Public CS2 Cheat Defensive Analysis
Scope
This document records static defensive analysis of public source revisions. No binary was built or executed. Repository names and file names are versioned indicators only; behavioral controls must remain effective after renaming.
| Project | Revision | Access model | Rendering and input |
|---|---|---|---|
| Osiris | f314a97592a8176912a9dd9741846b97601a0622 |
In-process DLL; loader or manual map | Panorama, SDL callback replacement, copied VMT |
| Valthrun CS2 | ac08b2d70659f36699b157e100efa4cef365ac52 |
External client backed by a kernel interface | Capture-excluded external overlay; kernel input |
| CS2_External | b7e3b41687ce6ba798975741d9a9755249d1b65c |
OpenProcess, RPM, and WPM |
D3D11 overlay and synthetic mouse input |
| deadlocked | 1c5bbb22698f8ff80e71c44b76ea92058fb989b9 |
Linux process_vm_readv/writev and procfs |
X11 overlay and /dev/uinput |
| WilonityLoader | 746ed119aa5af48ef371e220e178f3ee539cd764 |
Not established from repository contents | Generic runtime DLLs only |
| cs2-sdk | a19f4a5cce937539c865e59596e5471e38568ed7 |
In-process DLL | Funchook trampolines, DX11/Vulkan, SDL, WndProc |
Defensive mapping
Internal mapped components
Osiris initializes from DllMain, replaces an SDL function pointer, and
redirects a view-render object to a copied VMT. The copied VMT changes writable
dispatch data rather than the original executable section. A manual-mapped
payload is covered by private/unlinked executable-region classification; a
loader-visible payload requires manifest authorization. Game integrations must
configure --watch-pointer for critical callback slots and --watch-vtable
for global object-pointer slots.
The cs2-sdk revision creates an initialization thread and installs trampoline hooks through funchook. Executable-section comparison and private executable region classification cover persistent trampolines. Kernel thread telemetry provides a separate start-address correlation signal. WndProc replacement is covered by target-window dispatch validation.
External user-mode access
CS2_External requests broad target process rights and uses RPM/WPM. The kernel Object Manager callback records dangerous handle creation and duplication, including the requestor PID, access mask, and process path. Its topmost, transparent, capture-excluded overlay is covered by behavioral overlay classification. Data-only writes are not equivalent to executable-section modification and require game/server state validation.
External kernel-backed access
Valthrun uses a native Object Manager device rather than requiring a DOS
symbolic link. The collector therefore inventories both QueryDosDeviceW
names and the native \Device directory. A startup PSAPI snapshot records
drivers loaded before target registration; image callbacks record subsequent
loader-mediated driver loads. A pinned driver manifest supplies local
authorization input. Manual kernel mapping and malicious ring-0 falsification
remain outside authoritative local detection.
The overlay is independently classifiable by topmost, transparent, capture-excluded, and target-overlap properties. Direct attribution of packets in the Windows input class stack is not available through a documented passive API; driver identity, overlay behavior, target state, and server-side input statistics must be correlated.
Linux external access
deadlocked reads through process_vm_readv, optionally writes through
process_vm_writev, opens procfs memory, creates a uinput device, and uses an
always-on-top X11 overlay. The Linux collector covers target tracing,
/proc/<pid>/mem file descriptors, /dev/uinput ownership, and suspicious
executable mappings. Observation of process-vm system calls requires an
integrator-owned eBPF LSM or audit rule and is explicitly reported as a
coverage gap when absent.
Unverifiable package
The WilonityLoader revision contains no loader executable, driver, installer, or implementation source. The committed FFmpeg, EGL/GLES, ICU, and shader compiler files are common runtime components and are not suitable standalone indicators. Analysis requires the distributed installer or executable, Authenticode metadata, embedded payload inventory, service/device creation, and protocol behavior. Blocking the generic DLL names would create excessive false positives.
Correlation policy
High-confidence correlation should combine independent sources:
- a foreign process requests dangerous target access;
- an external overlay strongly overlaps the target and excludes capture;
- an unknown driver or native device is present;
- a thread start, function pointer, VMT entry, or WndProc resolves outside authorized loader-visible modules;
- the module or driver identity violates the pinned manifest;
- server-side state or input behavior is inconsistent with the game rules.
A single public name, file path, window title, device name, or hash must not be used as an account-level enforcement decision.