Offensive security in online games, MMO, anti-cheat, in-game economy and IP protection.
Why now
Cheaters, bots and fraudsters destroy game economy and retention. Server code leaks expose vectors. Skin theft, leaderboard manipulation and secondary economy attacks are pure fraud.
Applicable regulation
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Anti-cheat robustness analysis, executable integrity.
Server-side validation, speed-hack prevention, dupes and exploits.
Item duplication, leaderboard manipulation, loot box fraud.
Player account, recovery, multi-factor authentication.
Receipt forgery, refund fraud, gift card abuse.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Experience in competitive online games.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Yes. We assess client/server architecture, kernel-level anti-cheat and bypass techniques used by cheaters.
Yes. IPA/APK analysis, anti-tampering, certificate pinning, in-app purchase fraud.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.