Skip to content

Features

Eight tabs, plus a few capabilities that exist as a C++ API but are not wired to the UI yet. Those are called out explicitly rather than implied.

First scan         โ†’  Narrow: Changed     โ†’  Narrow: Exact 42
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€        โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€     โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
2000 results          87 results             3 results
0x1A001234            0x1A001234             0x1A001234  โœ“
0x1A001238            0x1A001238             0x1A005580  โœ“
0x1A001240            ...                    0x1B000020  โœ“

Enter a value and tap scan. Once there are results, the narrow bar appears and the action button switches to filtering.

Value types

Type Input example
int8 int16 int32 int64 100, -5, 0xFF
uint8 uint16 uint32 uint64 255
float double 3.14
hex โ€” IDA-style pattern FF 43 01 D1 ?? ?? ??
string PlayerName
regex HP:[0-9]+

Tap the type button to cycle. Input accepts an optional sign and a 0x prefix.

Malformed input is rejected, not truncated

A value that is empty, unparseable, out of range for its type, or has trailing characters is refused with an error. It used to be silently coerced โ€” "12abc" became 12, and 300 as an int8 became 44.

Narrowing filters

Available in the narrow bar: Changed ยท Unchanged ยท Inc ยท Dec, plus Reset. Entering a value instead of tapping a filter narrows to an exact match.

Comparisons are numeric, honouring sign and floating point. A bytewise compare gets this wrong on little-endian ARM64 โ€” 1 โ†’ 256 is an increase, but its low byte decreases.

Core API only

CompareMode::GreaterThan and LessThan exist in Scanner::narrowResults but have no narrow-bar buttons yet.

Batch modify and export

Long-press the action button for Export to JSON and Batch Modify. Batch modify reports how many addresses were actually written, not just how many were attempted.

๐Ÿ”ง Patch

Address      Original       Patched        State
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”€โ”€โ”€โ”€โ”€โ”€
0x1A001234   FF 43 01 D1    1F 20 03 D5    โœ… ON
0x1A005580   E0 03 00 AA    1F 20 03 D5    โธ OFF
             โ†‘ auto backup                 โ†‘ toggle

Input is 0xADDR HEXBYTES [label]. Original bytes are captured before the first write, so a patch can be toggled off. Tap a row to toggle, swipe to delete (restoring the original first), long-press for undo/redo.

๐Ÿ”’ Freeze

0x1A001234  =  99999  (float)  [FROZEN]   โ† tap to pause
0x1A001238  =  1      (int32)  [INC +1]   โ† auto-increment each tick
0x1A00123C  =  100    (int32)  [PAUSED]   โ† tracked but not writing

Input is 0xADDR VALUE [type]. A background worker rewrites the value every 16 ms. Long-press a row to toggle auto-increment.

Core API only

FreezeManager::addConditional supports writing only while a threshold condition holds. No UI for it yet.

๐Ÿ‘ Watch

0x1A001234   float    42.0 โ†’ 43.0   โ–ฒ  (changed 7x)
0x1A001238   int32    99  โ†’ 99      ยท  (unchanged)
0x1A00123C   int32    0   โ†’ 255     โ–ฒ  (changed 1x)

Input is 0xADDR [type]. A 100 ms poll records previous โ†’ current and a change count; the table refreshes twice a second while there are entries.

Core API only

WatchManager::setTrigger attaches a compare mode, threshold and one-shot flag, firing a callback outside the manager lock. No UI for it yet.

๐ŸŒฟ Pointer scan

Target: 0x1A001234

Chain 1: [UnityFramework + 0x1234AB] โ†’ +0x10 โ†’ +0x28 โ†’ +0x00  โœ“
Chain 2: [GameLib + 0xABCD00] โ†’ +0x08 โ†’ +0x00                  โœ“
Chain 3: [GameLib + 0xABCD10] โ†’ +0x08 โ†’ +0x00                  ??

Input is 0xADDR [depth] [maxOffset]. Finds module-relative chains that resolve to the target, so an address survives relaunches and ASLR. Chains are stored as module + offset plus a list of dereference offsets.

๐Ÿ’พ Dump

0xADDR len      โ†’  hex dump
0xADDR asm      โ†’  ARM64 disassembly

0x1A001234  FF 43 01 D1   STP  x29, x30, [sp, #-0x10]!
0x1A001238  FD 03 00 91   MOV  x29, sp
0x1A00123C  1F 20 03 D5   NOP                           โ† long-press to NOP

The disassembler covers common ARM64 encodings โ€” branches, loads/stores, moves, arithmetic โ€” and falls back to raw opcodes otherwise.

A NOP from this tab is not undoable

It is written directly rather than through the patch list, so it does not appear on the Patch tab and cannot be toggled back.

๐Ÿงต Threads ยท ๐Ÿ“ฆ Modules

Threads                              Modules
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€     โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
tid 0x103  PC 0x1A2B3C4D  RUNNING    UnityFramework   0x104B00000
tid 0x207  PC 0x1B0000A0  WAITING    GameLib          0x1051C0000

Threads enumerates via task_threads() and reads ARM64 PC/SP/LR plus run state. Modules lists loaded images with a substring filter; tap to copy the base address, long-press to copy the full path โ€” which feeds directly into an image-scoped pattern scan.

Sessions

Bookmarks, patches, freezes, pointer chains and search history are saved to ~/Documents/Shirayuki/<bundleid>_autosave.json when the app backgrounds.

Addresses persist as hex strings and types as tags, so a value above 2^53 and a future reordering of the ValueType enum both survive a round trip. Saves go through a temp file and rename, so an interrupted save cannot replace a good session with a truncated one.

Not functional yet

Shipped as API surface only, needing on-device work:

  • Speedhack โ€” Speedhack::setScale/install is stable, but the mach_absolute_time interposition is unimplemented.
  • Hotkeys โ€” SYHotkey bind:action: exists; multi-finger gesture hit-testing is unimplemented.
  • Group scan (GroupScan) โ€” multi-field struct matching, e.g. {HP, MP, state}.
  • Snapshot diff (Snapshot) โ€” capture a range and diff two captures.
  • Read cache (ReadCache) โ€” per-thread TTL cache for the poll loops.

The last three are complete and usable from C++; they simply have no tab.