- C++ 89%
- C 10.7%
- CMake 0.3%
BLAZE_DIAG_SUBLEVEL forced an early clean exit at the Boot load (~157KB run, [AnthemHook] process detach at Boot/Boot) because the walker (0x0174EB60) and byName (0x00488F20) hooks fire during the BOOT load. byName 0x00488F20 is a low-RVA small/generic function - the 'no trampolines on universal primitives' trap (MinHook corrupts the prologue). Only Hook B (findStartPoint 0x0A7B4560) is needed for the StartPoint-resolve data ([SubLevelResolve] StartPoint=... -> rec=... autoload=N) and it fires cold (once per resolve), off the Boot hot path. Walker/byName detours retained (unused) for easy re-enable behind a sub-flag. Builds clean; deployed to both slots. |
||
|---|---|---|
| AnthemHook | ||
| dxgi | ||
| minhook | ||
| .gitignore | ||
| README.md | ||
anthem-dll - client-side instrumentation DLL
AnthemHook is the in-process hook and probe layer injected into retail
Anthem.exe. It is the client half of the stack: every [Kick], [PermitDeep],
[BundleNameIndex], [LoadGate STALL] and [CommitState] line the
reverse-engineering docs quote comes from here. The server half lives in
anthem-blaze and
anthem-gameserver;
findings go to anthem-docs.
Layout
| path | what |
|---|---|
AnthemHook/StateScanHook.cpp |
the bulk of it - state-machine probes, the force-load/kick path, bus and ghost instrumentation |
AnthemHook/Hooks.cpp |
socket and Blaze-transport hooks |
AnthemHook/FrankensteinHost.cpp |
in-proc host scaffolding |
AnthemHook/dllmain.cpp |
attach/detach, hook install order |
AnthemHook/include, AnthemHook/src |
vendored MinHook used by the project |
minhook/ |
upstream MinHook sources |
dxgi/ |
proxy loader - the game loads dxgi.dll, which loads AnthemLogger.dll |
Build output (x64/), .vs/ and the archived oldExeUnpatchedAnthemHook.7z
are deliberately not tracked; see .gitignore.
Migrated to the forge 2026-09-18 from the un-remoted
F:\anthem\anthemproject\code\AnthemPacketLogger_realudp\. That tree is now
superseded - edit here, commit and push. The section below is the original
project README, retained for its build instructions.
AnthemPacketLogger_realudp
Fork of AnthemPacketLogger/ for use with the real-UDP Blaze fork (blaze_realudp_fork).
What is different from the main DLL
| Feature | Main DLL (AnthemLogger.dll) | This fork (AnthemLogger_realudp.dll) |
|---|---|---|
| bridge::Start() | Called in DoHooks() | Disabled (commented out) |
| bridge::Stop() | Called in DoUnHooks() | Disabled |
| bridge::ForwardToPython() | Called in MySockCallback | Disabled |
| bridge::CaptureCtx() | Called in MySockCallback | Disabled |
| BRIDGE_DISABLE_HMAC | Active | Still active (required) |
| Observer hooks (PeerAccept, PeerConstruct, DequeueGate, ProbeRecv, IRBS, setters) | Active | Still active |
| Output DLL name | AnthemLogger.dll | AnthemLogger.dll (aligned with dxgi loader) |
| PostBuildEvent auto-copy | Copies to game folder | Enabled for Release|x64 - copies AnthemLogger.dll -> $(ANTHEM_INSTALL_DIR)\AnthemLogger.dll (default C:\gamews\Anthem2\) and the hv\ subdir if present. Emits a loud Write-Warning per slot when the copy fails (game running, DLL locked) so the build log makes clear the deployed DLL is stale. Debug|x64 has no post-build copy. |
Build
Open in Visual Studio (project uses PlatformToolset v145 - VS 2026 / VS 18 preview) or run MSBuild directly:
cd AnthemHook
& "C:\Program Files\Microsoft Visual Studio\18\Community\MSBuild\Current\Bin\MSBuild.exe" AnthemHook.vcxproj /p:Configuration=Release /p:Platform=x64
If your VS install lives elsewhere, find MSBuild with:
& "C:\Program Files (x86)\Microsoft Visual Studio\Installer\vswhere.exe" -latest -requires Microsoft.Component.MSBuild -find MSBuild\Current\Bin\MSBuild.exe
Output: AnthemHook\x64\Release\AnthemLogger.dll (renamed 2026-08-20 from AnthemLogger_realudp.dll - the loader dxgi.dll hardcodes AnthemLogger.dll and older builds silently mis-deployed).
