Forensic scan · The main event

16 scanners,
one click.

Hit Start Scan and Custos runs every scanner below in smart batches, each reporting its own live state — pending, active, done. A count badge means findings to review.

01✓ ready

AppData Scanner

Surfaces configs, logs and remnants that installed tools tend to leave behind in application storage.

02✓ ready

Prefetch Scanner

Reconstructs which programs have run on the machine — even ones since removed.

03✓ ready

Recent Files Scanner

Surfaces which files were recently opened on the system.

04✓ ready

Game Folder Scanner

Checks the game's own files for foreign or tampered components.

05✓ ready

Registry Scanner

Examines system records that track which applications have been used.

06✓ ready

Browser History Scanner

Reviews browsing traces for signs of contact with cheat sources.

07✓ ready

Process Scanner

Inspects active processes for anything that shouldn't be running.

08✓ ready

Steam Scanner

Checks game-platform accounts and their associated data.

09✓ ready

Amcache Scanner

Recovers a deeper record of program-execution history that Windows keeps.

10✓ ready

BAM / DAM Scanner

Cross-checks system activity logs for recently executed programs.

11✓ ready

Shellbags Scanner

Recovers traces of folder activity that persist after a folder is closed or deleted.

12✓ ready

VM Scanner

Detects virtual machines and sandboxes commonly used to mask cheat activity.

13✓ ready

DNS Cache Scanner

Looks for signs of suspicious network destinations the system recently contacted.

14✓ ready

Scheduled Tasks Scanner

Audits system automation for entries used to keep cheats running.

15✓ ready

File Hash Scanner

Fingerprints files on the system and matches them against known cheat signatures.

16✓ ready

Window & Module Scanner

Inspects active programs and their loaded components for cheat signatures.

Results export to custos-scan-YYYY-MM-DD.txt / .json — and a finding is a lead, not a conviction. Corroborate it with the manual check before you act.

Advanced · Optional

Live Scan

A separate, optional mode that inspects the running game's memory in real time — injected modules, code hooks, suspicious threads. If it's unavailable, that's fine: every forensic scanner above works without it.

All four must be true

  1. 01You're on Windows
  2. 02The native memory module is installed
  3. 03The game is currently running
  4. 04Custos runs as Administrator

The status banner tells you exactly where you stand

  • Checking Status
  • Windows Only
  • Native Unavailable
  • Game Not Running
  • Ready

Every finding carries a confidence level

  • highStrong signal — prioritize it.
  • suspiciousWorth a closer look.
  • infoContext, not an alarm.

Custos

The watchman for game servers