Overview Ocean Anticheat Solutions is a post-mortem detection framework that identifies and analyzes cheating activity across FiveM, Minecraft and other supported platforms.
This guide condenses the official documentation for developers, partners and server administrators: detection categories, integrity systems, and the Ocean Dashboard and Ocean+ APIs.
Getting started Use the sidebar to explore the Detections and API sections. Learn how Ocean classifies detections and communicates results through the dashboard. Follow the full-reference links for complete schemas and examples. Official documentation Detections Collection → enrichment → analysis → verdict.
Detects logs Generic and specific detections, step by step. Direct detections are too numerous to describe individually.
Direct Direct cheat detections using residues or other methods.
Generic Highly suspicious executables; a strong likelihood of cheating, not 100% certain unless stated.
Specific Tampering or modification methods used for illegal advantages, cheat dependencies and similar. Full reference Warning logs Detections that do not necessarily mean cheating, but flag modifications that can evade detection vectors.
Bypass method in Prefetch Two Prefetch (.PF) files with identical content, which is impossible.
Executed suspicious file A suspicious file that must be checked manually.
Modified extension A file whose content does not match its extension, e.g. an executable renamed to .txt.
Disabled ActivitiesCache The user disabled the ActivitiesCache function.
Suspicious DLL loaded A DLL external to the game was loaded. May false-positive with ReShade on FiveM. Full reference Suspicious logs Highly suspicious executable detections. Read the description, apply common sense, and always check manually.
VM / sandbox detection The executable checks for Qemu, VMWare, Sandboxie, Parallels, VirtualBox or Virtual PC — an anti-debug technique.
DotNet executable / DLL Files written in C#, the language the majority of bypasses are written in.
Packed file (UPX / VMProtect / Themida) An unsigned file protected by packer software commonly used to protect cheats. A clear indication, not proof.
Tampered file Files purposely modified to evade detection vectors.
Process hollowing (P1 / P2) Process hollowing or similar techniques to evade execution vectors.
AutoIT / AutoHotkey Files made with macro tools, widely used for macros and autoclickers.
Secure cheat detection (S1 / S2 / C3 / C4) Secure detection of cheats.
Suspicious .NET file A packed, protected file written in C#. Full reference Detection systems Integrity detections: things that alter the scan's integrity or reveal discrepancies.
Executed & modified A previously executed file was later modified — possible self-destruct.
Executed & deleted A previously executed file was later deleted — possible self-destruct.
Prefetch deleted A Prefetch file for an executed program was deleted — antiforensic behavior.
Suspicious DLL deleted A suspicious DLL was deleted — possible self-destruct.
Network file bypass A file on a network resource was modified, executed or deleted.
Suspicious file change Modification, deletion or execution of a highly suspicious file.
Impossible file change A file change that is practically impossible under normal conditions.
NVIDIA / PowerShell log bypass A change in a file that is practically impossible under normal conditions.
RAR execution Direct file execution from inside a RAR archive.
External device execution Execution from an external device, most often a phone — commonly used for bypass.
External device deletion File deletion from an external device. Full reference Integrity checks Ocean's most sophisticated cheat detection systems.
Recovery Detects files even after deletion, with download or VirusTotal review. NTFS and FAT32.
Antivirus Shows which file an antivirus flagged, what type of detection, and when.
Generic packed mods Detects mods with obfuscation or suspicious modules.
Engines Detectability range for new and unknown cheats. Requires a VirusTotal API key.
Interaction Direct client detections, now part of Detect logs.
Untrusted file Highly suspicious files with many VirusTotal flags, for manual review.
RAM instance Uses volatile RAM to check cheats at the instance level.
IA detection Learns from scan telemetry to detect cheats.
RUIN mode Detects the slightest game-instance modification. Minecraft Java and Ocean+ only; the game must close after the scan. Full reference Ocean API A RESTful API for scan data, user information, risk scores and detection systems. Authenticated calls are rate-limited to 1,000 requests per hour.
Requirements The API needs an active license or Enterprise membership. Free users cannot create API keys. The only exception is /v1/version, which is public.
Base URL https://api.anticheat.ac/v1
Authentication x-api-key header
Rate limit 1,000 requests/hour
Server label Optional x-server-name headerUsage logging Every authenticated call is recorded — key prefix, endpoint, IP and server name — and kept for 90 days to spot key sharing and abuse. Full keys are never stored.
Endpoints
Scanned users GET /v1/scanned-users/lookup/:discordIdComplete scan history, detections, ban/warn status and related accounts for a Discord user.
User risk score GET /v1/users/:discordId/risk-scoreAggregated risk score and level across all linked profiles.
Pin results GET /v1/pins/:pinCode/resultsFull scan results for pins owned by your account.
Pin status GET /v1/pins/:pinCode/statusReal-time scan progress, status percentage and result summary.
Create pins POST /v1/pins/createCreate scan pins programmatically. Enterprise owners only.
Cheater database GET /v1/db/query/:discordIdCommunity profile, network lookup and Ocean scan matches by Discord ID. Needs DB Access.
Version GET /v1/versionThe currently active Ocean client version. Public, no key needed.
MCP Server MCP https://api.anticheat.ac/mcpRemote MCP server exposing the same data as the REST API to AI agents over Streamable HTTP. OAuth 2.1 with PKCE — no API key.
Risk levels Level Score Meaning clean0 No detections or suspicious activity low1–25 Minor flags, likely false positives medium26–50 Some suspicious activity detected high51–75 Multiple detections, likely cheating critical76–100 Confirmed cheating with extensive history
Condensed reference This page summarizes the official documentation. Schemas, examples and new endpoints can change — the official reference below is always current.
anticheat.ac/docs