To disable the auto-copy for a build (e.g. when the destination is a protected path):
& "...MSBuild.exe" AnthemHook.vcxproj /p:Configuration=Release /p:Platform=x64 /p:PostBuildEventUseInBuild=false
Deploy for testing
A Release|x64 build auto-deploys via PostBuildEvent (see AnthemHook.vcxproj lines 136-138):
it copies x64\Release\AnthemLogger.dll -> $(ANTHEM_INSTALL_DIR)\AnthemLogger.dll (default
C:\gamews\Anthem2\) and also to the hv\ subfolder if that exists. If the game is running,
the file is locked and each failed copy emits a Write-Warning line in the build log (no
longer silently swallowed) - the build still reports success but the deployed DLL is stale
until you close the game and rebuild.
For Debug|x64 (no PostBuildEvent), or if your install lives elsewhere, copy manually:
Copy-Item -Force "AnthemHook\x64\Release\AnthemLogger.dll" "<game-folder>\AnthemLogger.dll"
Override the deploy destination for one build by setting ANTHEM_INSTALL_DIR before invoking
MSBuild.
Environment variables
Required for a normal capture run: none. The DLL runs with sensible defaults.
Optional:
| Var | Effect | Default |
|---|---|---|
ANTHEM_DLL_LOG_DIR |
Directory for output.txt (tee'd stdout) and ghost_schema.log (ghost-schema capture). |
Historical dev-box path (C:\Users\calvi\Documents\New folder\anthemproject) - falls back if unset, does NOT exist on this box, so output.txt warns and ghost_schema.log silently no-ops. Set this to a writable dir. |
Ghost-schema capture (patches 0011/0013/0042/0043):
Both required for a ghost-schema capture run:
setx BLAZE_DIAG_HOOKS 1 # installs InstallGhostQ1DumpHook (without this, capture is empty)
setx BLAZE_GHOST_GAPDUMP 1 # enables gap + prefix word dumps
setx ANTHEM_DLL_LOG_DIR "F:\anthem\anthemproject\code\logs" # or wherever you want the log
Delete any pre-existing ghost_schema.log at that dir before a run - the log appends (per-run marker ===== GHOST SCHEMA CAPTURE OPEN pid=N =====), analysis without segmenting on the marker mixes captures. After the capture, clear BLAZE_DIAG_HOOKS - its full ~84-hook footprint has regressed Fort Tarsis on some builds:
setx BLAZE_DIAG_HOOKS ""
Do NOT set unless you know what you are doing:
ANTHEM_WIRELLBRIDGE=1- re-enables a wire->engine bridge with mismatched struct layout. Passes raw NLL pointer toFUN_14337d850which expectsLoadLevelInfoat +0x28. Crashes (SEH fault + leaked pool node). SeeStateScanHook.cpp:7203-7211.BLAZE_FORCE_*family (LOADLEVEL, LOADLEVEL_COOP, LEVEL, STARTPOINT, GAMEMODE, INCLUSION, REALM, REALM_ENQONLY, REALM_FULLCHAIN, TRYLOADLEVEL, LINKLEVEL) - inject forced state into engine internals; change what your capture contains. Also noteLOADLEVELandLOADLEVEL_COOPdefault ON in the current fork (2026-07-23 change): F7 auto-fires the freeplay-host force-load. Set=0explicitly to restore the pre-flip baseline.BLAZE_DIAG_*family (SOCK, REALM, GATE, SPAWN, CONNSTALL) - chatty diagnostic paths, safe but noisy in the log.BLAZE_FH_PORT,BLAZE_FRANKENSTEIN_HOST,BLAZE_FH_FORCE_ACCEPT,BLAZE_FH_ARM_AT_BOOT- Frankenstein-host tunables (FrankensteinHost.cpp); only relevant when running Frankenstein.BLAZE_PT_PLAINTEXT,BLAZE_HOLD_ISLOADED,BLAZE_SPARE_MENU_PEER,BLAZE_DUMP_GHOST_Q1,BLAZE_BLOCK_SINGLETON_TEARDOWN,BLAZE_REBUILD_BUNDLE_SINGLETON- specialised flags for specific investigations; do not set unless you're running that investigation.
How to switch between forks
To switch TO real-UDP fork:
- Stop game, stop main Blaze
- Rebuild fork Release|x64 (PostBuildEvent auto-copies to game folder) - or copy
AnthemHook\x64\Release\AnthemLogger.dllmanually - Start
blaze_realudp_forkBlaze - Start game
To switch BACK to main branch:
- Stop game, stop realudp Blaze
- Rebuild main DLL - its PostBuildEvent also targets
C:\gamews\Anthem2\AnthemLogger.dll, so it will overwrite the fork's deployed copy. (Alternatively, manually copyAnthemPacketLogger/AnthemHook/x64/Release/AnthemLogger.dll.) - Start
blaze_test_share_experimentalBlaze - Start game