TECHNICAL ARCHITECTURE

Forensic Inspection Engine Matrix

Explore the forensic inspection modules that power Air.ac. We maintain complete transparency regarding our implemented detection capabilities and our forward-looking product roadmap.

CURRENTLY IMPLEMENTED & ACTIVEIncluded in all current Air.ac client builds

Hardware & OS Environment

Hardware Identification (HWID)

ACTIVE

Gathers immutable motherboard UUID, CPU processor ID, disk serials, and MAC addresses to construct a resilient HWID preventing ban evasion across alt accounts.

Windows Secure Boot & Virtualization

ACTIVE

Audits UEFI Secure Boot state and hypervisor virtualization flags to flag bypass environments or virtual machine instances.

Operating System & Patch Build

ACTIVE

Identifies exact Windows version, build number (e.g. 22631), install date, and system architecture to ensure compatibility with FiveM anti-cheat requirements.

Deep Forensic Artifacts (Anti-Cleaner)

NTFS USN Journal Deletion Recovery

ACTIVE

Parses the NTFS Update Sequence Number journal to uncover files deleted, renamed, or scrubbed in the last 7 to 30 days. Defeats "cleaner" scripts executed right before a check.

BAM (Background Activity Moderator)

ACTIVE

Inspects the Windows BAM registry hive to recover timestamps of recently executed executables for the target user profile, even if the files are no longer on disk.

Windows ShimCache & Prefetch Forensics

ACTIVE

Correlates Application Compatibility ShimCache with Prefetch (.pf) files to determine execution frequency, last run timestamp, and original file paths.

Process & Memory Analysis

Digital Signature & Authenticode Verification

ACTIVE

Scans all active processes and loaded DLLs. Flags unsigned executables masquerading under system names (e.g. svchost.exe or discord.exe running from Temp).

FiveM Runtime & Citizen Cache Audit

ACTIVE

Verifies the integrity of CitizenFX core binaries, citizen-resources, and custom game files to detect modified weapon damages, bullet trajectories, or rogue DLLs.

YARA Pattern & Hex Signature Engine

ACTIVE

Inspects memory buffers against a server-synchronized database of known FiveM cheat strings, DirectX hook detours, and Lua injection stubs.

Local Identity & Peripheral Forensics

Discord Client LevelDB Account Correlator

ACTIVE

Inspects local Discord client LevelDB storage for unique numerical user IDs only (no private tokens collected). Discloses whether the user is playing under an alt.

USB Mass Storage Device History

ACTIVE

Examines USBSTOR registry entries and currently connected USB devices to identify flash drives used to load and inject cheats.

Browser Cheat Keyword Index

ACTIVE

Non-invasively compares recent browser history against an index of known FiveM cheat distribution domains and software loaders. Zero personal pages read.

Staff Workflow & Verification

Real-Time Telemetry & Progress Heartbeats

ACTIVE

The desktop client sends HMAC-SHA256 signed progress heartbeats every 2 seconds. Staff can see exact scan stages live on the web portal.

Case Notes & Decision Audit Trail

ACTIVE

Staff can log internal notes, record final verdicts (Approved, Flagged, Denied, Under Review), and reference past scan history across the community.

Instant PIN-Based Check Initiation

ACTIVE

Generate temporary 6-digit verification PINs so candidates can start a scan in seconds without registering an account.

PLANNED ROADMAP FEATURESUpcoming enhancements in active development
In Development (Q4)

Automated Discord Bot Voice-Channel Gatekeeper

An automated Discord bot that automatically moves candidates into a private "PC Check" voice channel, generates their PIN, and posts the completed report embed into private staff channels.

Architecture Phase (Q1)

Community Cross-Server Ban Intelligence Network

An opt-in shared threat intelligence network allowing FiveM servers to check if a player's hardware profile has been flagged for confirmed injection on participating servers.

Research Phase (Q1)

Virtualization-Based Security (VBS) Driver Verifier

Enhanced telemetry checking for vulnerable signed third-party kernel drivers (BYOVD exploits) commonly utilized by external cheat developers to bypass FiveM memory safeguards.

Prototype Phase (Q2)

Interactive Low-Latency Screen Frame Inspector

Secure ephemeral screen capture taken at scan initialization to confirm game screen state and active overlay hooks without saving persistent desktop recordings.

Ready to verify candidate PCs with Air.ac?

Setup takes less than two minutes. Create your server license or inspect our interactive PC check workflow.