Newbie Spellweaver
- Joined
- Oct 2, 2023
- Messages
- 13
- Reaction score
- 21
Hey everyone,
GitHub: https://github.com/Bearusx/AoC-RiseOfPhoenix
Sharing a project I've been working on for a while. Now that AoC's Alpha-2 servers are shut down for good, the retail client just sits there with no backend to talk to. This is a from-scratch reverse-engineered server emulator that gets the client to log in, load Verra, possess your character, and render the world — all against a local loopback.
I'm posting this here because I'd love for more people to get involved and turn this into an actual functioning emulator. Right now it's me, There's enough working to prove the approach is viable, and enough left to do that nobody's going to finish it solo. UE5 RE folks, server emu devs, anyone who wants to dig into protocol work — we can take this from "client connects and renders terrain" all the way to a real playable emulator. The foundation is there.
It's NOT a populated game server today. No combat, no NPCs with AI, no quests, no economy. What it is: a working UE5 / IntrepidNetDriver wire-protocol implementation built on captured replays + IDA Pro decompilation of the client. Open source, open development.
What works right now
In progress
Not in scope (yet)
Screenshot (in-game, possessed):
This is a replay! The first picture is native
Tech
How it was figured out
GitHub: https://github.com/Bearusx/AoC-RiseOfPhoenix
Includes:
Run: launch_all.bat currently plays back the captured replay and patches in our minted NetGUIDs / spawn coords. The PM148+ roadmap replaces this with full live actor synthesis.
Run: launch_all_native.bat runs the from-scratch live actor synthesis
Looking for contributors
Especially valuable areas:
Legal
Cheers.
GitHub: https://github.com/Bearusx/AoC-RiseOfPhoenix
Sharing a project I've been working on for a while. Now that AoC's Alpha-2 servers are shut down for good, the retail client just sits there with no backend to talk to. This is a from-scratch reverse-engineered server emulator that gets the client to log in, load Verra, possess your character, and render the world — all against a local loopback.
I'm posting this here because I'd love for more people to get involved and turn this into an actual functioning emulator. Right now it's me, There's enough working to prove the approach is viable, and enough left to do that nobody's going to finish it solo. UE5 RE folks, server emu devs, anyone who wants to dig into protocol work — we can take this from "client connects and renders terrain" all the way to a real playable emulator. The foundation is there.
It's NOT a populated game server today. No combat, no NPCs with AI, no quests, no economy. What it is: a working UE5 / IntrepidNetDriver wire-protocol implementation built on captured replays + IDA Pro decompilation of the client. Open source, open development.
- StatelessConnect handshake + NMT negotiation
- Auth, character select, lobby transitions
- LoadMap → Verra_World_Master, World Partition initializes
- PC + Pawn + PlayerState replicated, NetGUIDs registered
- ClientRestart RPC, ServerAcknowledgePossession flows back
- Pawn spawned at real Riverlands coordinates (-777762.2, 616611.1, 15944.1 cm)
- Verra terrain visible (HLOD level), player nameplate at correct location
- (LastGoodPacketRealtime not advancing — need continuous actor traffic, fix is PM148)
- World Partition cells unload after loading screen ends (HLOD-only view, no detailed foliage)
- No visible body mesh — CharacterAppearanceComponent replication needs more work
- ServerMove parsed but not echoed (no movement reconciliation yet)
- Multi-client testing
- Server-side game logic (AI, combat, persistence)
- Anything beyond PC/Pawn/PlayerState in the schema
This is a replay! The first picture is native
- C++ / CMake / vcpkg
- Stock UE5 wire protocol (PacketNotify, bunches, NetGUID exports, RepLayout) + AoC-specific extensions (FIntrepidNetGUID 128-bit, custom flags at UNetConnection+0x240)
- Captured pre-shutdown replays as ground truth (replay_data.bin in repo)
- ~350 IDA Pro decomp dumps included in docs/ida-dumps/ so anyone can verify RE claims
- Disassembly of AOCClient-Win64-Shipping.exe (the IDA decomps are in the repo)
- Captured-replay byte-level analysis (YLPR replay format walker + per-packet decoders included)
- Empirical probe iteration for RPC handle indices and ambiguous wire-format fields
- SDK IN GITHUB
Includes:
- Full source (C++)
- Captured replay fixture (fixtures/replay_data.bin, 7.4 MB plaintext)
- IDA decomp dumps (docs/ida-dumps/, ~350 files / 44 MB)
- Build + launch scripts (Windows / VS2022)
- Progress milestone notes inline in source comments (search for PM107, PM118, PM146, etc.)
Run: launch_all.bat currently plays back the captured replay and patches in our minted NetGUIDs / spawn coords. The PM148+ roadmap replaces this with full live actor synthesis.
Run: launch_all_native.bat runs the from-scratch live actor synthesis
Especially valuable areas:
- Wire-format gaps — any Mismatch read log line is fertile ground
- Disassembly cross-references against AoC's RepLayout customizations
- More captured-replay analysis (extracting property fixtures from existing pcaps)
- Documentation — every PM tagged in source has a story; not all of them are written up
- No game assets, art, audio, or Blueprint source included or redistributed
- No live Intrepid service contacted — everything is local loopback only
- EOSSDK proxy explicitly redirects auth calls AWAY from real Epic/Intrepid services
- Educational reverse-engineering, non-commercial
- Not affiliated with Intrepid Studios. If they ask, the repo gets archived
Cheers.
Last edited:

