This account is using a first-login placeholder password.
Set a new password now to access the rest of the panel.
NoxShield Dashboard
-
Active Sessions →
-
Max Clients / HWID
-
Firewall
-
Version
-
AFK Farmers / 24h →
-
HWID Volatility / 24h →
-
Flagged Cases →
Recent Events
Time
Account
ID
HWID
Event
Detail
Severity
Active Sessions
ID
Account
Character
HWID
IP
Connected
Last Sync
Flagged Cases (Audit Log)
Click a row to expand events and take action.
Risk
Player
Account
ID
HWID
Events
Sources
Severity
Last Seen
HWID Bans
HWID
Account
Character
IP
Reason
Banned By
Banned At
Expires
Player / Account Search
Search by character name, account name, or account ID to find associated HWIDs.
Click a row to expand details inline, or "Open Dossier" for the full per-entity investigation view.
Account
Account ID
Character
HWID
Last Seen
Status
Behavioral Bot Scores
Live behavioral scoring of connected players. Scores accumulate from input telemetry every 30s and decay over time. Kick threshold: 60 | Ban threshold: 150(tune in Settings tab)
HWID
Account ID
Score
Reports
Status
Last Update
Suspect Queue
HWIDs ranked by composite reliable-signal score. Banned HWIDs sort to bottom.
Score weights: CheatProcess hits ×1.0 (primary signal) • Distinct accounts ×3 capped at 30 • HWID-rotation count ×0.5 • Currently-online ×1.5 multiplier • Browser research (CovidHax_Window) ×0.2 • Capture mismatch ×0.01.
Click "Open Dossier" to see full evidence before banning.
Score
HWID
CP hits
Accts
HWID rot
Online
Why this rank
Last event
Actions
Click Refresh to load.
Behavioral Anomalies
Server-side detectors that scan telemetry independently of the bot-score system. Both are usable today on existing v=1 telemetry; v=2 (QPC + key-identity) will sharpen accuracy further.
Anomalies here are flags for review, not auto-actions — open the dossier and decide.
AFK key-farmer detector — roadmap §1.5
Flags HWIDs that emitted N+ telemetry windows with keys pressed while the mouse was fully stationary (keys≥5 & path_ent≤1 & clicks≤1 & straight=0). Strong AFK-pot fingerprint that does not depend on key-timing analysis, so it's immune to the unit/polling artifacts noted in feedback_check_units_before_acting.
HWID
Account ID
AFK Windows
Total Keys
First Seen
Last Seen
Click Refresh to load.
HWID-volatility detector — roadmap §3.2
Flags accounts that bound to N+ distinct HWIDs in the lookback window. Threshold defaults to 6 (calibrated 2026-05-18 against PrimaryRO: 4 caught legitimate multi-PC players, 6 narrows to clear outliers).
Honest player with 2 PCs will not flag; a HWID spoofer cycling identities every session will.
Account ID
Distinct HWIDs
First Seen
Last Seen
Click Refresh to load.
Broadcast-macro suspects — roadmap §2.2
Flags currently-tracked HWIDs with N+ consecutive 0x0014 telemetry windows where keys were active (keys≥5 or clicks≥5) AND the game window was NOT in foreground (fg_match=0). Sustained pattern = broadcast macro injecting input into a backgrounded game window. Honest alt-tabs don't sustain.
In-memory view: profiles age out 1h idle. For historical review open the HWID's Dossier.
HWID
Account ID
Current Streak
Peak Streak
Score
Last Update
Click Refresh to load.
HP-react autopot suspects — roadmap §1.3
HWIDs whose rolling 0x0034 reaction-time distribution shows mean < max_mean_us (default 80,000 µs = 80ms) over 10+ samples. Human reflex floor is ~150-200ms; sub-80ms with low variance = autopot. Requires 0x0034 events from the DLL's hp_correlator.cpp.
HWID
Account
Samples
Mean (µs)
StdDev (µs)
Score
Click Refresh.
Injected-input suspects — roadmap §2.1
HWIDs with N+ observed 0x0035 EVT_INJECTED_INPUT events (external tool injecting WM_KEYDOWN from a non-keyboard-driver thread). Every event is +20 score and a panel-visible row. Legit overlay tools (Discord, Razer, NVIDIA) can be muted via Detector Config → Suspicious module allowlist — substring match against the from_module= field in the detail.
