Noxara

NoxShield Login

Noxara Anti-Cheat Suite

NoxaraNoxShield Dashboard

-
Active Sessions →
-
Max Clients / HWID
-
Firewall
-
Version

Recent Events

TimeAccountIDHWIDEventDetailSeverity

Active Sessions

IDAccountCharacterHWIDIPConnectedLast Sync

Flagged Cases (Audit Log)

Click a row to expand events and take action.

RiskPlayerAccountIDHWIDEventsSourcesSeverityLast Seen

HWID Bans

HWIDAccountCharacterIPReasonBanned ByBanned AtExpires

Behavioral Bot Scores

Live behavioral scoring of connected players. Scores accumulate from input telemetry every 30s and decay over time. Kick threshold: 60 | Ban threshold: 150 (tune in Settings tab)

HWIDAccount IDScoreReportsStatusLast Update

Suspect Queue

HWIDs ranked by composite reliable-signal score. Banned HWIDs sort to bottom. Score weights: CheatProcess hits ×1.0 (primary signal) • Distinct accounts ×3 capped at 30 • HWID-rotation count ×0.5 • Currently-online ×1.5 multiplier • Browser research (CovidHax_Window) ×0.2 • Capture mismatch ×0.01. Click "Open Dossier" to see full evidence before banning.

Score HWID CP hits Accts HWID rot Online Why this rank Last event Actions
Click Refresh to load.

Behavioral Anomalies

Server-side detectors that scan telemetry independently of the bot-score system. Both are usable today on existing v=1 telemetry; v=2 (QPC + key-identity) will sharpen accuracy further. Anomalies here are flags for review, not auto-actions — open the dossier and decide.

AFK key-farmer detector — roadmap §1.5

Flags HWIDs that emitted N+ telemetry windows with keys pressed while the mouse was fully stationary (keys≥5 & path_ent≤1 & clicks≤1 & straight=0). Strong AFK-pot fingerprint that does not depend on key-timing analysis, so it's immune to the unit/polling artifacts noted in feedback_check_units_before_acting.

HWIDAccount IDAFK WindowsTotal KeysFirst SeenLast Seen
Click Refresh to load.

HWID-volatility detector — roadmap §3.2

Flags accounts that bound to N+ distinct HWIDs in the lookback window. Threshold defaults to 6 (calibrated 2026-05-18 against PrimaryRO: 4 caught legitimate multi-PC players, 6 narrows to clear outliers). Honest player with 2 PCs will not flag; a HWID spoofer cycling identities every session will.

Account IDDistinct HWIDsFirst SeenLast Seen
Click Refresh to load.

Broadcast-macro suspects — roadmap §2.2

Flags currently-tracked HWIDs with N+ consecutive 0x0014 telemetry windows where keys were active (keys≥5 or clicks≥5) AND the game window was NOT in foreground (fg_match=0). Sustained pattern = broadcast macro injecting input into a backgrounded game window. Honest alt-tabs don't sustain. In-memory view: profiles age out 1h idle. For historical review open the HWID's Dossier.

HWIDAccount IDCurrent StreakPeak StreakScoreLast Update
Click Refresh to load.

HP-react autopot suspects — roadmap §1.3

HWIDs whose rolling 0x0034 reaction-time distribution shows mean < max_mean_us (default 80,000 µs = 80ms) over 10+ samples. Human reflex floor is ~150-200ms; sub-80ms with low variance = autopot. Requires 0x0034 events from the DLL's hp_correlator.cpp.

HWIDAccountSamplesMean (µs)StdDev (µs)Score
Click Refresh.

Injected-input suspects — roadmap §2.1

HWIDs with N+ observed 0x0035 EVT_INJECTED_INPUT events (external tool injecting WM_KEYDOWN from a non-keyboard-driver thread). Every event is +20 score and a panel-visible row. Legit overlay tools (Discord, Razer, NVIDIA) can be muted via Detector Config → Suspicious module allowlist — substring match against the from_module= field in the detail.

HWIDAccountCountScoreLast Update
Click Refresh.

Cheat Detection Heatmap

Map-level aggregation of detection events. Shows where cheating concentrates. Input anomaly events (behavioral telemetry) are excluded.

Autotrade hubs (gold_mart, prontera vending row) dominate the raw counts and drown out actual cheat hotspots. Add map-name substrings to exclude; the filter persists in this browser only.

Top Maps by Events

MapEventsBar

Select a map to view coordinates

Admin Accounts

IDUsernameRoleCreatedLast Login

Change My Password

Per-HWID Client Limit Overrides

HWIDMax ClientsLabelSet ByCreated

Threat Report

High-precision detections — cheat tools, injected input, and network hooks — grouped by machine. This is the signal; the volume counts at the bottom are mostly benign background noise.

🔴 Confirmed — cheat tools

High-precision: a known cheat/bot tool was running. This is act-on-it.

SignalWhatAccountCharHitsLast seenStatus

🟠 Needs review — lower confidence

Injected input and network hooks have real false positives — macro keyboards, AHK binds, VPN/overlay software all trip these. Not a ban on their own; open the dossier and look for a bot pattern (sustained, exact-interval, huge volume) before acting.

SignalWhatAccountCharHitsLast seenStatus

Recent bans

HWIDReasonByWhen

Detection volume — context, not threats

CodeDetectorEventsMachines

High counts on Suspicious Module and Screenshot Evasion are usually false positives (background apps, overlays) — they're logged, not acted on. The Confirmed threats table above is what needs your attention.

Battle Pass

XP is granted by the server (rAthena NPC) — the panel configures the season + rewards and can GM-override a player's progress. Tier curve: tier N costs 100 + 75×(N−1) XP (tier 1 = 100, tier 30 = 35,625 total).

Season & duration

A season is live when now is between Starts and Ends. Editing the dates changes the duration immediately. Delete removes the season + its reward grid; player XP/claims are kept unless you tick the box.

Rewards — 30 tiers × 2 tracks

Item ID is the rAthena item. Icon = identifiedResourceName from iteminfo. Set item ID to 0 to clear a slot.

TierXP Free Premium
itemqtyname / icon itemqtyname / icon
Player progress — GM override; XP change recomputes tier
AccountNameXPTier PremiumClaimed (free / prem)Actions

Global Settings

Captcha mode uses rAthena's built-in macro detection system. Ensure captcha images are registered in captcha_db.

Bot-Score Thresholds

Live behavioral scoring. When a player's cumulative score crosses Kick, they're disconnected. When it crosses Ban, the HWID is auto-banned. Scores decay over time (2 points/min) so transient noise doesn't accumulate.

Ban must be ≥ Kick — a ban-without-kick threshold makes no sense. Defaults: Kick=60, Ban=150 (tuned conservatively to avoid false positives during launch). Changes take effect immediately on next telemetry ingest, no sidecar restart.

In-Game Chat Translation

OpenAI-backed chat translation. Each player picks their language in noxshield.ini (chat_language); incoming foreign chat is translated into it. Enter your own OpenAI API key — usage is billed to your OpenAI account, so set daily/monthly caps to bound spend. Supported: English (en), Indonesian (id), Filipino (tl), Thai (th) + de/fr/es/pt/it/pl/ru/tr/ja/ko/zh/vi. Hot-reload: takes effect immediately, no restart.

Diagnostics Console

Run read-only diagnostic commands against this sidecar — no SSH needed. Type help for the list. Handy for translation: status (is it enabled + key set?), translate th Hello there (live test — shows the exact OpenAI error if it fails), logs 200 translate (recent translation activity).

Type a command and hit Run. 'help' lists what's available.

Sidecar Update

Pull + apply a new sidecar binary from the operator's update host. Applying RESTARTS the sidecar — connected players drop for ~10s (and this panel logs you out; just log back in). Downloads are verified (SHA-256 + signature) and auto-roll-back if the new build doesn't come up healthy, so a bad update can't take you offline.

Allowed DLL Hashes

SHA-256 of every NoxShield.dll build accepted at auth. One per line, 64-char hex (case-insensitive — saved as uppercase). Mismatched builds get OP_KICK at auth-time, so seed a new DLL hash before rolling it to players or you'll lock everyone out. Hot-reload: changes take effect on next auth, no sidecar restart, no active-session disconnects.

WARNING: empty list rejects ALL DLLs. Always keep at least the in-field hash + the new hash during a rollout, then prune the old hash one release cycle later.

Allowed EXE Hashes

SHA-256 of every primaryro.exe build accepted at auth. One per line, 64-char hex (case-insensitive — saved as uppercase). Empty list = open mode (every EXE accepted). Mismatched builds get OP_KICK at auth-time with the "Client outdated - please run the patcher to update" message. Hot-reload: changes take effect on next auth, no sidecar restart, no active-session disconnects.

WARNING: setting an EXE allowlist activates strict mode — players whose primaryro.exe hash isn't on the list will be rejected at auth. Empty list returns to open mode (no EXE check).

Image Attestation

Challenges each client to prove the in-memory NoxShield.dll matches a trusted reference image (defeats a dummy client that just absorbs the handshake). Reference .dll files live in the sidecar's reference_dir — one per shipped DLL build, dropped there once. Everything below is hot-reload: no sidecar restart, no active-session disconnects.

1. Reference images

Upload the exact NoxShield.dll you ship to players. The sidecar names it by its SHA-256 and stores it — no SSH, no path to type. One per shipped build.

2. Enforcement

Upload a reference first, then run log mode and watch for false-positives (every legit DLL build needs its own reference). Flip to kick only after a clean soak — and only once every shipped DLL hash has a reference here, or genuine players on an unreferenced build get kicked.

GRF Integrity

Server-authoritative check that each client's GRF content matches an Ed25519-signed feed (a client can't forge it — unlike the client-side manifest). The feed is generated by Patch Studio on each publish and pulled from feed_url. Enable/mode are hot-reload; feed_url + the pubkey are config-managed.

Run log mode first and watch the diag console (logs 50 grf) for [grf] FAIL — those tell you whether the feed matches what players actually run. Only flip to kick after a clean soak across a Star.grf change. A stale feed in kick mode mass-kicks players; the sidecar keeps the current + previous revision, covering one publish of lag.

LGP Map Blocklist

Maps where the client LGP skill-marker overlay must not render — one base map name per line, lowercase, no extension (e.g. prontera, prt_fild08). Pushed to every client live (no restart, no re-ship); players can't override it. Empty = LGP allowed everywhere.

Claude AI disabled

Optional. Powers two dossier actions: Summarize this player (writes a 200-word narrative GM brief) and Draft response (writes a player-facing reply for Discord/tickets). NOT used as a detector — verdicts still come from the rule-based pipeline. Claude just reads the dossier and writes it up.

API key from console.anthropic.com → Settings → API Keys. Stored in config.json (root:root mode 600). Key is masked in the UI after save; submit with the field blank to keep the existing key, or check "Clear key" to remove it.

Recent API calls this month

When (UTC)AdminActionHWIDTokens in/out$ USDError
No calls yet this month.

Captcha System

Master switch OFF halts all in-flight captcha queues immediately — the poller NPC stops firing macro_detector even for active queue rows. Independent from Enforcement Mode above.
Regenerate writes 100 fresh BMPs + a new captcha_db.yml to every configured rAthena instance. Run @reloaddb on each affected map-server afterward.

Pending captcha queue

Loading…

Lists pending + active captcha triggers. Cancel marks every queued row for the account as cancelled, so the in-game poller stops firing.

Per-Customer Detector Config

Each toggle filters events server-side before they hit the database, audit log, or Discord webhook. The DLL still runs every detector — only the sidecar's filter view changes. Edits persist to /opt/noxshield/config.json immediately; no restart required.

Enable / disable detectors

Hook detection

Packet replay

Heartbeat / periodic kRO opcodes. Identical-payload runs on these never flag.

Suspicious module

Common legit overlays / utilities to ignore.