v1.0 · Unity 6000.0+

Integrity Shield Pro

Client-side anti-cheat and tamper protection for Unity — protected values, encrypted storage, a catalog of runtime detectors, and HMAC-signed evidence for your server. Drop in one component and press Play; no scripting required to get started.

Unity 6000.0+ No-Code Ready Mono & IL2CPP All Platforms No auto-ban by default
ⓘ
What it is. A layered, client-side integrity toolkit: it raises the cost of tampering and gives your backend signed evidence to act on. It is defense-in-depth, not a silver bullet — pair it with server authority for anything that affects fairness or economy. See FAQ and the bundled SecurityLimitations.md.
✅
Safe by default. Detection is silent out of the box — the asset never auto-bans, punishes, or collects personal data by default. You decide the response policy. All limitations are documented honestly.

⤓ Installation

Import the package and you're ready — the core needs no extra packages.

Import the package. A one-time Welcome window opens with quick actions. You can reopen it anytime from Tools ▸ Integrity Shield ▸ Welcome & Help.
Take the interactive tour. From the Welcome window click Open the Welcome Scene (or open Assets/IntegrityShield/Demo/Scenes/IntegrityShield_Welcome.unity) and press Play for an on-screen “Start Here” guide: the 3-step quick start, a live built-in-profile browser, and one-click links to the docs and demo.
(Optional) Run the Setup Wizard. Tools ▸ Integrity Shield ▸ Setup Wizard creates default Profile / Policy / Signature assets and picks a game profile.
Add protection. Continue to the No-Code Quick Start.

Requirements

ComponentNeedsNotes
Core runtime + editor toolsNo extra packagesCompiles in an empty project against default Unity modules. Verified by clean-room import.
Demo scenescom.unity.uguiuGUI ships in every standard template (3D, 2D, URP, HDRP).
Tests (developer only)com.unity.test-frameworkNot required at runtime.
Mobile native detectionBundledAndroid .so (arm64-v8a, armeabi-v7a, x86_64) + iOS native source included.
✅
Unity 6000.0 (Unity 6) or newer. The full runtime is verified end-to-end on both Mono and IL2CPP players.

⚡ Quick Start — No Code

A non-coder can get working protection by clicking, not scripting.

Add the component. In the menu bar choose GameObject ▸ Integrity Shield ▸ Add Protection (Bootstrap). This drops an Integrity Shield object into your scene.
Choose your protection. In the Inspector, either assign a Profile Asset or pick a Built-In Profile from the dropdown that matches your game (the inspector shows a one-line description of each).
Press Play. Protection starts automatically. The Inspector shows a live Runtime Status panel; open Tools ▸ Integrity Shield ▸ Event Viewer to watch detections.
ⓘ
No profile asset assigned? That's fine — the selected Built-In Profile preset is used at runtime. Click Create Profile Asset in the Inspector when you want to customize detectors, policy and reporting.

Built-in profiles

ProfileFor
Single Player BasicOffline games — protected values, encrypted storage, time checks.
Single Player EconomyOffline with currency/economy — adds time-manipulation + file-integrity.
Casual MultiplayerCasual online — enables signed evidence reporting.
Competitive MultiplayerCompetitive online — debugger, injection, known-tool detection + evidence.
Mobile Live ServiceMobile — Android/iOS native root, jailbreak, emulator detection.
PC CompetitivePC — debugger, injection, known-tool, file-integrity detection.
QA Stress TestEnables every detector with a relaxed frame budget.
WebGL LimitedDisables detectors not meaningful in the browser sandbox.

💻 Quick Start — Scripting

Prefer code? Initialize the manager directly. (A code-first Initialize always takes precedence over the no-code Bootstrap.)

