Cheat Engine
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã
Cheat Engine ã¯ãå®è¡äžã®ã²ãŒã ã®ã¡ã¢ãªå
ã«éèŠãªå€ãã©ãã«ä¿åãããŠããããèŠã€ããŠå€æŽããããã®äŸ¿å©ãªããã°ã©ã ã§ãã
ããŠã³ããŒãããŠå®è¡ãããšãããŒã«ã®äœ¿ãæ¹ã®ãã¥ãŒããªã¢ã«ã衚瀺ãããŸããããŒã«ã®äœ¿ãæ¹ãåŠã³ããå Žåã¯ããããå®äºããããšã匷ããå§ãããŸãã
äœãæ€çŽ¢ããŠããŸããïŒ
.png)
ãã®ããŒã«ã¯ãããã°ã©ã ã®ã¡ã¢ãªå
ã«ã©ãã«å€ïŒéåžžã¯æ°å€ïŒãä¿åãããŠããããèŠã€ããã®ã«éåžžã«äŸ¿å©ã§ãã
éåžžãæ°å€ã¯4ãã€ã圢åŒã§ä¿åãããŸãããããã«ããããŒã圢åŒã§èŠã€ããããšããããŸãããæ°å€ä»¥å€ã®äœããæ¢ãããšããããããããŸããããã®ãããæ€çŽ¢ããããã®ãéžæããããšã確èªããå¿
èŠããããŸãïŒ
.png)
ãŸããç°ãªãã¿ã€ãã®æ€çŽ¢ãæå®ããããšãã§ããŸãïŒ
.png)
ã¡ã¢ãªãã¹ãã£ã³ããŠããéã«ã²ãŒã ã忢ããããã®ãã§ãã¯ããã¯ã¹ããªã³ã«ããããšãã§ããŸãïŒ
.png)
ãããããŒ
Edit â> Settings â> Hotkeys ã§ã¯ãã²ãŒã ã忢ãããªã©ã®ç®çã®ããã«ç°ãªããããããŒãèšå®ã§ããŸãïŒããã¯ãã¡ã¢ãªãã¹ãã£ã³ããããšãã«éåžžã«äŸ¿å©ã§ãïŒãä»ã®ãªãã·ã§ã³ãå©çšå¯èœã§ãïŒ
.png)
å€ã®å€æŽ
æ¢ããŠããå€ãã©ãã«ããããèŠã€ãããïŒãã®ããšã«ã€ããŠã¯æ¬¡ã®ã¹ãããã§è©³ãã説æããŸãïŒããããããã«ã¯ãªãã¯ããŠã次ã«ãã®å€ãããã«ã¯ãªãã¯ããããšã§å€æŽã§ããŸãïŒ
.png)
æåŸã«ãã¡ã¢ãªå ã§å€æŽãè¡ãããã«ãã§ãã¯ãå ¥ããããšãå¿ èŠã§ãïŒ
.png)
ã¡ã¢ãªãžã®å€æŽã¯ããã«é©çšãããŸãïŒã²ãŒã ããã®å€ãå床䜿çšãããŸã§ãå€ã¯ã²ãŒã å ã§æŽæ°ãããŸããïŒã
å€ã®æ€çŽ¢
éèŠãªå€ïŒãŠãŒã¶ãŒã®ã©ã€ããªã©ïŒãæ¹åããããšä»®å®ãããã®å€ãã¡ã¢ãªå ã§æ¢ããŠãããšããŸãã
æ¢ç¥ã®å€æŽãéããŠ
å€100ãæ¢ããŠãããšä»®å®ãããã®å€ãæ€çŽ¢ããããã«ã¹ãã£ã³ãå®è¡ãããšãå€ãã®äžèŽãèŠã€ãããŸãïŒ
.png)
次ã«ãå€ã倿Žããããããªæäœãè¡ããã²ãŒã ã忢ããŠæ¬¡ã®ã¹ãã£ã³ãå®è¡ããŸãïŒ
.png)
Cheat Engineã¯ã100ããæ°ããå€ã«å€ãã£ãå€ãæ€çŽ¢ããŸããããã§ãšãããããŸããæ¢ããŠããã¢ãã¬ã¹ãèŠã€ããŸãããããã§ãå€ã倿Žã§ããŸãã
ãŸã è€æ°ã®å€ãããå Žåã¯ãå床ãã®å€ã倿Žããæäœãè¡ããããäžåºŠã次ã®ã¹ãã£ã³ããå®è¡ããŠã¢ãã¬ã¹ããã£ã«ã¿ãªã³ã°ããŸãã
äžæãªå€ãæ¢ç¥ã®å€æŽ
å€ãããããªãããã©ã®ããã«å€æŽããããïŒå€æŽã®å€ãå«ãïŒãç¥ã£ãŠããå Žåã¯ãæ°å€ãæ¢ãããšãã§ããŸãã
ãŸããäžæãªåæå€ã®ã¹ãã£ã³ãå®è¡ããŸãïŒ
.png)
