Runtime Memory Guardian (RMG) is a modern C++20 library for defensive, read-only runtime memory monitoring on Windows and Linux. It helps applications detect signs of runtime tampering — modified code sections, suspicious inline/IAT/EAT hooks, and unexpected module loads — using documented, non-invasive techniques.
RMG is built for security engineers, anti-cheat/anti-tamper developers, and anyone who wants their application to notice when its own memory has been altered at runtime.
- Purely defensive. RMG only reads memory and reports observations. It never patches, injects, or modifies anything in the target process.
- Cross-platform by design. A single
IPlatformTraitsabstraction backs both the Windows and Linux implementations; the domain logic (integrity checking, hook detection, module monitoring) is written once. - No hidden dependencies. The core library has zero third-party dependencies — only the C++20 standard library. Tests and benchmarks fetch GoogleTest/Google Benchmark solely for development purposes.
- Fails loudly, never silently. Every fallible operation returns
rmg::core::Result<T>(std::expected-based); there are no hidden exceptions to catch.
- 🔒 Integrity baselines — hash code sections (SHA-256 by default) and detect any deviation later.
- 🔍 Memory scanning — enumerate and read memory regions with flexible filters (executable-only, W^X detection, per-module).
- 🪝 Hook detection — recognize documented inline-hook opcode patterns (
JMP,JMP [rip+disp32],PUSH;RETtrampolines); IAT/EAT validation logic is implemented and ready for the planned image-format parser (see docs/architecture/HOOK_DETECTOR.md). - 📦 Module monitoring — get notified when modules are loaded or unloaded unexpectedly.
- ⚙️ Continuous or on-demand monitoring — run a background polling loop via
ProcessMonitor, or drive checks manually. - 🖥️ CLI tooling —
rmg-clifor ad-hoc checks,rmg-baseline-generatorfor producing baselines to ship with your application.
#include <rmg/rmg.hpp>
#include <cstdio>
int main() {
auto guardian = rmg::api::RuntimeMemoryGuardian::createForSelf();
if (!guardian) {
std::fprintf(stderr, "%s\n", guardian.error().toDiagnosticString().c_str());
return 1;
}
if (auto result = guardian->establishBaseline(); !result) {
std::fprintf(stderr, "%s\n", result.error().toDiagnosticString().c_str());
return 1;
}
auto report = guardian->checkIntegrity();
if (report && report->isValid) {
std::printf("No tampering detected.\n");
}
}See examples/ for five progressively richer usage scenarios, and docs/guides/GETTING_STARTED.md for a full walkthrough.
cmake -S . -B build -DCMAKE_BUILD_TYPE=Release
cmake --build build --parallel
ctest --test-dir build --output-on-failureSee docs/guides/BUILDING.md for all CMake options, platform requirements, and CMake presets.
| Platform | Status |
|---|---|
| Windows 10/11 (x64) | ✅ Supported |
| Linux (x64, glibc) | ✅ Supported |
| macOS | ❌ Not currently supported |
Contributions are welcome — see CONTRIBUTING.md for coding standards, the PR process, and how to add support for a new platform. Please also review our Code of Conduct.
If you discover a security vulnerability, please follow the responsible disclosure process described in SECURITY.md. Please do not open a public issue for security-sensitive reports.
Runtime Memory Guardian is licensed under the MIT License.