Findings
This section records what we learned about how Dauntless’s online side worked, from two client builds. We started on the final client and later moved to an older one that Undaunted supports. Every page says which build a fact is about, and marks anything we have not verified.
| Build | Released | Engine and packaging | Our use |
|---|---|---|---|
| 2.1.1 (“Awakening”) | December 2024, the final release | UE5, IoStore containers | Where most of the reverse engineering was done: the backend contract, the login chain, crash forensics |
| 1.4.4 | October 2020 | UE4, pak v9 | The build we run, with Undaunted |
This site and the repository contain no game files. The pages quote endpoint URL templates, field names, function names, addresses and short snippets, and only as much as each explanation needs.
Pages
| Page | Build | What it covers |
|---|---|---|
| Verifying game files | Both | How we checked that community-archived copies are genuine, complete and clean before running anything. |
| Game assets and config | Both | How each build stores content and cooked config, how to read it, which map paths matter, and what a user config file can override. |
| Backend contract | Mostly 2.1.1 | Phoenix Labs’ REST services on steelyard.ca hosts (not PlayFab): hosts, envelope rules and the response shapes we pinned down. |
| Reading the JSON contract from the binary | 2.1.1 | The method for recovering field names, types and envelopes from the client’s code, including the mistakes we made. |
| Client internals | 2.1.1, checked on 1.4.4 where it matters | What the shipped executable can and cannot do: launch switches, logging, the hang detector, and why it is a client-only build. |
| How multiplayer works | 1.4.4 | How Undaunted turns extra copies of the client into game servers by driving the intact network layer from an injected DLL. |
| Crash forensics | Mostly 2.1.1 | Turning crash reports into instruction addresses, and what each crash we hit turned out to be. |
| The 2.1.1 standalone attempt | 2.1.1 | How far a solo boot into Ramsgate got, where it stopped (no controllable player), and where to continue. |
| Friends, parties and guilds | 1.4.4 | How the client finds other players, the exact replies friends, parties and guilds need, why the first two-player test showed nothing, and what is still unconfirmed. |
| Text chat | 1.4.4 | How the client’s text chat works on our server, why the first chat server showed UID-… instead of names, the nickname check, the rooms and who may join them. |
| The in-game store | 1.4.4 | How the store screen lists and buys an offer, and the free store built from Harmonic’s fork: the purchase token, the catalogue and its tabs, stacked and instanced grants, and which character gets the item. |
| Escalation | 1.4.4 | How Escalation progress is saved, the season registry read from the client, the rules every save must pass, and what players see when real saves are switched on. |
| The Harmonic port | 1.4.4 | What we took from Harmonic’s 1.4.4 fork and what we kept of our own, feature by feature, with the reason for every choice. |
The scripts used for most of the static analysis are described on Tools.
A correction
We once concluded that multiplayer was impossible, because both retail builds are client-only: the server entry points are compiled out. That conclusion was wrong. The network layer beneath those entry points is intact, and an injected DLL can drive it, which is how Undaunted hosts Ramsgate and hunts on 1.4.4. How multiplayer works explains the details.