{
  "version": "2025-04-26",
  "rules": [
    {
      "id": "example-cheat-process",
      "enabled": false,
      "name": "Example Cheat Process",
      "severity": "DETECTED",
      "description": "Replace with a real cheat process name (no .exe needed, substring match).",
      "match": {
        "process_name": "examplecheat"
      }
    },
    {
      "id": "example-cheat-dll",
      "enabled": false,
      "name": "Example Cheat DLL",
      "severity": "DETECTED",
      "description": "Replace with a real DLL module name loaded by any running process.",
      "match": {
        "process_module": "examplecheat.dll"
      }
    },
    {
      "id": "example-cheat-folder",
      "enabled": false,
      "name": "Example Cheat Installation Folder",
      "severity": "DETECTED",
      "description": "Supports %APPDATA%, %TEMP%, %PROGRAMFILES%, etc.",
      "match": {
        "file_path": "%APPDATA%\\ExampleCheat"
      }
    },
    {
      "id": "example-cheat-config",
      "enabled": false,
      "name": "Example Cheat Config File",
      "severity": "WARNING",
      "description": "Config or data file left behind by a cheat tool.",
      "match": {
        "file_path": "%APPDATA%\\ExampleCheat\\config.ini"
      }
    },
    {
      "id": "example-registry-key",
      "enabled": false,
      "name": "Example Cheat Registry Entry",
      "severity": "WARNING",
      "description": "Registry key created by a cheat installer. Use HKCU\\ or HKLM\\ prefix.",
      "match": {
        "registry_key": "HKCU\\Software\\ExampleCheat"
      }
    },
    {
      "id": "example-registry-value",
      "enabled": false,
      "name": "Example Cheat Registry Value",
      "severity": "WARNING",
      "description": "Specific registry value set by a cheat. Omit registry_value to match key existence only.",
      "match": {
        "registry_key": "HKCU\\Software\\ExampleCheat",
        "registry_value": "Installed"
      }
    }
  ]
}
