ios reverse engineering — game engines, obfuscation, anti-cheat internals
i reverse iOS game binaries and write down how the internals actually work — the engines, the string obfuscation, the hooking, and the anti-cheat that sits on top of all of it. everything is read-only, analysis-oriented, and stops at understanding on purpose.
- engines — unreal engine 4 (
GWorld/GNames/ProcessEvent/FName), unity il2cpp, roblox's luau vm, netease's messiah (ecs + python gameplay layer) - the low level — arm64/arm64e by hand: inline hooks, W^X, instruction relocation, PAC, XOR string deobfuscation
- anti-cheat — how tencent's ACE (
anogs) is built, and why the naive attacks on it crash or ban instead of working
a connected series — each one leans on the last. start at the hub:
- ios-ue4-re — the index for the whole series, plus how the pieces fit together
- ios-binary-re-notes — the groundwork: decrypt, slice, load, read an iOS app at all
- xor-string-deobf-notes — breaking XOR string obfuscation and pulling every hidden string statically
- arm64-ios-inline-hook-notes — inline hooks by hand, and the four things that crash you
- ue4-ios-gworld-gnames-notes — the two globals everything hangs off, and the anti-tamper traps around them
- ue4-ios-fname-notes — turning
an FName index into a string by walking
FNamePool - ue4-ios-processevent-notes —
finding
ProcessEvent, the funnel every UFunction call goes through - tencent-ace-anogs-notes — how ACE is built and why the easy attacks fail — analysis, not a bypass
- roblox-ios-luau-vm-notes —
reversing roblox's luau runtime on iOS: functions, anchors,
lua_Statelayout - ios-messiah-re — reversing
netease's messiah engine: an ecs with no
GWorld, a python gameplay layer, and telemetry anti-cheat - ida-pro-guide — a practical guide to getting around a binary in IDA
- Reveal — a ~500-line skeleton ESP for UE4
on iOS. the concrete version of every note above: read
GWorld, walk the actors, project the bones, draw. read-only. - unity-il2cpp-esp-tutorial —
the unity side: a native objc esp for an il2cpp game, from
dump.csto lines on screen with plain uikit. no imgui, no drawing hooks.
questions about any of it go to the discussions; something wrong in a note → open a correction.
for research and defensive purposes. the repos don't ship attacks — they stop at how things work.



