Skip to content
View NetVar1337's full-sized avatar
💻
Developer | Reverse Engineer
💻
Developer | Reverse Engineer

Organizations

@BitterSecurity

Block or report NetVar1337

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NetVar1337/README.md

Markus Halvorsen

Independent research toward game-security analyst work. I do not work for a studio or an anti-cheat vendor.

The loop I practice: name the cheat class, measure a behavior, cohort it, write the query, and say what the evidence does not prove.

Work to judge

Repo What a reviewer can check
apex-anticheat-lab Clone and run detections/run_fixture.py. Synthetic fixture, per-cohort baselines, explainable scores. The investigation packet includes the case where a high-skill human outranks a recoil script on the composite.
cheat-intel How to grade a community claim. The landscape note marks its own weak sources.
account-security Account-takeover and session-abuse signals, as a graph rather than a login rate-limit.

How I would work a report

  1. Taxonomy first. Aimbot, triggerbot, ESP, DMA, macro, spoofing, boosting. Name the class, then the layer that can even see it.
  2. Behaviour over binaries. A signature dies on the next build. Aim kinematics, input timing, and account behavior survive the rewrite.
  3. Cohort before score. Mouse versus controller, rank, weapon. A pooled baseline is a false-positive machine.
  4. Explainable review queue. No auto-ban on one feature. Every flag carries the numbers that produced it.
  5. Measure enforcement. Match infection rate before and after, not the raw ban count. Replacement accounts fake a win.

What this profile is not

  • Not employment, and not a claim that any of this runs on a live game.
  • The lab fixture is synthetic. The investigation packet says so in the title.
  • YARA in the lab is a heuristic sketch. It is not an operational ruleset.
  • Kernel and hypervisor projects are not the work I want this profile judged on.

I also contribute to Decepticon, an authorized red-team agent. That is a different job. Do not read it as anti-cheat employment.

Open to game-security analyst and detection roles.

Pinned Loading

  1. BitterSecurity/Decepticon BitterSecurity/Decepticon Public

    Autonomous Hacking Agent for Red Team

    Python 5.7k 1.1k

  2. omniwire omniwire Public

    Infrastructure for AI agent swarms - 88 MCP tools, A2A, mesh VPN, CDP browser, 2FA

    TypeScript 17 7

  3. decepticon-ghidra-mcp decepticon-ghidra-mcp Public

    Ghidra MCP: P-code, BSim, version tracking, and emulation.

    Java 5