Kubian  ·  Proven in production

Battle tested, not lab tested.

Kubian doesn't sit in a demo. It runs inside large, live game environments with real players and real cheaters — where every release is probed for weaknesses from day one, patched continuously, and every lesson is shared across the whole network.

<1ms
Verify time
2s
Threat sweep
10s
Ban re-poll
60s
Tier recheck
~30s
Policy push
400ms
Self-pager

Running where failure isn't an option

Production titles with real populations, real sessions, and real revenue on the line. Not sandboxes, not demos, not load-test rigs.

Production is the only test that counts

A system that only works in a lab fails the moment it meets real traffic: clock skew, flaky networks, exotic devices, OS versions years out of date, and players on the other side of the planet.

Kubian operates around the clock under exactly those conditions. Challenge issuance, attestation verification, realtime alerts, ban enforcement, and the developer dashboard all run continuously against live player populations — exercised hardest precisely when it matters most. Verification completes in under a millisecond of backend processing time, telemetry is fire-and-forget so gameplay never waits on security, and attestation parsing is cached per certificate so repeated sessions cost almost nothing.

The result: protection your players never feel and your cheaters never beat — at production scale, every hour of every day.

Production traffic, 24/7

Challenges, verifications, alerts, reviews, and bans flow continuously. There is no quiet period where Kubian rests — and none where attackers do either.

Zero gameplay cost

Sub-millisecond verification, cached parsing, and asynchronous reporting mean protection never costs frames, never blocks sessions, and never shows up in the player experience.

Real device diversity

Flagship phones, budget devices, tablets, and VR headsets across every OS generation — Google-issued and Meta-issued hardware attestation alike, each verified against its own trust root.

Under constant attack — and holding

Bypasses, spoofs, hooks, and replays aren't a theoretical threat model. They're the daily weather. Each maps to a real, named detection inside libKubianIntegrityCore.so.

AttackWhat the attacker triesWhat Kubian does
Token replayCapturing a valid integrity response and reusing it across sessions or devices.Single-use, nonce-bound challenges — a captured response is dead on arrival and the replay itself is logged.
Attestation spoofingFaking the KeyMint certificate chain or app identity to impersonate a trusted device.Hardware-rooted chain verification against Google and Meta trust roots, with package name and certificate digest binding.
Frida & dynamic hooksAttaching Frida gadgets, intercepting functions, and rewriting behavior at runtime.Memory-map scans, known Frida ports, anon-exec page detection, and Frida connection blocking.
Renamed Frida buildsPatching or renaming Frida binaries to dodge signature scans.Patched-module detection that recognizes repackaged Frida by behavior and structure, not by filename.
Fileless Frida injectionInjecting Frida entirely in memory via memfd so nothing touches disk.File-descriptor leak analysis that catches memory-only injection other scanners miss.
Debugger evasionAnti-debug bypasses, ptrace tricks, and JDWP/LLDB concealment.Layered anti-debug traps plus TracerPid and timing checks that treat evasion itself as a detection.
Root hidingMagisk and KernelSU concealment to look unrooted while keeping privileges.Mount-table inspection, su-path sweeps, system-property checks, and hidden-root heuristics.
Injection frameworksZygisk, Riru, LSPosed, and Substrate modules injected into the process.Module scans against known framework signatures, with per-check Alert, Kick, or Ban policy.
DebuggingAttaching a debugger to step through or dump the running app.TracerPid inspection, timing checks, and app-debugging prevention.
Weak buildsRunning test-keys, userdebug, or SELinux-permissive builds to weaken the platform.Build-tag, debuggable-flag, and SELinux-enforcement gates with studio-controlled enforcement.
Binary tamperingRepackaging the APK or patching the native library itself.SHA-256 application-digest binding plus the core library's own .text integrity hash.

Selected public capabilities. Additional safeguards remain intentionally undisclosed to keep the suite effective.

Anatomy of a blocked attack

What happens when a cheater runs Frida against a protected game — told in seconds, not paragraphs.

