Every finding in an Ocean report belongs to one of five categories. Detects are proof, warnings and suspicious logs need a reviewer's judgement, detection systems expose attempts to hide evidence, and integrity checks go beyond what is running right now. The pipeline is always the same: collection, enrichment, analysis, verdict.
Confirmed detections. Direct detections come from residues of a known cheat, generic detections flag highly suspicious executables, and specific detections cover tampering methods and cheat dependencies. Per-game semantics are documented for Global, Minecraft and FiveM.
Modifications that can be used to evade detection vectors but are not proof of cheating on their own: duplicate Prefetch content, an executed file whose extension does not match its content, a disabled ActivitiesCache, or a DLL loaded into the game from outside. The penalty depends on the server and the warning.
Executables flagged with a reason: virtual-machine checks, .NET tooling, packers and protectors such as UPX, VMProtect or Themida, tampered files, process hollowing, and AutoIT or AutoHotkey macros. Read the reason, then check the file manually before acting.
Anti-forensic behaviour around the scan itself: files executed and then modified or deleted, Prefetch entries removed, execution from a network share, an external device or straight out of a RAR archive, and modifications that are practically impossible under normal use.
The deeper systems: Recovery brings back deleted files from NTFS and FAT32 drives, antivirus correlation shows what the antivirus flagged and when, Engines rank unknown executables through VirusTotal, memory is checked at runtime, untrusted files are listed for manual review, and RUIN mode catches the slightest change to a Minecraft Java instance.