次ã«ãå€ã倿Žããã©ã®ããã«ãã®å€ã倿Žããããã瀺ãïŒç§ã®å Žåã¯1æžå°ããŸããïŒã次ã®ã¹ãã£ã³ãå®è¡ããŸãïŒ
.png)
éžæããæ¹æ³ã§å€æŽããããã¹ãŠã®å€ã衚瀺ãããŸãïŒ
.png)
å€ãèŠã€ããããããã倿Žã§ããŸãã
å€ãã®å¯èœãªå€æŽãããããšã«æ³šæããçµæããã£ã«ã¿ãªã³ã°ããããã«ãããã®ã¹ããããäœåºŠã§ãè¡ãããšãã§ããŸãïŒ
.png)
ã©ã³ãã ã¡ã¢ãªã¢ãã¬ã¹ - ã³ãŒãã®çºèŠ
ãããŸã§ãå€ãä¿åããŠããã¢ãã¬ã¹ãèŠã€ããæ¹æ³ãåŠã³ãŸããããã²ãŒã ã®ç°ãªãå®è¡ã§ã¯ãã®ã¢ãã¬ã¹ãã¡ã¢ãªå ã®ç°ãªãå Žæã«ããå¯èœæ§ãé«ãã§ããã§ã¯ããã®ã¢ãã¬ã¹ãåžžã«èŠã€ããæ¹æ³ãèŠã€ããŸãããã
åè¿°ã®ããªãã¯ã®ããã€ãã䜿çšããŠãçŸåšã®ã²ãŒã ãéèŠãªå€ãä¿åããŠããã¢ãã¬ã¹ãèŠã€ããŸããæ¬¡ã«ïŒã²ãŒã ã忢ããŠãæ§ããŸããïŒãèŠã€ããã¢ãã¬ã¹ãå³ã¯ãªãã¯ãã**ããã®ã¢ãã¬ã¹ã«ã¢ã¯ã»ã¹ãããã®ãèŠã€ããããŸãã¯ããã®ã¢ãã¬ã¹ã«æžã蟌ããã®ãèŠã€ããã**ãéžæããŸãïŒ
.png)
æåã®ãªãã·ã§ã³ã¯ããã®ã¢ãã¬ã¹ã䜿çšããŠããã³ãŒãã®éšåãç¥ãã®ã«åœ¹ç«ã¡ãŸãïŒããã¯ãã²ãŒã ã®ã³ãŒãã倿Žã§ããå Žæãç¥ãã®ã«åœ¹ç«ã¡ãŸãïŒã
2çªç®ã®ãªãã·ã§ã³ã¯ããå
·äœçã§ããã®å€ãã©ãããæžã蟌ãŸããŠããããç¥ãã®ã«åœ¹ç«ã¡ãŸãã
ãããã®ãªãã·ã§ã³ã®ãããããéžæãããšããããã¬ãããã°ã©ã ã«æ¥ç¶ãããæ°ãã空ã®ãŠã£ã³ããŠã衚瀺ãããŸããä»ãã²ãŒã ããã¬ã€ãããã®å€ã倿ŽããŸãïŒã²ãŒã ãåèµ·åããã«ïŒããŠã£ã³ããŠã¯ãå€ã倿ŽããŠããã¢ãã¬ã¹ã§åãŸãã¯ãã§ãïŒ
.png)
å€ã倿ŽããŠããã¢ãã¬ã¹ãèŠã€ããããèªç±ã«ã³ãŒãã倿Žã§ããŸãïŒCheat Engineã§ã¯ãNOPã«ããã«å€æŽã§ããŸãïŒïŒ
.png)
ããã§ãã³ãŒããããªãã®æ°å€ã«åœ±é¿ãäžããªãããã«å€æŽããããšãã§ããŸãããåžžã«ãã©ã¹ã®åœ±é¿ãäžããããã«ããããšãã§ããŸãã
ã©ã³ãã ã¡ã¢ãªã¢ãã¬ã¹ - ãã€ã³ã¿ã®çºèŠ
åã®ã¹ãããã«åŸã£ãŠãèå³ã®ããå€ãã©ãã«ããããèŠã€ããŸããæ¬¡ã«ã**ããã®ã¢ãã¬ã¹ã«æžã蟌ããã®ãèŠã€ããã**ã䜿çšããŠããã®å€ãæžã蟌ãã¢ãã¬ã¹ãèŠã€ããããã«ã¯ãªãã¯ããŠãã£ã¹ã¢ã»ã³ããªãã¥ãŒãååŸããŸãïŒ
.png)
次ã«ãâ[]âã®éã®16鲿°å€ãæ€çŽ¢ããæ°ããã¹ãã£ã³ãå®è¡ããŸãïŒãã®å Žåã¯$edxã®å€ïŒïŒ
.png)
ïŒè€æ°ã®ã¢ãã¬ã¹ã衚瀺ãããå Žåã¯ãéåžžãæå°ã®ã¢ãã¬ã¹ã®ãã®ãå¿
èŠã§ãïŒ
ããã§ãèå³ã®ããå€ã倿Žãããã€ã³ã¿ãèŠã€ããŸããã
**ãã¢ãã¬ã¹ãæåã§è¿œå ã**ãã¯ãªãã¯ããŸãïŒ
.png)
次ã«ããã€ã³ã¿ã®ãã§ãã¯ããã¯ã¹ããªã³ã«ããããã¹ãããã¯ã¹ã«èŠã€ããã¢ãã¬ã¹ã远å ããŸãïŒãã®ã·ããªãªã§ã¯ãåã®ç»åã§èŠã€ããã¢ãã¬ã¹ã¯ãTutorial-i386.exeã+2426B0ã§ããïŒïŒ
