client-side classification.
  • Popup viewer – Each cfg entry has a View action that opens a Tailwind-styled modal and shows the stored cfg content directly from the database without leaving the scan page.
  • Safe transport – A dedicated cfg_view.php endpoint returns only cfgs that belong to the current scan/user, preventing arbitrary path access and keeping cfg content scoped to legitimate records.
  • IP masking – Public IP masking logic was updated to a custom per-octet pattern (e.g. 11.11.11.11 → 1*.*1.11.1*) that is stable for admins but hides enough detail for sharing screenshots/logs externally.
  • Consistency – The same masked IP format is now surfaced in the admin scan view, so operators always see exactly what the client reported without exposing the full address.
  • User history – The bottom of the scan page now shows a compact table of other scans for the same user (time, status, score, detections, game process), with the current scan highlighted.
  • Fast navigation – Each historical entry links back into scan_view.php, making it trivial to hop between suspicious scans for the same account during investigations.
  • Admin UX – Layout widths were slightly relaxed and tables made horizontally scrollable so cfg paths and process names remain readable even on narrower screens.

v0.0.4

Forensic stability and AmCache handling

8 changes

Refined how AACGUARD interacts with Windows forensic artifacts, especially AmCache, to improve robustness on locked systems while keeping detection logic unchanged.

  • Improved – AmCache scanner now always works on a temporary copy and never touches the live hive directly, reducing the chance of unnecessary file locking and access conflicts.
  • Hardened – Added a dedicated TryReadAmcacheHive helper that uses maximal safe sharing flags and gracefully handles the “file in use by another process” condition instead of crashing the scan.
  • Resilient – When AmCache is exclusively locked by the OS, AACGUARD now reports a clear, non-fatal warning and continues the rest of the scan instead of treating it as a hard failure.
  • Future-ready – Internals refactored so a Volume Shadow Copy (VSS)-based reader can be plugged in later without changing the detection rules or UI text for AmCache.
  • Safety – Confirmed that AmCache access is performed via standard read-only file I/O patterns commonly used by DFIR tools, avoiding invasive kernel tricks that could resemble cheat behavior to third-party anti-cheats.
  • Versioning – Added real versioning compatibility!
  • Limits – Daily per-user scan cap is enforced more cleanly, with a clear client-side message when the 5 scans/day limit is reached instead of a silent failure.
  • UI polish – Admin panel scan view shows masked IP and additional environment details (browsers used, game exit status) for quicker manual triage.

v0.0.3

Detection engine improvements

6 changes

Focused on detection reliability, exact-name matching, and consistent scoring across all forensic modules.

  • New – Exact-name scoring system (ExactNames) for known cheats; matching names now add +1000 to the score and instantly trigger CHEAT DETECTED.
  • Expanded – Exact-name logic wired into Prefetch, BAM, MUICache, CS:GO/CS2 folders, Downloads, Desktop, Recycle Bin, USB traces, Amcache, Shimcache, and RunKeys.
  • Updated – Processes and modules scanner so both process names and loaded modules participate in exact-name and fuzzy detection rules.
  • Improved – Browser history engine with better multi-profile support for Chromium/Firefox-based browsers and clearer separation between cheat sites and cheat-search queries.
  • Tuned – Centralized verdict rule around Score >= 999 for hard CHEAT DETECTED, while keeping weaker signals in SUSPICIOUS.
  • Stability – Hardened error handling for locked/denied files so scans complete even when some locations are inaccessible.

v0.0.2-fix

Hotfix

Panel integration & fixes

5 changes

First version that connects the Windows client to the live AACGUARD web panel with real-time stats.

  • Added – Dashboard stats: total scans, unique players, total flags, last 24h detections, and last scan timestamp from the scans table.
  • Added – Detected-players listing with verdicts and basic scan metadata for server admins.
  • Improved – Logging format so each scan is consistently tied to Steam ID and verdict on the panel.
  • Fixed – Client startup issues on some Windows 10 setups where scans could fail silently.
  • UI – Landing page hero now shows live stats and last 24h detections instead of placeholder numbers.

v0.0.1

Initial public prototype

5 changes

First public Windows client and PHP/MySQL panel release for community testing.

  • Added – User-mode Windows client designed to be VAC-safe.
  • Added – Core forensic checks for CS:GO / CS2 (configs, game directories, basic file traces, processes).
  • Added – Score-based verdict system with CLEAN, SUSPICIOUS, and CHEAT DETECTED outcomes.
  • Added – PHP/MySQL backend storing scans with Steam ID, scan time, and verdict.
  • UI – First AACGUARD landing page with download CTA and “how it works” explanation.

Get the latest version.

Every release is scanned and hash-verified before it's published.

We use cookies

We use necessary cookies to make this site work and optional cookies for analytics and marketing. You can change your choices at any time.

Cookie settings

Choose which cookies we can use. You can update these settings at any time.

✓

Necessary

Always on

Required for basic site functionality, security and consent preferences.