Cuantox Scanner is an advanced security, auditing, and memory integrity tool designed specifically for detecting injected modules, unauthorized hooks, and modified game clients (with a specialized focus on Minecraft and Java environments).
- Advanced Injection Detection (Manual Mapping & Shellcode): Scans private memory regions for orphaned PE headers, "headerless" PE signatures, or MZ signatures that bypass the standard OS loader (
LoadLibrary). - Thread Execution Analysis: Identifies suspicious processes and threads whose entry point or execution occurs within
MEM_PRIVATEexecutable memory—a common indicator of manual mapping or shellcode. - Memory Hook Detection: Detects Import Address Table (IAT) redirections and inline alterations (Inline Hooks) in game APIs, as well as unauthorized modifications to system calls related to thread management.
- SIMD-Accelerated Pattern Scanning: Utilizes Aho-Corasick algorithm coupled with SIMD (AVX-512, AVX, SSE) instructions for lightning-fast, simultaneous searching of direct strings in memory to identify traces of over 20+ known cheat clients.
- Silent DNS Cache Monitoring: Inspects system DNS records to intercept domain resolutions linked to cheat authentication servers or malicious backends without triggering standard monitoring.
- System Integrity Auditing:
- Windows Services: Validates service states and identifies suspicious service behavior.
- Registry: Detects subreptitiously modified registry values used for persistence or stealth.
- Event Log Forensics: Specifically searches for critical security events and detects manual clearing of logs (Event IDs 104, 1102) often performed during "self-destruct" routines.
- YARA Integration: Supports loading and executing YARA rules for memory-based signature matching on process images and unsigned JNI modules.
- Post-Destruct USN Journal Analysis: Reconstructs the timeline of recent file modifications at high speed directly from the NTFS Master File Table, identifying physical traces of deleted "payload" DLLs.
- Fileless Threat Detection: Searches system processes for RAM-resident malware fingerprints that leave no traceable footprint on the disk.
- Core Language: C++
- Graphics & UI Subsystem: Dear ImGui rendered natively via DirectX 11 for optimal performance and a responsive, modern interface.
- OS-Level Depth: Extensive use of Win32 APIs, NTAPI (
NtOpenProcess), and direct Syscalls to bypass User-Mode hooks and evade detection. - Performance: Performance-critical scanning loops are optimized with SIMD intrinsics to handle multi-gigabyte memory dumps with minimal latency.
- Launch
CuantoxScanner.exeas Administrator. This is required to query the memory of other processes and read low-level system registers. - The UI will automatically detect concurrent Java/Minecraft processes.
- Select the target process(es) you wish to analyze from the dashboard.
- Click START INTEGRITY SCAN.
- Analyze the interactive report. Threats are classified by severity:
- Direct Detections (High Severity): Hard evidence of injected cheats, shellcode, or malicious hooks.
- Suspicious Modules: Unsigned DLLs or those loaded from irregular locations (e.g.,
.lunarclienttemp folders). - System Integrity & Services: Discrepancies in core OS components or evidence of log tampering.
This software is intended exclusively for educational and analytical purposes in the fields of software security and forensic anti-cheat research.