C#using IntegrityShield;

public class GameBoot : MonoBehaviour {
    void Awake() {
        // Pass a profile asset, or null for sensible defaults.
        IntegrityShieldManager.Initialize(myProfile);
    }
}

Protect a value and react to threats:

C#// Obfuscated, tamper-evident value.
var coins = new ProtectedInt(100);
coins.Value += 50;

// Subscribe to integrity responses.
IntegrityShieldManager.Instance.ResponseIssued += decision => {
    Debug.Log($"Response: {decision.action}");
};

⚙ How It Works

Detectors observe the runtime, raise threat events, the policy engine decides a response, and evidence is optionally exported.

Detectors
→
Threat Event Bus
→
Policy Engine
→
Response
→
Exporters / Server Evidence

🎮 Profiles & Policy

A Profile bundles which features and detectors are on; a Policy defines the rules and responses.

Profile

Create via Assets ▸ Create ▸ Integrity Shield ▸ Profile. The custom inspector shows a plain-language description of the chosen game type and an Apply Preset Defaults button that configures detectors, frame budget and reporting for that scenario. Fields are grouped and tooltipped.

Policy rules

A rule matches by detector, signal, platform, scripting backend, dev/release build, minimum severity, minimum confidence, required event count and time window, then issues a response and a risk-score delta. Tune rules visually in Tools ▸ Integrity Shield ▸ Policy Editor and dry-run them in the Policy Simulator.

🔒
A local kill switch (PlayerPrefs flag) lets you disable all detectors during local development without code changes.

🛡 Responses

What happens when a rule matches. You control this entirely; nothing punishes players by default.

ResponseEffect
LogRecord the event silently (default-friendly).
ExportRoute the event to your exporters (local JSON Lines and/or HTTP).
Require Server ValidationFlag the session for server-authoritative re-checks; sends signed evidence.
Block Online SessionMark the session as not eligible for online play.
Disable Leaderboard / Ranked QueueSoft responses your game code can read and honor.
Quit ApplicationOnly when explicitly allowed in the policy (off by default).
⚠
Client-side responses are deterrents. For anything that affects fairness or economy, treat the client as untrusted and enforce on your server — the signed evidence path exists for exactly this.

🔎 Detectors

Thirteen built-in detectors run on a frame-budgeted scheduler. Enable per profile.

Speedhack / Time Manipulation

Detects fake clock drift between trusted and local time.

Debugger

Flags an attached debugger on supported platforms.

Known Tool

Word-boundary matching of cheat-tool process/module names (Cheat Engine, Frida, Xposed, …).

Native Module Injection

Flags suspicious loaded native modules.

Assembly Injection

Reports unexpected managed assemblies (framework-aware allowlist; reports once).

File Integrity

Hashes manifest files and flags mismatch / missing.

Wallhack / Visibility Sentinel

Detects hidden-object visibility and occlusion mismatches.

Memory Tamper Canary

Decoy values that reveal memory editing.

Root / Jailbreak / Emulator

Android & iOS native signals (root, Magisk, jailbreak, emulator/VM).

App / Certificate Integrity

Package name, signing certificate and app-hash mismatch checks.

ⓘ
Each detector reports a confidence (0–100) and severity; the policy decides what (if anything) to do. Detectors are tuned to avoid false positives (for example short tool tokens match only on whole words).

🔒 Protected Values

Drop-in replacements for primitive fields that resist memory editing and reveal tampering.

Values are XOR-obfuscated in memory with a decoy mismatch check — a memory editor that changes the stored value triggers a tamper event. Supported types include ProtectedInt, ProtectedFloat, ProtectedBool, ProtectedString, ProtectedVector2/3/4, ProtectedQuaternion, ProtectedColor and many more, plus protected collections: ProtectedList, ProtectedDictionary, ProtectedQueue, ProtectedStack and ProtectedHashSet.

C#var health = new ProtectedFloat(100f);
health.Value -= 25f;          // use it like a normal float
var inventory = new ProtectedList<int>();
inventory.Add(7);
✅
In the Inspector, protected fields render as read-only (protected) labels so their decoy contents aren't mistaken for the real value.

💾 Protected Storage

Encrypted, authenticated local storage that fails closed when tampered.

