Manipulation always leaves a trace.

Lyphere builds detection systems for the places where hardware and software lie about themselves — and the evidence that still holds up after the ban.

session inspection live
session
a7f3·2e91·bd04
captured
smbios
5c1d·9ab0·e401
consistent
gpu uuid
GPU-4f8e·11d2·c21a
consistent
nvme s/n
9F2A → 44E1
rotated mid-session
verdict spoofing detected · confidence 0.94

How detection works

01

signal

A cheat can hide itself. Its behaviour cannot.

Rules across combat, movement, entities, integrity, identity, native calls and connection. Input timing and combo shape. Origin classification against a VPN, datacenter and Tor corpus. Hardware-token correlation that links accounts a player believes are separate.

02

evidence

A suspicion is not proof. We store the proof.

Every trigger writes a case: which signal fired, the values that fired it, when, and how long it is kept. Exportable and reviewable — because the moment a ban is disputed, a score is worth nothing and a record is worth everything.

03

verdict

No account is ended by a language model.

The model summarises and correlates; it does not decide. Thresholds, escalation and enforcement mode are set per rule, and anything terminal is confirmed by a person. Fewer false positives, and an operator who can explain every decision they made.

Product

hoaxeye

Anti-cheat for FiveM servers. Rule engine, evidence store, cross-server ban context, self-hosted analysis.

hoaxeye.net
2.14M anti-VPN entries from 16 sources, refreshed every 24 hours
20 configurable detection rules with per-server thresholds
29 tracer tokens for cheat fingerprinting
4 servers in separated trust zones

Where this applies

The pipeline is the same everywhere. The deployment never is.

Anti-cheat is the hardest school detection has: adversaries with kernel access who iterate daily. The discipline that survives there — signal, evidence, verdict — transfers to any field where systems are manipulated for advantage. We build each deployment to fit its field: its own signals, its own thresholds, its own evidence model.

Start with your field's signals →

Where manipulation happens

ring −1 · hypervisor ring 0 · kernel ring 3 · app
  • ring 3

    Application layer

    Rewriting what user space reports is cheap and widely tooled. A check that only reads the value a process hands it is checking the attacker's own answer.

  • ring 0

    Kernel

    A signed driver can reshape firmware tables, storage serials, GPU UUIDs and NIC identity into one coherent fake machine. Detection has to compare layers against each other instead of trusting any single one.

  • ring −1

    Hypervisor

    A CPU-enforced boundary the guest cannot see past. What stays observable is behaviour: timing, topology, and combinations a real machine would never report.

Legacy rings 1 and 2 go unused on modern operating systems — the boundaries that matter are −1, 0 and 3. Every layer above a manipulated one inherits the lie, which is why coherence across layers is the most durable signal there is.

Reverse engineering

You cannot detect what you have not taken apart.

Every rule we ship started as someone opening an artifact and finding out what it really does. That work does not stop at the software we defend — it runs on the software that attacks it, and on products we are asked to examine. Defects we find in someone else's code go to that vendor first.

We publish after the fix. Never before, never for leverage.

Disclosure policy
  1. day 0 report
  2. day 7 acknowledge
  3. vendor fix
  4. day 90 publish

Most of this feeds our own detection. Some of it is done for other people's software — if you need something taken apart by someone who hands you the report and keeps nothing, talk to the engineer →

Language models in the loop

No account is ended by a language model. Choosing one still matters.

In our pipeline the model holds exactly one seat: it summarises cases and correlates evidence — it never decides. That seat has hard requirements: structured output that parses every time, context long enough for a full case, a price that survives thousands of cases, and a fabrication rate that never invents evidence. Rated for that seat only — not a general ranking.

Claude Sonnet 5 — structured output: 5/5 Claude Sonnet 5 — evidence context: 5/5 Claude Sonnet 5 — cost per case: 3.5/5 Claude Sonnet 5 — self-host: 1.5/5 Claude Sonnet 5 — fabrication resistance: 4.5/5 Claude Haiku 4.5 — structured output: 4/5 Claude Haiku 4.5 — evidence context: 3.5/5 Claude Haiku 4.5 — cost per case: 4.5/5 Claude Haiku 4.5 — self-host: 1.5/5 Claude Haiku 4.5 — fabrication resistance: 3.5/5 GPT-5.6 Terra — structured output: 4.5/5 GPT-5.6 Terra — evidence context: 5/5 GPT-5.6 Terra — cost per case: 4/5 GPT-5.6 Terra — self-host: 1.5/5 GPT-5.6 Terra — fabrication resistance: 4/5 Claude Opus 5 — structured output: 5/5 Claude Opus 5 — evidence context: 5/5 Claude Opus 5 — cost per case: 3/5 Claude Opus 5 — self-host: 1.5/5 Claude Opus 5 — fabrication resistance: 5/5 Gemini 3.1 Pro — structured output: 4/5 Gemini 3.1 Pro — evidence context: 2/5 Gemini 3.1 Pro — cost per case: 4/5 Gemini 3.1 Pro — self-host: 1.5/5 Gemini 3.1 Pro — fabrication resistance: 4/5 DeepSeek V4 — structured output: 3.5/5 DeepSeek V4 — evidence context: 2/5 DeepSeek V4 — cost per case: 3/5 DeepSeek V4 — self-host: 5/5 DeepSeek V4 — fabrication resistance: 3.5/5 Llama 4 Maverick — structured output: 2.5/5 Llama 4 Maverick — evidence context: 2/5 Llama 4 Maverick — cost per case: 3/5 Llama 4 Maverick — self-host: 5/5 Llama 4 Maverick — fabrication resistance: 2.5/5 Gemini 2.5 Flash-Lite — structured output: 2/5 Gemini 2.5 Flash-Lite — evidence context: 2/5 Gemini 2.5 Flash-Lite — cost per case: 5/5 Gemini 2.5 Flash-Lite — self-host: 1.5/5 Gemini 2.5 Flash-Lite — fabrication resistance: 1.5/5

Our seat rating, 0–5 — engineering judgment against the criteria above, not a benchmark.

as of 2026-07-26 one case ≈ 8k tokens of evidence in, 500 tokens of summary out
  • Claude Sonnet 5 Anthropic
    context
    1M tokens
    per case
    $0.032
    self-host
    no
    fit

    Dependable structured output and room for any evidence bundle, at a price that survives case volume.

  • Claude Haiku 4.5 Anthropic
    context
    200k tokens
    per case
    $0.011
    self-host
    no
    fit

    The economical seat for routine cases; complex cross-case correlation gets escalated to a larger model.

  • GPT-5.6 Terra OpenAI
    context
    1M tokens
    per case
    $0.028
    self-host
    no
    fit

    Mid-tier of the July 2026 family: reliable schema-bound output at case-volume prices.

  • Claude Opus 5 Anthropic
    context
    1M tokens
    per case
    $0.053
    self-host
    no
    conditional

    Flagship reasoning earns its price on the hardest correlation work — not on every routine case.

  • Gemini 3.1 Pro Google
    context
    per case
    $0.022
    self-host
    no
    conditional

    Strong and well priced, but still labelled preview — an evidence chain wants a track record first.

  • DeepSeek V4 DeepSeek
    context
    per case
    infra only
    self-host
    yes
    conditional

    Open weights keep evidence entirely in-house; the trade is serious GPU capacity and self-managed reliability.

  • Llama 4 Maverick Meta
    context
    per case
    infra only
    self-host
    yes
    poor fit

    Sparse experts with 17B active weights: economical to serve, but summaries of dense evidence drift. Seat-specific — fine elsewhere.

  • Gemini 2.5 Flash-Lite Google
    context
    per case
    $0.001
    self-host
    no
    poor fit

    Priced for volume, but a summariser that can invent a detail is a liability at any price. A fabricated fact costs more than the tokens saved.

Who we are

We build detection, not surveillance.

Lyphere is a detection-engineering company. We come from low-level work — the layers where hardware and software can be made to lie — and from anti-cheat, the most adversarial school detection has. What it taught us: a detection system you cannot explain is a liability wearing a dashboard.

evidence over scores
A number convinces nobody. A record of what fired, and why, survives the dispute.
humans decide
Automation surfaces and correlates. Anything terminal is confirmed by a person.
built per field
No two deployments share thresholds. The field defines the signals, not the other way round.

Research

Talk to the person who built it.

Server operators, studios and security teams. No sales team and no discovery call — you reach the engineer.

hello@lyphere.com