github bbfox0703/UE5CEDumper v3598
UE5CEDumper v3598

2 hours ago

UE5CEDumper — Unreal Engine 4/5 dumper (C++ DLL + Cheat Engine bridge + Avalonia UI).

About this release

Mostly about getting types right: struct, object and enum types that were missing or wrong are now filled in, above all in the SDK header (.h) and USMAP exports and on older UE4 games (4.11–4.24). Nothing changes in how you use the tool. As before, the list is only what you are likely to notice; small fixes are not listed.

New

  • USMAP export now includes the game's Blueprint structs and enums, so FModel / CUE4Parse can read the assets that use them (EVERSPACE 2: 22 structs and 45 enums that used to be missing).
  • SDK header export:
    • Blueprint structs are now defined in the header, so a member of such a type points to a struct you can find.
    • A member that holds a class says which one — TSubclassOf<class Pawn> DefaultPawnClass instead of just "a class" — and maps and sets that hold objects name the object's class instead of UObject.

Fixed

  • UE 4.18–4.24 games (e.g. DRAGON QUEST XI S): right after connecting, struct, object and enum types were read from the wrong place, so the SDK export showed raw bytes and plain UObject*, and the USMAP export named none of its structs. Only a Live Walker walk happened to repair it, and whatever was read before that stayed wrong for the session. They are right from the start now. Arrays, maps and sets on these games also say what they hold.
  • UE 4.11–4.17 games (e.g. NEKOPALIVE): Live Walker now shows the element type of struct arrays, and games whose engine version is not recognised read their struct, object and enum types from the right place.
  • UE 5.0 / 5.1: members that hold a class came out as raw bytes in the SDK export, and as a type the USMAP readers cannot size. Fixed.
  • Titan Quest II (UE 5.7): types are right from the moment you connect, instead of being corrected a little later.
  • SDK header export: names C++ rejects are renamed, and the comment keeps the real name — members called class or default, two members with one name, names with spaces, type names with a dash, two Blueprint types sharing one name, and a type that inherited from itself.
  • Live Walker → Export .h: a member was declared with the type of its current value (an enum as the name of its current value, a pointer as whatever it pointed at right then). It now uses the declared type, and names the parent class instead of repeating its members.
  • Class lists (with Game classes only unticked — class list, Property Search, Interesting Functions): five engine entries named Default__Class, Default__BlueprintGeneratedClass, … showed up as empty classes, and every class count was five too high. They are gone, from Dump All and the SDK / USMAP exports too.
  • DataTable rows (Live Walker, Class Pivot): TEnumAsByte columns now show their enumerator names.
  • Cheat Engine structure dissect (ue5_dissect.lua): a struct member could be expanded with the fields of an unrelated class found next to it in memory (EVERSPACE 2: seven Blueprint members). Such a member is now left unexpanded.
  • A member's struct, class or enum type is now accepted only when it really is one, so games with an unusual memory layout are less likely to show a wrong type name.

Details for anyone who wants them: v3580…v3598

⚠ If anything regresses for you, fall back to v3580.

Setup

  • Deploy proxy DLL from UI's Proxy Deploy tab (recommended), inject via UI's Proxy Deploy tab (AntiVirus may block UI; add it to exclude list), inject via the bundled Cheat Engine table (UE5CEDumper.CT), or drop the proxy version.dll into the game's Binaries\Win64 (manual mode).
  • If neither version.dll nor dinput8.dll is loaded by your game, try dxgi.dll; if that filename is already taken (ReShade commonly uses it), try winmm.dll.
  • See README.md for details.

The exe is unsigned — Windows SmartScreen / antivirus may warn on first run. Verify the download with the included .sha256.
Inject scripts like inject-ue.ps1 or UE5DumpUI.exe may be labeled as a hacking tool by antivirus. Add them to your exclusion list, or review the code in this repository and compile it yourself.

Just rambling, feel free to skip: The recent releases adopted a much more rigorous approach. By pairing up with different Unreal Engine versions, building corresponding custom test games for each, and running real-world execution tests against potential edge cases, I was able to squash a ton of bugs. The overall stability is definitely converging now. The earlier codebase generated heavily with Opus 4.5 relied mostly on manual testing back then—honestly, without a complete test case suite. Over the past month or so, I've managed to run live verification on whatever parts were previously untested.
Over the last two months, I changed my testing methodology. Previously, I'd test on actual commercial games using manual verification (basically just me doing the testing solo, with very few people occasionally helping out), which honestly wasn't very systematic. Recently, instead of trying to hunt down testable patterns in commercial games, I decided to just build multiple custom games myself. For one, it keeps the package size down; second, it makes it way easier to control the exact test scenarios.
The current limitation is that I can only solidly test UE 4.23 and above, plus I don't have every single version installed (eats up way too much disk space). That recent SDK export issue was also only pinpointed by diving straight into the UE source code.

Don't miss a new UE5CEDumper release

NewReleases is sending notifications on new releases.