Records are encrypted with AES-CBC and authenticated with HMAC-SHA256 (encrypt-then-MAC), with separately derived encryption and authentication keys. Use ProtectedPrefs in place of PlayerPrefs, and ProtectedFileStore for larger JSON/text payloads.

C#ProtectedPrefs.SetInt("coins", 500);
int coins = ProtectedPrefs.GetInt("coins", 0);  // returns default if tampered
⚠
The default key provider stores a per-install key in PlayerPrefs for zero-config and cloud-save compatibility. On platforms where PlayerPrefs is readable, this is deterrence, not a cryptographic guarantee — keep server authority for fairness-critical values. See ProtectedStorage.md.

🌐 Multiplayer Evidence

Give your server tamper-evident, replay-resistant evidence to act on.

Threat events are wrapped in an EvidenceEnvelope and signed with HMAC-SHA256 (with a per-session nonce for replay protection). Your server verifies with the shared key before trusting the report.

Client signs envelope
→
Transport
→
Server verifies (HMAC + nonce)
→
Accept / Reject

Bundled transports: Mirror, Netcode for GameObjects, FishNet, generic HTTP and WebSocket. Server-side rule validators are included for movement speed, economy delta, cooldown, inventory, match result and session risk.

ⓘ
The full client→socket→server-verify round-trip (accept, replay-reject, tamper-reject) is covered by automated tests, including inside a built player.

📡 Remote Policy

Tune detection live without shipping an app update.

Fetch a signed policy from your endpoint; it is verified with HMAC-SHA256 and an expiry timestamp before being applied, and every apply/reject is recorded to an audit log. Tampered or expired policies are rejected.

C#var ok = RemotePolicyService.TryVerifyAndApply(envelope, key, policy, audit, out var error);

📊 Analytics & Reporting

Privacy-aware local and remote reporting.

Route threat events to local JSON Lines files and/or an HTTP endpoint. Exporters enforce a bounded queue and apply privacy redaction (e.g. emails and raw player ids are stripped at the Standard/Minimal privacy levels). Configure via Assets ▸ Create ▸ Integrity Shield ▸ Event Routing Config or the Event Routing window.

🔒
No personal data is collected by default. You opt in to analytics and choose the privacy level.

🔧 Editor Tools & No-Code Workflow

Everything important is reachable by clicking. This is a headline capability — you can ship protection without writing a line.

Drop-in & scaffolding

Authoring assets (no code)

Create from Assets ▸ Create ▸ Integrity Shield ▸ …: Profile, Policy, Known Tool Signature Database, File Integrity Manifest, Event Routing Config. The Signature Database inspector supports CSV import (file picker or drag-and-drop, with automatic delimiter detection — comma, semicolon, tab or pipe), copy-as-CSV, clipboard merge, and reset-to-defaults.

Windows (Tools ▸ Integrity Shield)

Setup Wizard

Create default assets & pick a game profile.

Dashboard

Hub for every Integrity Shield tool.

Policy Editor / Simulator

Author rules and dry-run events against them.

Event & Evidence Viewers

Inspect recent threat events and signed envelopes.

Signature Database

Edit and import known-tool signatures.

Risk Scanner

Scan your project for risky patterns (e.g. raw PlayerPrefs).

Protected Storage Browser

Inspect protected records.

Analytics Dashboard

Summarize routed events.

Build Validator / Benchmarks

Pre-ship checks and micro-benchmarks.

📱 Platforms

Builds verified across all desktop and mobile targets, on Mono and IL2CPP.

PlatformStatusNotes
Windows (x64)VerifiedMono & IL2CPP players verified end-to-end.
macOSVerifiedStandalone build verified.
Linux (x64)VerifiedStandalone build verified.
AndroidVerifiedBundled native library; root/emulator/injection signals.
iOSVerifiedBundled native source; jailbreak/injection signals.
WebGLLimitedBrowser sandbox limits some detectors (use the WebGL profile).

📙 Scripting API

The most common entry points. The no-code Bootstrap calls these for you.

