# 09 — Recon findings: ARES PC client (Phiên 1 — 2026-09-15)

> Kết quả thực tế Phase 1. Mọi offset ghi trong `configs/offsets.json` phải đối chiếu file này.

## 1. Thông tin client (đã xác nhận)

| Mục | Giá trị |
|-----|---------|
| Process | `Ares.exe` — **64-bit** (PID 20048 lúc recon) |
| Đường dẫn | `C:\Program Files\Hive\THEIRONVANGUARD\Ares\Ares.exe` |
| Engine | **Unity, IL2CPP**, metadata version **31** (Unity 2022.3/2023+) |
| Module chính | `Ares.exe` (~10.5 MB image), `GameAssembly.dll` (**126.8 MB** trong RAM / 36.4 MB file), `UnityPlayer.dll` (31.8 MB) |
| Memory footprint | ~4.65 GB committed (3.76 GB private) |
| **Anti-cheat** | **nProtect GameGuard** (`GameGuard/`, `GameGuard.des`, `NPGameDLL64.dll`) |
| Networking | protobuf (`MapField.Codec`, `RepeatedField` trong dump) |
| Bảo vệ dữ liệu | **`SecTypeBase<T>`** — HP/giá trị nhạy cảm bọc trong `SecInt/SecFloat/SecULong/SecEnum` (mã hóa runtime, có virtual encrypt/decrypt) |
| Obfuscation | Tên field/method phần lớn bị obfuscate (identifier 10 ký tự in hoa, vd `KGIBCNKPCFM`); **tên class và nhiều field gameplay vẫn giữ nguyên nghĩa** |

## 2. Hệ quả thiết kế quan trọng

1. **IL2CPP = lối tắt recon.** Có `global-metadata.dat` (30.3 MB, nằm trong thư mục cài) ⇒ dump được toàn bộ class/field/RVA bằng Il2CppDumper — không cần scan mù.
2. **SecType ⇒ value-scan kiểu Cheat Engine có thể thất bại** với HP/tiền (giá trị trong RAM không phải plaintext). Đường đi đúng: tìm **object pointer** của controller class rồi đọc theo offset field, thay vì scan giá trị.
3. **GameGuard ⇒ mọi thao tác runtime phải chạy elevated** (UAC). `OpenProcess` từ tool thường → `ERROR_ACCESS_DENIED`. Recon đọc bộ nhớ bằng `ares_recon` (đã verify) hoạt động tốt với quyền Admin — GameGuard không chặn ReadProcessMemory ở mức kiểm tra hiện tại.
4. **Chính sách chỉ-đọc là bắt buộc** — GameGuard có thể phát hiện ghi bộ nhớ.

## 3. Offsets đã xác nhận (từ dump IL2CPP, chưa verify runtime)

### ObjectStateInfoViewer (state sync server→client — chính là "telegraph cue" cần cho dodge)
| Field | Offset | Kiểu |
|-------|--------|------|
| `serverPos` | **0x20** | Vector3 |
| `clientPos` | **0x2C** | Vector3 |
| `serverRotY` | **0x38** | float |
| `clientRotY` | **0x3C** | float |
| `serverAIState` | **0x40** | KGIBCNKPCFM (enum) |
| `clientAIState` | **0x44** | KGIBCNKPCFM (enum) |
| `serverSkillIndex` | **0x48** | int |
| `clientSkillIndex` | **0x4C** | int |
| `serverTarget` | **0x50** | Transform |
| `clientTarget` | **0x58** | Transform |
| `serverHitStateCase` | **0x60** | AresCharacterController.HitStateCase |
| `clientState` | **0x64** | AresCharacterController.eCharState |
| mob controller ref | **0x68** | AresMobController |

### AresCharacterController (base cho cả player lẫn mob)
| Field | Offset | Kiểu |
|-------|--------|------|
| `_rootBone` | **0x28** | Transform |
| `__charState` | **0x30** | eCharState (enum) |
| `_currPhaseIndex` | **0x110** | int (phase của boss!) |
| `_skillSeqer` | **0x138** | OICBDCGGNAG (skill sequence controller) |
| `AbnormalController` | **0x148** | AbnormalController (debuff/CC state) |

`AresMobController : AresCharacterController` — boss/mob dùng cùng layout phía trên.

### Class đáng chú ý cho giai đoạn sau
- `CharacterAIManager` (singleton) — truy cập AI của mọi character
- `AresStatOrbController`, `AresUILifeGauge`, `AresHUDMonsterLifeInfo`, `AresLifeGaugeInfo` — HUD HP (đường dự phòng đọc từ UI layer)
- `AresCharStateTransition` — state machine của character
- `AresIntroManager.TutorialContext` — có `evadeStepTriggerSkillIndices` (cơ chế evade của tutorial!)

## 4. Tooling đã xây (nội bộ)

- `tools/ares_recon.exe` (C++23, trong repo): `info / modules / regions / read / valuescan / valuefilter / watch / aob`.
- **Cách dùng với GameGuard:** phải chạy elevated. Pattern đã verify:
  ```powershell
  Start-Process cmd -ArgumentList '/c cd /d C:\Projects\ARES &&
    build\msvc-debug\tools\Debug\ares_recon.exe info > build\out.txt 2>&1' -Verb RunAs -Wait
  ```
- **Il2CppDumper v6.7.46** (net6) dump thành công metadata v31 — **phải chạy với cwd = thư mục cài game** (PE loader cần resolve dependency DLL của GameAssembly). Output: `dump.cs` (58.5 MB), `il2cpp.h`, `script.json`, `DummyDll/` — lưu tại `recon/` (không commit — xem .gitignore).

## 5. Bước tiếp theo (Phiên 2)

1. **Verify runtime:** từ `il2cpp.h` + `script.json`, dựng pointer chain: `GameAssembly` il2cpp domain → find instance `AresCharacterController` → đọc `__charState` @0x30, đối chiếu với trạng thái trên màn hình (dùng `ares_recon watch`).
2. **Tìm nguồn HP:** ưu tiên hướng `AresUILifeGauge`/`AresStatOrbController` (HUD bind trực tiếp giá trị) hoặc decrypt `SecTypeBase<T>` qua hàm `CKGIEGJBIJF()` (RVA có sẵn trong dump).
3. **IL2CPP runtime helper:** cân nhắc dùng il2cpp export APIs của GameAssembly (`il2cpp_domain_get`, `il2cpp_thread_attach`...) — export table của GameAssembly.dll có sẵn các hàm này, an toàn hơn tự walk metadata.
4. **Boss state_id:** dump enum `KGIBCNKPCFM` (AIState) + `eCharState` đầy đủ để xây `encounter_db/` (docs/05).