.png)
ïŒæåã®ãã¢ãã¬ã¹ãã¯ãå ¥åãããã€ã³ã¿ã¢ãã¬ã¹ããèªåçã«å ¥åãããããšã«æ³šæããŠãã ããïŒ
OKãã¯ãªãã¯ãããšãæ°ãããã€ã³ã¿ãäœæãããŸãïŒ
.png)
ããã§ããã®å€ã倿Žãããã³ã«ãå€ãã©ã®ã¡ã¢ãªã¢ãã¬ã¹ã«ãã£ãŠãéèŠãªå€ã倿ŽããŠããŸãã
ã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³
ã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ã¯ãã¿ãŒã²ããããã»ã¹ã«ã³ãŒãã®äžéšãæ³šå ¥ãããã®åŸãã³ãŒãã®å®è¡ãèªåãæžããã³ãŒããééãããæè¡ã§ãïŒäŸãã°ããã€ã³ããäžãã代ããã«æžããããšãªãïŒã
ãã¬ã€ã€ãŒã®ã©ã€ããã1ãåŒããŠããã¢ãã¬ã¹ãèŠã€ãããšæ³åããŠãã ããïŒ
.png)
ãã£ã¹ã¢ã»ã³ãã©ã衚瀺ããŠãã£ã¹ã¢ã»ã³ãã«ã³ãŒããååŸããŸãã
次ã«ãCTRL+aãã¯ãªãã¯ããŠãªãŒãã¢ã»ã³ãã«ãŠã£ã³ããŠãåŒã³åºããTemplate â> Code Injection ãéžæããŸãã
.png)
倿Žãããåœä»€ã®ã¢ãã¬ã¹ãå ¥åããŸãïŒéåžžã¯èªåçã«å ¥åãããŸãïŒïŒ
.png)
ãã³ãã¬ãŒããçæãããŸãïŒ
.png)
ãã®ãããnewmemã»ã¯ã·ã§ã³ã«æ°ããã¢ã»ã³ããªã³ãŒããæ¿å ¥ããoriginalcodeããå ã®ã³ãŒããåé€ããŸãïŒå®è¡ããããªãå ŽåïŒããã®äŸã§ã¯ãæ³šå ¥ãããã³ãŒãã¯1ãåŒã代ããã«2ãã€ã³ãã远å ããŸãïŒ
.png)
å®è¡ãã¯ãªãã¯ãããšãããªãã®ã³ãŒããããã°ã©ã ã«æ³šå ¥ãããæ©èœã®åäœã倿Žãããã¯ãã§ãïŒ
Cheat Engine 7.xã®é«åºŠãªæ©èœïŒ2023-2025ïŒ
Cheat Engineã¯7.0以éé²åãç¶ããŠãããçŸä»£ã®ãœãããŠã§ã¢ïŒã²ãŒã ã ãã§ãªãïŒïŒãåæããéã«éåžžã«äŸ¿å©ãªç掻ã®è³ªãæ»æçãªããŒã¹æ©èœã远å ãããŠããŸãã以äžã¯ãã¬ããããŒã /CTFäœæ¥äžã«æã䜿çšããå¯èœæ§ãé«ãè¿œå æ©èœã®éåžžã«ç°¡æœãªãã£ãŒã«ãã¬ã€ãã§ãã
ãã€ã³ã¿ã¹ãã£ããŒ2ã®æ¹å
ãã€ã³ã¿ã¯ç¹å®ã®ãªãã»ããã§çµäºããå¿ èŠããããŸããæ°ããDeviationã¹ã©ã€ããŒïŒâ¥7.4ïŒã¯ãæŽæ°åŸã«åã¹ãã£ã³ããéã®èª€æ€ç¥ãå€§å¹ ã«æžå°ãããŸããããããã«ããããæ¯èŒïŒ.PTRâ ä»ã®ä¿åããããã€ã³ã¿ããããšçµæãæ¯èŒïŒãšçµã¿åãããŠããããæ°åã§åäžã®èé害æ§ããŒã¹ãã€ã³ã¿ãååŸããŸãã- ãã«ã¯ãã£ã«ã¿ã·ã§ãŒãã«ããïŒæåã®ã¹ãã£ã³åŸã«
Ctrl+A â SpaceãæŒããŠãã¹ãŠãããŒã¯ããæ¬¡ã«Ctrl+IïŒå転ïŒãæŒããŠåã¹ãã£ã³ã«å€±æããã¢ãã¬ã¹ãéžæè§£é€ããŸãã
Ultimap 3 â Intel PTãã¬ãŒã¹
*7.5以éãå€ãUltimapã¯Intel Processor-Trace (IPT)ã®äžã«åå®è£ ãããŸãããããã«ãããã¿ãŒã²ãããåããã¹ãŠã®åå²ãåäžã¹ããããªãã§èšé²ã§ããããã«ãªããŸããïŒãŠãŒã¶ãŒã¢ãŒãã®ã¿ãã»ãšãã©ã®ã¢ã³ããããã°ã¬ãžã§ããã«ã¯åŒã£ããããŸããïŒã
Memory View â Tools â Ultimap 3 â check «Intel PT»
Select number of buffers â Start
æ°ç§åŸã«ãã£ããã£ã忢ããå³ã¯ãªã㯠â å®è¡ãªã¹ãããã¡ã€ã«ã«ä¿åããŸãããã©ã³ãã¢ãã¬ã¹ã Find out what addresses this instruction accesses ã»ãã·ã§ã³ãšçµã¿åãããŠãé«é »åºŠã®ã²ãŒã ããžãã¯ãããã¹ããããéåžžã«è¿
éã«ç¹å®ããŸãã
1ãã€ã jmp / èªåããããã³ãã¬ãŒã
ããŒãžã§ã³7.5ã§ã¯ãSEHãã³ãã©ãã€ã³ã¹ããŒã«ããå ã®äœçœ®ã«INT3ãé 眮ãã1ãã€ã JMPã¹ã¿ãïŒ0xEBïŒãå°å ¥ãããŸãããããã¯ã5ãã€ãã®çžå¯Ÿãžã£ã³ãã§ãããã§ããªãåœä»€ã«å¯ŸããŠAuto Assembler â Template â Code Injectionã䜿çšãããšèªåçã«çæãããŸããããã«ãããããã¯ãããããµã€ãºå¶çŽã®ããã«ãŒãã³å ã§ãã¿ã€ãããªããã¯ãå¯èœã«ãªããŸãã
ã«ãŒãã«ã¬ãã«ã®ã¹ãã«ã¹ãšDBVMïŒAMD & IntelïŒ
DBVMã¯CEã®çµã¿èŸŒã¿Type-2ãã€ããŒãã€ã¶ãŒã§ããæè¿ã®ãã«ãã§ã¯ãAMD-V/SVMãµããŒãã远å ãããRyzen/EPYCãã¹ãã§Driver â Load DBVMãå®è¡ã§ããããã«ãªããŸãããDBVMã䜿çšãããšïŒ
- Ring-3/ã¢ã³ããããã°ãã§ãã¯ã«å¯ŸããŠèŠããªãããŒããŠã§ã¢ãã¬ãŒã¯ãã€ã³ããäœæã§ããŸãã
- ãŠãŒã¶ãŒã¢ãŒããã©ã€ããç¡å¹ã«ãªã£ãŠããå Žåã§ããããŒãžã³ã°å¯èœãŸãã¯ä¿è·ãããã«ãŒãã«ã¡ã¢ãªé åãèªã¿æžãã§ããŸãã
- VM-EXITãªãã®ã¿ã€ãã³ã°æ»æãã€ãã¹ãå®è¡ã§ããŸãïŒäŸïŒãã€ããŒãã€ã¶ãŒãã
rdtscãã¯ãšãªïŒã
ãã³ãïŒ Windows 11ã§HVCI/ã¡ã¢ãªæŽåæ§ãæå¹ã«ãªã£ãŠãããšãDBVMã¯èªã¿èŸŒãããšãæåŠããŸã â ç¡å¹ã«ããããå°çšã®VMãã¹ããèµ·åããŠãã ããã
ãªã¢ãŒã / ã¯ãã¹ãã©ãããã©ãŒã ãããã°ãšceserver
CEã¯çŸåšãceserverã®å®å šãªæžãæããæäŸããLinuxãAndroidãmacOS & iOSã¿ãŒã²ããã«TCPã§æ¥ç¶ã§ããŸãã人æ°ã®ãã©ãŒã¯ã¯Fridaãçµ±åããåçèšæž¬ãšCEã®GUIãçµã¿åãããŸã â é»è©±ã§å®è¡ãããŠããUnityãŸãã¯Unrealã²ãŒã ããããããå¿ èŠãããå Žåã«æé©ã§ãïŒ
# on the target (arm64)
./ceserver_arm64 &
# on the analyst workstation
adb forward tcp:52736 tcp:52736 # (or ssh tunnel)
Cheat Engine â "Network" icon â Host = localhost â Connect
For the Frida bridge see bb33bb/frida-ceserver on GitHub.
ãã®ä»ã®æ³šç®ãã¹ãæ©èœ
- Patch Scanner (MemView â Tools) â å®è¡å¯èœã»ã¯ã·ã§ã³ã®äºæããªãã³ãŒã倿Žãæ€åº; ãã«ãŠã§ã¢åæã«äŸ¿å©ã§ãã
- Structure Dissector 2 â ã¢ãã¬ã¹ããã©ãã° â
Ctrl+Dãæ¬¡ã« Guess fields ã§Cæ§é äœãèªåè©äŸ¡ããŸãã - .NET & Mono Dissector â Unityã²ãŒã ã®ãµããŒããæ¹åãããŸãã; CE Luaã³ã³ãœãŒã«ããçŽæ¥ã¡ãœãããåŒã³åºããŸãã
- Big-Endianã«ã¹ã¿ã ã¿ã€ã â ãã€ãé åºãéã«ããŠã¹ãã£ã³/ç·šéïŒã³ã³ãœãŒã«ãšãã¥ã¬ãŒã¿ãŒããããã¯ãŒã¯ãã±ãããããã¡ã«äŸ¿å©ã§ãïŒã
- Autosave & tabs for AutoAssembler/LuaãŠã£ã³ããŠãããã«
reassemble()ã§è€æ°è¡ã®åœä»€ãæžãæããŸãã
ã€ã³ã¹ããŒã« & OPSECããŒã (2024-2025)
- å
¬åŒã€ã³ã¹ããŒã©ãŒã¯InnoSetup åºåãªãã¡ãŒïŒ
RAVãªã©ïŒã§ã©ãããããŠããŸããåžžã« Decline ãã¯ãªã㯠ãããããœãŒã¹ããã³ã³ãã€ã«ããŠPUPãé¿ããŠãã ãããAVã¯äŸç¶ãšããŠcheatengine.exeã HackTool ãšããŠãã©ã°ããŸãããããã¯äºæ³ãããããšã§ãã - çŸä»£ã®ã¢ã³ãããŒããã©ã€ããŒïŒEAC/BattleyeãACE-BASE.sysãmhyprot2.sysïŒã¯ãååã倿ŽããŠãCEã®ãŠã£ã³ããŠã¯ã©ã¹ãæ€åºããŸãããªããŒã¹ã³ããŒãäœ¿ãæšãŠã®VMå ã§å®è¡ãããããããã¯ãŒã¯ãã¬ã€ãç¡å¹ã«ããåŸã«å®è¡ããŠãã ããã
- ãŠãŒã¶ãŒã¢ãŒãã¢ã¯ã»ã¹ã®ã¿ãå¿
èŠãªå Žåã¯ã
Settings â Extra â Kernel mode debug = offãéžæããŠãWindows 11 24H2 Secure-Bootã§BSODãåŒãèµ·ããå¯èœæ§ã®ããCEã®çœ²åãããŠããªããã©ã€ããŒã®èªã¿èŸŒã¿ãé¿ããŠãã ããã
åèæç®
- Cheat Engine 7.5 release notes (GitHub)
- frida-ceserver cross-platform bridge
- Cheat Engineãã¥ãŒããªã¢ã«ãCheat Engineã®äœ¿ãæ¹ãåŠã¶ããã«å®äºããŠãã ãã
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã


