Skip to main content
Finds modules and byte patterns in the game process and defines struct layouts to read with. The reading itself is done through Pointer.
Game memory is read-only, there is no write API. No manifest permission is needed.

Overview

Modules

module.

Pattern scans

scan, scanAll, pattern syntax.

Structs

struct, union.

Modules

module


A loaded module by file name, case-insensitive, as { name, base, size }, or null. Only client.dll, engine2.dll, inputsystem.dll, matchmaking.dll and soundsystem.dll are available.
name is lower-case, base is a Pointer, size is the image size in bytes.

Pattern scans

Patterns are IDA-style: hex bytes separated by spaces, ? or ?? for any byte.
Scans are slow. Scan once at load, not every tick.

scan


The first match, or null when there’s none. Throws ENOENT when the module isn’t loaded.

scanAll


Every match in address order, [] when none.

Structs

struct


Defines a C layout to read with Pointer.read or Snapshot.as, laid out in field order with C alignment. Same as ffi.struct, without needing the ffi permission.
Field types are the scalar types, C names ("DWORD", "void*"), arrays ("float[16]", "Vec3[4]", "char[32]") or another struct. A named struct can be used by name in later definitions. In game memory ptr fields read as Pointer.
"string" and "char*" fields are pointers, not text. Follow them with view.name.read("string"). Inline text is "char[N]".

union


Same as struct, but every field starts at offset 0.

Example

Finds a global through a signature once, then reads it every tick.