AppData Scanner
Surfaces configs, logs and remnants that installed tools tend to leave behind in application storage.
Forensic scan · The main event
Hit Start Scan and Custos runs every scanner below in smart batches, each reporting its own live state — pending, active, done. A count badge means findings to review.
Surfaces configs, logs and remnants that installed tools tend to leave behind in application storage.
Reconstructs which programs have run on the machine — even ones since removed.
Surfaces which files were recently opened on the system.
Checks the game's own files for foreign or tampered components.
Examines system records that track which applications have been used.
Reviews browsing traces for signs of contact with cheat sources.
Inspects active processes for anything that shouldn't be running.
Checks game-platform accounts and their associated data.
Recovers a deeper record of program-execution history that Windows keeps.
Cross-checks system activity logs for recently executed programs.
Recovers traces of folder activity that persist after a folder is closed or deleted.
Detects virtual machines and sandboxes commonly used to mask cheat activity.
Looks for signs of suspicious network destinations the system recently contacted.
Audits system automation for entries used to keep cheats running.
Fingerprints files on the system and matches them against known cheat signatures.
Inspects active programs and their loaded components for cheat signatures.
Advanced · Optional
A separate, optional mode that inspects the running game's memory in real time — injected modules, code hooks, suspicious threads. If it's unavailable, that's fine: every forensic scanner above works without it.