How it works

Delete the file.
The evidence stays.

Every GORE scan runs five forensic layers against the parts of Windows that quietly log what executed. Below, each layer is shown with real-shaped scan output — click any terminal to re-run it.

The five forensic layers, and what the scan reports

LAYER 01

Execution artifacts

BAM, Amcache, ShimCache, UserAssist and SRUM each record program execution independently, and none of them lives inside the file that ran. GORE reads all five, stitches them into one timeline, and names any it could not read — so a deleted aimbot.exe still shows up with a run count and a last-run timestamp. Prefetch is read on top of those wherever Windows left it readable; where it was stored compressed instead, the scan says so in its coverage report rather than counting an artifact it never opened.

BAMAmcacheShimCacheUserAssistSRUMPrefetch
artifacts.scanlive
LAYER 02

Known-cheat signatures

Every execution record is matched against a live list of cheat brands and marketplace domains, pulled fresh from our servers at scan time. A hit names the brand — and because MUICache and the execution artifacts hold the name long after the binary is gone, the match survives the delete.

Brand listMarketplace domainsMUICacheAuto-updated
signature.scanlive
LAYER 03

Deleted-file traces

Deleting the binary does not delete the record of it. The NTFS change journal logs every create, rename and delete on the volume, and the Master File Table keeps the name, size and timestamps behind after the entry itself is freed — so a loader pulled into \Temp\, run once and wiped, still leaves a dated trail with the path it was wiped from.

$UsnJrnlMFTDeleted binariesStaging paths
deleted.scanlive
LAYER 04

Anti-forensic detection

The cover-up is the tell. Event logs cleared, a USN journal that was deleted or shrunk to bury its own record of deletions, a burst of files removed from a loader path inside a few seconds, timestamps back-dated to dates no file on the volume can legitimately claim, Windows' own prefetcher switched off in the registry or its folder emptied — GORE detects the clean-up itself and treats evasion as its own category.

Cleared logsJournal deletedTimestompingWiped Prefetch
antitamper.scanlive
LAYER 05

Cross-source correlation

One source can be edited; six agreeing is a different problem. GORE corroborates the independent write sources against each other — the USN journal, the MFT, UserAssist, BAM, ShimCache and the event logs — so a name scrubbed out of one still stands in the rest, and hours inside a powered-on session with no write activity anywhere read as a hole somebody made. It also reports its own blind spots by name: a volume it could not read, or an artifact held in a format this build cannot decode, is stated rather than quietly counted as clean.

CorroborationSilent windowsClock changesCoverage report
correlate.scanlive
THE RESULT

Gang dashboard

Owners see every member's status at a glance — from no evidence found to cheats found, with the findings behind each result and a coverage warning where the scan could not see everything. Keys are hardware-locked and non-transferable, and admins can assign or revoke them on the spot.

Owner viewHW-locked keysAssign / revoke
gore-dashlive
Setup

Four steps to a protected crew.

STEP 01

Buy & assign keys

Grab Solo or Gang keys and assign them to members from the dashboard. Each key is locked to one machine and valid for 30 days.

STEP 02

Member runs the agent

The member downloads the one-click agent for Windows 10/11 and runs a scan — no persistent install, nothing left behind.

STEP 03

Five layers run

Execution artifacts, cheat signatures, deleted-file traces, anti-forensics and cross-source correlation complete in about two to three minutes.

STEP 04

Verdict on the dashboard

The verdict — and the evidence behind it — appears on the owner dashboard for the whole gang.

gore setuplive
Scoped & authorized

Built to find cheats — used with consent.

GORE surfaces the evidence a cheat leaves behind — execution traces, signature matches, deletion bursts and evasion markers — for server administrators running authorized checks on their own communities. A finding is evidence for a human to weigh, not a verdict on a person, and a scan that finds nothing is reported as exactly that.

Keys are hardware-locked and time-limited, the agent leaves no background service, and results live on the owner's dashboard under their control.

Admin-authorized No persistence Hardware-locked keys 30-day validity
verdicts.streamlive
Next step

Give your staff receipts.

Pick a plan and run your first evidence-backed scan today.