CYREX
Back to Portfolio
Security Testing

Doom Eternal

Client:Bethesda Softworks (id Software)

Cyrex partnered with Bethesda to conduct grey box penetration testing for DOOM Eternal, securing backend live services including matchmaking, account management, and session controls to reinforce server-side security.

The Challenge

Securing Backend Services for a Global AAA Release

DOOM Eternal, developed by id Software and published by Bethesda Softworks, launched to critical acclaim and significant global adoption. As a large-scale AAA title with online components, protecting backend services was essential to maintaining player trust and operational stability.

The scope focused on non-gameplay backend systems responsible for:

  • Matchmaking
  • Party and party management
  • Account creation and registration
  • Session management and authentication
  • Account and profile management
  • In-game achievements and reward systems

Vulnerabilities in these areas could impact player progression, account integrity, and platform reputation. Bethesda required structured security validation to ensure server-side controls were robust before and after launch.

The Cyrex Solution

Grey Box Penetration Testing of Live Services

Cyrex conducted comprehensive grey box penetration testing, combining architectural awareness with real-world attack simulation.

Our objective was to validate the integrity of server-side security controls and identify weaknesses that could be exploited by malicious actors.

Backend & Account System Assessment

The engagement included structured testing of:

  • Matchmaking workflows
  • Party and session handling logic
  • Registration and authentication mechanisms
  • Profile management controls
  • Achievement and reward validation

We simulated attacker behavior to evaluate access control enforcement, session validation, and business logic protections within backend services.

Vulnerability Identification & Remediation

During testing, Cyrex identified multiple vulnerabilities ranging in severity from low-priority issues to findings deemed critical by Bethesda.

We delivered:

  • Detailed documentation of findings
  • Proof-of-concept exploitation scenarios
  • Prioritized remediation guidance

Following remediation, Cyrex conducted structured sanity and regression testing to confirm that vulnerabilities were resolved and no additional issues were introduced.

The Outcome

Reinforced Backend Security for a AAA Title

  • Identification and remediation of critical server-side vulnerabilities
  • Improved protection of account and session management systems
  • Reinforced validation of matchmaking and reward logic
  • Increased confidence in backend resilience
CYREX VERIFIED

Don't Let Players Find the Weakness

Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.

Response time: <24 hours • NDA included • No commitment required