Overwatch 2's 47 MB .text section ships encrypted at entropy 8.000, decrypted lazily one page at a time by Blizzard's Eidolon protector. The pad that decrypts it is 16 KB of plaintext bytes sitting in Overwatch_loader.dll, in the same folder, read circularly across the whole section. 99.84% of the game's code recovered from two files on disk - no key, no memory dump, no running process. Plus the 22 functions Eidolon guts entirely, and an honest account of the four times I fooled myself on the way.
Part 3 of the Anti-Lag+ teardown. The hook lived in code - but the on/off switch was data. Reverse-engineering AMD's per-game application-profile database (atiapfxx.blb / the BWJE format) and the single byte that turned the feature off.
Part 2 of the Anti-Lag+ teardown. A deep dive into amdihk64 - a Microsoft Detours-based inline-hook engine that ships in the same driver package and also hooks raw input. It's a sibling to the Delag detour from Part 1; I couldn't prove it's on the Anti-Lag+ path itself, and I say so.
A symbol-level teardown of the Adrenalin 23.10.1 feature that got Counter-Strike 2 players VAC-banned - what it hooked, how it hooked it, and the single byte that turned it off.