FIVEM FORENSIC SCANNER · V1

Find the traces.
See the evidence.

Scan-Ware turns hidden FiveM system activity into clear forensic evidence for moderation teams.

FiveM forensic scanner Fast evidence review Windows artifact analysis

Scan Results

7KM2F91AReview required

GAME

FiveM

DURATION

1m 02s

RISK

67%

Detections

4

Warnings

9

Integrity

5

Suspicious

3

PC: Windows 11 Pro·Boot 4h ago·VPN No·FiveM Running

Scan-Ware V1 · FiveM first

FiveMSupported
RedMComing soon
RAGE MPComing soon
alt:VComing soon
GTA OnlineComing soon
FortniteComing soon
ValorantComing soon
RustComing soon

Workflow

One scan.
The full picture.

From PIN creation to readable evidence in about a minute. No client installation drama, no guesswork.

01

Create Scan

Moderator creates a new scan from the dashboard.

02

Share PIN

A temporary scan PIN is generated.

03

Run Scan-Ware

The player launches Scan-Ware and enters the PIN.

04

Analyze

Scan-Ware inspects relevant FiveM and Windows forensic artifacts.

05

Review

Results appear inside the moderator dashboard.

Temporary scan PIN

7KM2F91A

expires in 59:12 · single use · bound to player

Forensic depth

Eleven sources. One coherent story.

Scan-Ware correlates execution history, file artifacts and process activity instead of showing you isolated hits.

Prefetch

Execution history

1,284 traces

Amcache

Inventory + first execution

3,912 traces

ShimCache

Image load records

1,024 traces

ActivitiesCache

User activity timeline

486 traces

Registry

Persistence + config

212 traces

Filesystem

Create / modify / delete

8,431 traces

Processes

Live process tree

96 traces

Loaded Modules

DLLs per process

1,540 traces

PE Metadata

Sections, imports, entropy

322 traces

Authenticode

Signature validation

322 traces

SHA-256

File reputation

322 traces

+ Correlator

Chains traces into timelines

6 events linked

Capabilities

Built for the details.

Everything a moderation team needs to go from suspicion to decision — without drowning in raw logs.

Forensic Depth

Connect execution history, file artifacts and process activity into a single narrative.

Custom Detection Rules

Define organization-specific signatures and suspicious patterns with a visual builder.

Fast Scan Review

Put findings, timestamps and sources in one report. Triage in minutes, not hours.

FiveM Analysis

Analyze relevant game processes, modules and artifacts — purpose-built for FiveM.

Integrity Checks

Surface deleted and modified execution traces that cheats try to clean up.

File Reputation

Correlate SHA-256 and executable information against community hash intelligence.

Discord Integration

Bring scan results into moderation workflows with rich result embeds.

API Access

Connect Scan-Ware to external community tools with a clean REST API.

Severity model

Five severities. Zero ambiguity.

Every finding lands in exactly one category, so reviewers know what kind of decision each row needs.

DETECTION

Direct evidence matching a configured detection.

WARNING

Something requiring moderator attention.

SUSPICIOUS

Unusual executable characteristics.

INTEGRITY

Execution / deletion / modification correlation.

UNTRUSTED

Unknown or reputation-related files.

Interactive demo

Click a finding. Read the evidence.

This is a live slice of the real report UI — select any row to inspect what a moderator sees.

F-1042

Possible loaded module

detection
Process
FiveM_GTAProcess.exe · PID 14284
Module
unknown.dll
Path
C:\Users\Player\AppData\Local\Temp\unknown.dll
Signature
Unsigned
SHA256
9cf21a4e7b8d3c2a1f...

Evidence sources

Module analysisPE metadataHash database
Moderator note: Needs review — matches temp-loader staging pattern.
View Timeline View File Mark Reviewed

Timeline

Follow the evidence.

Scan-Ware connects individual traces into a readable sequence of events — download, execution, injection, cleanup.

Correlation6 events · 1 chain · 5m 27s window
20:31:24
DOWNLOADActivitiesCache

loader.exe

ZoneId 3 · from browser

20:32:10
EXECUTIONPrefetch

loader.exe

20:33:02
FILE CREATEDFilesystem

unknown.dll

20:33:08
MODULE LOADEDModule analysis

FiveM_GTAProcess.exe → unknown.dll

20:36:51
FILE DELETEDFilesystem

loader.exe

Deleted 4m after execution

20:37:12
SCAN COMPLETEDScan-Ware

PIN 7KM2F91A

Integrations

Your tools. Connected.

Results flow into Discord, your API consumers and webhook pipelines the moment a scan completes.

SW

SCAN-WARE BOT

Today at 20:37

Scan Complete — PlayerOne

PIN

7KM2F91A

GAME

FiveM

RISK

67%

DETECTIONS

3

WARNINGS

7

Open Report
Scan-Ware Rich embeds post to your moderation channel automatically.

Pricing

Protection that scales with you.

Start free. Upgrade when your moderation queue does.

STARTER

Starter

For Growing FiveM Communities

$8/ month

  • 5,000+ Detection Signatures
  • Advanced Client Detection System
  • 25 Scan PINs / Day
  • Custom String & Symbol Builder
  • Community Discord 24/7 Support
Select Starter
MOST POPULAR

PROFESSIONAL

Professional

For Established RP Communities

$12/ month

  • Everything in Starter
  • Unlimited Scan PINs / Day
  • Custom Detection Scripts & Rules
  • REST API Access & Webhook Keys
  • Priority Staff Support Queue
Select Professional

ENTERPRISE

Enterprise

For Multi-Server Networks & Esports

$6/ seat / month

5
$6 / seat / month
Monthly Total $305 seats × $6 — $30/month

Minimum 5 seats

  • Everything in Professional
  • Team Multi-User Management
  • Automated API Scan PIN Generation
  • Shared Threat Intelligence Database
  • Dedicated Enterprise Account Rep
  • Enterprise Branding
  • Advanced Roles & Permissions
  • Audit Logs
Select Enterprise

DOCS

Scanner operator guide

PIN lifecycle, player instructions, triage playbook.

Open →

API

REST reference

Scans, findings, players and webhook events.

Open →

STATUS

99.99% · 42ms median

Scanner service, API and Discord delivery health.

Open →

Your community.
Worth protecting.

Turn scattered traces into evidence your moderation team can review.

Free tier · No credit card · FiveM ready