HWID
Account
Count
Score
Last Update
Click Refresh.
Cheat Detection Heatmap
Map-level aggregation of detection events. Shows where cheating concentrates. Input anomaly events (behavioral telemetry) are excluded.
Autotrade hubs (gold_mart, prontera vending row) dominate the raw counts and drown out actual cheat hotspots. Add map-name substrings to exclude; the filter persists in this browser only.
Top Maps by Events
Map
Events
Bar
Select a map to view coordinates
Admin Accounts
ID
Username
Role
Created
Last Login
Change My Password
Per-HWID Client Limit Overrides
HWID
Max Clients
Label
Set By
Created
Threat Report
High-precision detections — cheat tools, injected input, and network hooks — grouped by machine. This is the signal; the volume counts at the bottom are mostly benign background noise.
🔴 Confirmed — cheat tools
High-precision: a known cheat/bot tool was running. This is act-on-it.
Signal
What
Account
Char
Hits
Last seen
Status
🟠 Needs review — lower confidence
Injected input and network hooks have real false positives — macro keyboards, AHK binds, VPN/overlay software all trip these. Not a ban on their own; open the dossier and look for a bot pattern (sustained, exact-interval, huge volume) before acting.
Signal
What
Account
Char
Hits
Last seen
Status
Recent bans
HWID
Reason
By
When
Detection volume — context, not threats
Code
Detector
Events
Machines
High counts on Suspicious Module and Screenshot Evasion are usually false positives (background apps, overlays) — they're logged, not acted on. The Confirmed threats table above is what needs your attention.
Battle Pass
XP is granted by the server (rAthena NPC) — the panel configures the season + rewards and can GM-override a player's progress. Tier curve: tier N costs 100 + 75×(N−1) XP (tier 1 = 100, tier 30 = 35,625 total).
Season & duration
A season is live when now is between Starts and Ends. Editing the dates changes the duration immediately. Delete removes the season + its reward grid; player XP/claims are kept unless you tick the box.
Rewards — 30 tiers × 2 tracks
Item ID is the rAthena item. Icon = identifiedResourceName from iteminfo. Set item ID to 0 to clear a slot.
Tier
XP
Free
Premium
item
qty
name / icon
item
qty
name / icon
Player progress — GM override; XP change recomputes tier
Account
Name
XP
Tier
Premium
Claimed (free / prem)
Actions
Global Settings
Captcha mode uses rAthena's built-in macro detection system. Ensure captcha images are registered in captcha_db.
Bot-Score Thresholds
Live behavioral scoring. When a player's cumulative score crosses Kick, they're disconnected. When it crosses Ban, the HWID is auto-banned. Scores decay over time (2 points/min) so transient noise doesn't accumulate.
Ban must be ≥ Kick — a ban-without-kick threshold makes no sense.
Defaults: Kick=60, Ban=150 (tuned conservatively to avoid false positives during launch).
Changes take effect immediately on next telemetry ingest, no sidecar restart.
In-Game Chat Translation
OpenAI-backed chat translation. Each player picks their language in noxshield.ini
(chat_language); incoming foreign chat is translated into it. Enter your own
OpenAI API key — usage is billed to your OpenAI account, so set daily/monthly caps to bound spend.
Supported: English (en), Indonesian (id), Filipino (tl), Thai (th) + de/fr/es/pt/it/pl/ru/tr/ja/ko/zh/vi.
Hot-reload: takes effect immediately, no restart.
…
Diagnostics Console
Run read-only diagnostic commands against this sidecar — no SSH needed. Type help for the list.
Handy for translation: status (is it enabled + key set?), translate th Hello there
(live test — shows the exact OpenAI error if it fails), logs 200 translate (recent translation activity).
Type a command and hit Run. 'help' lists what's available.
Sidecar Update
Pull + apply a new sidecar binary from the operator's update host. Applying RESTARTS the sidecar — connected players drop for ~10s (and this panel logs you out; just log back in). Downloads are verified (SHA-256 + signature) and auto-roll-back if the new build doesn't come up healthy, so a bad update can't take you offline.
Allowed DLL Hashes
SHA-256 of every NoxShield.dll build accepted at auth. One per line, 64-char hex (case-insensitive — saved as uppercase).
Mismatched builds get OP_KICK at auth-time, so seed a new DLL hash before rolling it to players or you'll lock everyone out.
Hot-reload: changes take effect on next auth, no sidecar restart, no active-session disconnects.
WARNING: empty list rejects ALL DLLs. Always keep at least the in-field hash + the new hash during a rollout, then prune the old hash one release cycle later.
Allowed EXE Hashes
SHA-256 of every primaryro.exe build accepted at auth. One per line, 64-char hex (case-insensitive — saved as uppercase).
Empty list = open mode (every EXE accepted). Mismatched builds get OP_KICK at auth-time with the "Client outdated - please run the patcher to update" message.
Hot-reload: changes take effect on next auth, no sidecar restart, no active-session disconnects.
WARNING: setting an EXE allowlist activates strict mode — players whose primaryro.exe hash isn't on the list will be rejected at auth. Empty list returns to open mode (no EXE check).
Image Attestation …
Challenges each client to prove the in-memory NoxShield.dll matches a trusted reference image (defeats a dummy client that just absorbs the handshake).
Reference .dll files live in the sidecar's reference_dir — one per shipped DLL build, dropped there once.
Everything below is hot-reload: no sidecar restart, no active-session disconnects.
1. Reference images
Upload the exact NoxShield.dll you ship to players. The sidecar names it by its SHA-256 and stores it — no SSH, no path to type. One per shipped build.
2. Enforcement
Upload a reference first, then run log mode and watch for false-positives (every legit DLL build needs its own reference). Flip to kick only after a clean soak — and only once every shipped DLL hash has a reference here, or genuine players on an unreferenced build get kicked.
GRF Integrity …
Server-authoritative check that each client's GRF content matches an Ed25519-signed feed (a client can't forge it — unlike the client-side manifest). The feed is generated by Patch Studio on each publish and pulled from feed_url. Enable/mode are hot-reload; feed_url + the pubkey are config-managed.
Run log mode first and watch the diag console (logs 50 grf) for [grf] FAIL — those tell you whether the feed matches what players actually run. Only flip to kick after a clean soak across a Star.grf change. A stale feed in kick mode mass-kicks players; the sidecar keeps the current + previous revision, covering one publish of lag.
LGP Map Blocklist
Maps where the client LGP skill-marker overlay must not render — one base map name per line, lowercase, no extension (e.g. prontera, prt_fild08). Pushed to every client live (no restart, no re-ship); players can't override it. Empty = LGP allowed everywhere.
Claude AI disabled
Optional. Powers two dossier actions: Summarize this player (writes a 200-word narrative GM brief) and Draft response (writes a player-facing reply for Discord/tickets). NOT used as a detector — verdicts still come from the rule-based pipeline. Claude just reads the dossier and writes it up.
API key from console.anthropic.com → Settings → API Keys. Stored in config.json (root:root mode 600). Key is masked in the UI after save; submit with the field blank to keep the existing key, or check "Clear key" to remove it.
Recent API calls this month
When (UTC)
Admin
Action
HWID
Tokens in/out
$ USD
Error
No calls yet this month.
Captcha System
Master switch OFF halts all in-flight captcha queues immediately — the poller NPC stops firing macro_detector even for active queue rows. Independent from Enforcement Mode above.
Regenerate writes 100 fresh BMPs + a new captcha_db.yml to every configured rAthena instance. Run @reloaddb on each affected map-server afterward.
Pending captcha queue
Loading…
Lists pending + active captcha triggers. Cancel marks every queued row for the account as cancelled, so the in-game poller stops firing.
Per-Customer Detector Config
Each toggle filters events server-side before they hit the database, audit log, or Discord webhook.
The DLL still runs every detector — only the sidecar's filter view changes. Edits persist to
/opt/noxshield/config.json immediately; no restart required.
Enable / disable detectors
Hook detection
Packet replay
Heartbeat / periodic kRO opcodes. Identical-payload runs on these never flag.