All articles
Published7 min read

Silent aim on RedM: the shot that lands where nobody aimed

Silent aim on RedM does not move the crosshair, it moves the bullet. How the server proves it by putting the shooter's own account next to the victim's.

silent aimRedMdetectioncorroborationPvP

A player dies in the middle of the street. He replays his own recording frame by frame: the man across the road was looking somewhere else, gun at hip height, and the bullet still arrived in his skull. Nobody on your staff can say what happened, because nothing abnormal happened on screen. That is exactly what silent aim does, and it is why it is the hardest cheat to punish on a roleplay server.

What it actually is

A classic aimbot moves the camera: it snaps the crosshair onto the target, and that is visible. Silent aim never touches the camera. It lets the player aim wherever he likes, then rewrites the shot on the way out. The client tells the server: shot origin, direction, entity hit, impact point. The cheat edits those fields after the click and before transmission.

The result is a pure contradiction: the declared aim vector points north, the declared impact is to the west, and the game applies the damage anyway. On RDR3 it produces scenes that are very recognisable once you know how to read them - a revolver connecting at eighty metres behind a rock, a shot aimed at the ground killing a player on a balcony, a target dropping while the shooter reloads at a walk.

The high quality variant is quieter still: the cheat deviates by a few degrees only, just enough to turn a miss into a kill. The player looks legitimate. He simply has a hit rate nobody else has.

Why the human eye cannot settle it

Three reasons, and they stack:

  • The victim never sees the shot. She sees the consequence. What her machine receives is already the version the cheat corrected, so the impact lands in a plausible position.

  • The shooter has nothing to hide on screen. No camera lock, no inhuman movement. A recording of his own screen would look innocent.

  • Latency blurs everything. On a busy server, two to three hundred milliseconds routinely separate what one player sees from what the other sees. A shot that looks impossible can be an ordinary desync, and the reverse is true as well.

That is why silent aim survives for months on well administered servers. Reports come in, admins go and look, see nothing, close the ticket. The cheater learns he will not be caught by eye and plays more openly every week.

The only evidence that holds: two accounts of the same shot

A shot is not one event, it is two accounts. The shooter describes his shot. The victim describes the impact she took. Those two accounts come from two different machines, and the cheat only runs on one of them. That is the structural flaw of silent aim: to stay coherent, it would have to corrupt the victim's computer too.

So the server keeps both, separately. From the shooter: where his camera was, which direction it pointed, which weapon, exactly when. From the victim: where the round came from, which body part, how much damage. Then the two are paired inside a short time window, and you ask whether they describe the same world.

Concretely we ask three questions, in this order. None of them is sufficient on its own - it is their accumulation that makes the case.

1. Was the camera on anyone at all?

Before the impact, one simple question: at the moment of the shot, did the shooter's aim vector cross a target? Not the right target - a target. A player who damages an entity while his aim pointed at strictly nobody did not miss his shot, he never made the gesture.

This is the cleanest case, and it is also the one a well tuned cheat avoids: good silent aim keeps a plausible target somewhere down the axis so it does not get caught here.

2. Is the victim the one who was aimed at?

Second question: is the entity the shooter declares he aimed at the same entity that actually took the round? A mismatch between the two - aim on A, impact confirmed by B - has no legitimate explanation. A bullet does not change recipient in flight.

3. Is the angle physically tenable?

Then the quantitative measure: the angle between the direction the shooter declared and the vector that actually runs from him to the impact the victim reported. An honest shot gives a gap of a few degrees at most, explained by recoil, weapon spread and both players moving while the bullet travels.

We only treat the gap as suspicious above degrees, and only when it repeats across several correlated shots inside the same firefight. The exact threshold and the number of repetitions are not published: a cheat developer who knows them sets his deviation just under and goes invisible again.

Withheld/Detection thresholds are never published: a value that is known is a value a cheat is tuned just underneath.

Repetition is the important part. One isolated wide shot is a desync. Twelve wide shots in the same engagement is a program.

The file you hand to an administrator

A detection that cannot tell its own story is worthless: the player will dispute it, and part of your community will back him. What holds in that conversation is the two accounts placed side by side, shot by shot.

One correlated shot, as it appears in the file
shooter
position, aim direction, weapon, server timestamp
target on axis
none, or the id of the entity aimed at
victim
id, impact point, body zone, damage
angular gap
between declared aim and confirmed impact
latency
measured delay between the two accounts
recurrence
number of diverging shots in the same firefight

From there the conversation changes nature. You are no longer saying "the anticheat flagged him", you are showing eleven shots where the player's aim and his victim's wound cannot both be true.

What this method cannot do

Three limits, which we would rather write down ourselves.

You need a player victim. The whole demonstration rests on a second witness. A cheater who only shoots NPCs, animals or horses produces no corroboration at all: there is nobody on the other side to contradict his account. We will catch him some other way, or not at all.

A tiny deviation stays inside the noise. Silent aim tuned to one or two degrees is indistinguishable from recoil and latency. We could make it detectable by lowering the threshold, at the cost of alerts on honest firefights - and an anticheat that screams constantly ends up ignored, which is the subject of the article on false positives. So we accept missing the bottom of the spectrum rather than accusing your regulars.

A degraded connection produces noise. A player sitting at an unstable 400 ms naturally generates gaps. The correlation window accounts for that, and shots whose latency exceeds what the measurement can absorb are discarded, which means lost. A bad connection protects the cheater a little; that is the price of not banning a player on satellite internet.

The short version

  1. 1

    Silent aim does not move the aim, it rewrites the shot declared to the server: nothing abnormal appears on screen.

  2. 2

    No human witness can testify to it, neither the victim nor a recording of the shooter.

  3. 3

    The proof comes from the server confronting the shooter's account with the victim's: target on axis, identity of the victim, angular gap.

  4. 4

    One diverging shot is a network incident; a series of diverging shots is a program.

  5. 5

    With no player victim, no measurable gap, or latency too high, the method does not conclude - and we say so.

Correlated shot files can be read on real data in the demo panel, and the pricing is public. Baobab anticheat sets out the whole detection stack this shot correlation belongs to.

Keep reading

Judge on evidence, not on a claim

The demo panel is open read-only on real data, no account required.

Everything on one page: anticheat RedM, detections, evidence and panel.