  1. T+0s — The attach. The attacker injects a Frida gadget into the running game, expecting to hook functions and rewrite behavior invisibly. The protection loop is already sweeping.
  2. T+2s — The spot. The next 2-second sweep flags the gadget's memory maps and ports. A realtime alert leaves the device carrying the full context: app, device identity, device certificate, check, and detail.
  3. Instant — The directive. The backend matches the studio's policy for Frida and answers: note, kick, or ban. In enforce mode the process is terminated on the spot — the session ends within seconds of the attach.
  4. T+minutes — The record. The offender audit keeps the full signal trail. If the verdict is a ban, it binds to hardware-backed identity — surviving reinstalls and account switches — and is enforced network-wide. A mid-session ban is logged as a banned-while-playing event.
  5. Forever — The immunization. The technique is fingerprinted into the detection set and shared across every protected app. The next attacker running the same gadget meets the defense on arrival.

Timings above follow the production configuration: 2-second sweeps, 10-second ban re-polls, realtime alerting. Studios tune actions per check; the loop itself never sleeps.

The loop, precisely

RTEP starts with a single native call that spawns the monitor on its own thread, off the game thread. Intervals below half a second are clamped; production runs a 2-second sweep with enforcement on.

Each cycle runs the hard and soft scan sets. On any change versus the previous scan, the monitor fires its callback and reports to the verification backend carrying app, device identity, device certificate, check, and detail. The server answers with a directive — log only, kick, or ban — and with enforcement on, a kick or ban verdict terminates the process on the spot. Between sweeps the loop re-polls ban state, checks shared ban records, and re-verifies the RSA-signed protection tier every 60 seconds, failing closed into full Max-tier protection if anything looks tampered. Need a verdict without the loop? The same scan set can run exactly once — the one-shot check studios use right before a ranked match starts.

Patched as fast as it's poked

Every attempt teaches the system something. Kubian is actively patched, released, and improved on a continuous cycle — not on quarterly schedules.

  1. Attempt. An attacker tries something new against a live protected game — a novel bypass, a modified tool, a fresh hiding technique.
  2. Signal. Telemetry captures it with full context: device identity, signals, and the exact check that fired, straight into the offender audit.
  3. Harden. The attempt is studied and hardened into a detection or a tightened check — a permanent addition, not a temporary block.
  4. Ship. Signed policy updates propagate within 30 seconds, revocation entries land immediately, and version gates close the door — all server-side, with no client update required.
  5. Verify. The same live environments that exposed the gap confirm it closed. Attackers get one shot at a gap before it shuts — permanently.

One network. Shared immunity.

A defeated bypass doesn't just protect the game that was attacked. It protects every game on the network.

An attack on one studio hardens every studio

Kubian operates as one connected system: offender signals, revoked device credentials, and hardened detections are shared across all protected apps.

Device bans execute server-side against hardware-backed identity — surviving reinstalls, account switches, and device wipes — and are enforced network-wide, so a cheater burned in one title stays burned everywhere. When a novel technique appears against any single game, the defense ships to all of them automatically, with no extra integration work from any studio.

Small games inherit the battle scars of the largest ones. Attackers never start over against Kubian — they start over against everything Kubian has already learned.

Always on. Always active. Always battle tested.

Not a slogan — an operating posture. This is what "always" means at every layer of the system.

On means serving. Active means watching. Tested means proven.

Too many security products are "always on" the way a statue is always on — present, but inert. Kubian is on the way a immune system is on: circulating, sensing, and responding, every second of every day.

Always on: the verification fleet and the edge serve around the clock with no maintenance windows for defense updates — signed policy pushes land in 30 seconds, revocation entries take effect immediately, and version gates close without downtime. If a node ever needs attention, identical nodes absorb its traffic; the network doesn't blink.

Always active: on-device, the core library sweeps for threats every 2 seconds, re-polls ban state every 10 seconds, and renews device certificates before they expire. Server-side, every detection fires a realtime alert with full signal context, dashboards refresh every 10 seconds, and any response slower than 400 milliseconds pages the team automatically. Nothing waits for a human to notice — the loop is closed by code.

Always battle tested: live production traffic, hostile probing from day one of every release, a patch cycle measured in hours and days instead of quarters, and every lesson shared network-wide. Kubian doesn't prepare for the fight. It lives in it.

Always on

Fleet + edge serving 24/7 with zero-downtime defense updates. Protection doesn't take nights, weekends, or deploy freezes off.

Always active

2-second device sweeps, 10-second ban re-polls, realtime alerts, and a 400ms self-pager. Watching is the default state, not a mode.

Always battle tested

Probed in production, patched continuously, immunity shared across every protected app. Yesterday's attack is today's detection.

Ready to ship behind defenses that never sleep?

Join the network where every attack makes every game stronger. Start an inquiry or read the integration docs.

Built by a small team over two years — read the development story →.