MemberPurpose
IntegrityShieldManager.Initialize(profile)Start protection with a profile (or null for defaults).
IntegrityShieldManager.IsInitializedWhether protection is running.
IntegrityShieldManager.EmitThreat(…)Raise a custom threat event (thread-safe).
Instance.RunManualCheck(id)Run a single detector on demand.
Instance.Events.RecentEventsRecent threat events.
Instance.ResponseIssuedEvent fired when a response decision is made.
Instance.StatusLive status (initialized, detector count, kill switch…).
IntegrityShieldBootstrap.StartProtection()Start from a UI button / your code.
IntegrityShieldManager.Shutdown()Stop protection and release runtime state.

See APIReference.md in the Documentation folder for the full surface.

💡 Troubleshooting

The issues that come up most, and how to resolve them.

Nothing happens when I press Play

Protection only starts if it is initialized. Add the Integrity Shield Bootstrap component (or use GameObject ▸ Integrity Shield ▸ Add Protection) with Initialize On Awake enabled, or call IntegrityShieldManager.Initialize(profile) from your code. The Bootstrap's Inspector shows a live Runtime Status panel in Play mode.

I see "[IntegrityShield] …" warnings in the Console

Those are intended threat-event logs (the system reporting a detection), not errors. Tune what gets logged via the Policy, or raise the routing minimum severity in the Event Routing Config.

A legitimate tool is being flagged

Edit the Known Tool Signature Database (remove or adjust a token), or disable the Known Tool detector in your Policy. Tokens match on whole words to reduce false positives.

The Demo scripts won't compile in a bare project

The Demo uses uGUI. Add com.unity.ugui via the Package Manager (it's included in all standard templates), or delete the Assets/IntegrityShield/Demo folder — the core runtime has no extra dependencies.

macOS build won't open ("damaged")

Unsigned development builds are quarantined by Gatekeeper. Clear it with xattr -dr com.apple.quarantine YourApp.app, or sign the build.

❓ FAQ

Quick answers to the questions that come up most.

Does this make my game uncheatable?

No — and no client-side tool can make that claim honestly. Integrity Shield raises the cost and effort of tampering and gives your server signed evidence to act on. For anything affecting fairness or economy, keep server-side authority. Limitations are documented in SecurityLimitations.md.

Do I have to write code?

No. Add the Bootstrap component (or use the GameObject menu), pick a profile, press Play. A full code API is available for advanced use and always takes precedence over the no-code path.

Will it auto-ban my players?

No. Detection is silent by default; the asset never bans or punishes on its own. You define the response policy.

Does it work with IL2CPP?

Yes. The full pipeline (crypto, storage, evidence, detectors) is verified end-to-end in a built IL2CPP player as well as Mono.

Does it need native plugins or an internet connection?

Desktop protection is pure C#. Mobile native detection uses a bundled Android library and iOS source (optional). No internet connection is required; remote policy and server evidence are opt-in features that use your endpoints.

Is multiplayer required?

No. Single-player profiles use protected values, encrypted storage and local detectors. The signed-evidence features are there when you need a server.

📬 Support

Need help? We're here for you.

📧

Get in Touch

Bug reports, feature requests, integration questions — reach out and we'll get back to you.

✉ szekipapa77@gmail.com

We typically respond within 24–48 hours.

💬 Before contacting
  • Check the Troubleshooting section
  • Run Tools ▸ Integrity Shield ▸ Build Validator
  • Confirm the Integrity Shield Bootstrap is in your scene (or you call Initialize)
  • Check the Console for threat-event messages
📋 Helpful info to include
  • Unity version (e.g. 6000.0.62f1)
  • Integrity Shield Pro version (v1.0)
  • Platform & scripting backend (Mono / IL2CPP)
  • The profile you're using + what you expected
⭐
Enjoying Integrity Shield Pro? A review on the Unity Asset Store helps other developers discover the asset and helps us keep improving it. Thank you!

Integrity Shield Pro v1.0 · Built for Unity 6000.0+ · Verified on Mono & IL2CPP

Support: szekipapa77@gmail.com