Cocktail
NewIntroducing the instance manager

Run any script.
On every instance.

Cocktail is a modern security research platform for game penetration testing, exploit detection, and strengthening anti-cheats.

Keys from $0.99Attaches in under 5sLinux · x86_64
cocktail 1.4.2 — instance #1
connected0.24 ms
main.luauremote-log.luauRun
9local Players = game:GetService("Players")1011-- log every remote the client fires12local mt = getrawmetatable(game)13setreadonly(mt, false)1415local namecall = mt.__namecall16mt.__namecall = newcclosure(function(self, ...)17  if getnamecallmethod() == "FireServer" then18    record("→", self.Name, ...)19  end20  return namecall(self, ...)21end)
Terminalsinstance #1Filter
[12:04:01][ct]attached to instance #1
[12:04:01][exec]running remote-log.luau
[12:04:02]→BuyItem 1 "sword"
[12:04:02]→UpdateCoins 250
[12:04:03]✓hook installed · 0.24 ms/frame
remote-log.luauLn 9, Col 24Spaces: 2UTF-8LuauConnected

Representative UI mockup — Drawn to mirror the shipping interface as closely as possible. Some details differ in the actual product.

One platform, every tool you need.

Decompile and read any script, run across multiple instances at once, and stay stable through the longest research sessions.

Luau decompiler

Turn compiled bytecode back into clean, readable Luau you can study and adapt in seconds — real control flow, recovered names, and a comment on anything inferred.

Learn more

Instance manager

Run many instances side by side and broadcast one script across every one of them at once, with per-row memory, CPU and reconnect policy.

Learn more

Rock-solid reliability

A tuned engine and audited, reproducible builds keep long sessions running smoothly through heavy use. Every release is signed and listed in the changelog.

Learn more

Decompiler

Bytecode you can actually read.

Feed it a compiled module and get structured Luau back: real loops and conditionals instead of jump soup, local names recovered where the debug data allows, and a comment on every reconstruction the decompiler was not certain about.

  • Control flow reconstruction, not an instruction dump
  • Constant folding shown beside the original
  • Batch mode writes a whole tree to disk
Read the reference
out/target.luau
94% recovered
1-- recovered from module 0x41a2 (proto 7)2local function step(self, dt)3  local engine = self.Model:FindFirstChild("Engine")4  if not engine then5    return6  end78  local vel = engine.CFrame:vectorToObjectSpace(engine.Velocity)9  local radius = self._cachedWheelRadius1011  if not radius then12    radius = self.Wheels[1].Size.Y / 213    self._cachedWheelRadius = radius14  end1516  local spin = vel.Z * dt / radius17  self.WheelRotation = (self.WheelRotation + spin) % 6.283185318end
cocktail — instance manager
4 connected

Instance manager

Launch and supervise many instances

Add
InstanceConnectionMemoryCPU
lab-018421connected
228 MB
3.1%
lab-029134connected
246 MB
2.8%
fuzz-a9772connected
396 MB
7.9%
fuzz-b9773connected
384 MB
8.2%
stage-01—idle
0 MB
0.0%

Instance manager

A hundred sessions, one grid.

Launch, label, group and tear down instances from a single table. Push a script to a group and watch each row report back independently — no terminal juggling, no guessing which window is which.

  • Broadcast to a group, or target a single row
  • Per-instance CPU, memory and reconnect policy
  • Credential vault, encrypted on disk
Instance API
“We kept seeing the same bypass scripts circulating, so we ran them through Cocktail against our own build. It showed us exactly which ones were slipping past our anti-cheat and doing real damage. That gave us what we needed to find and fix the vulnerabilities they were leaning on.”

Anonymous

Developer at an undisclosed studio

Identity withheld at the user’s request. Cocktail is a security research tool, and we do not endorse every use people find for it.

Benchmarks

Heavy scripts. Zero slowdown.

A purpose-built engine runs the heaviest scripts at full frame rate. Everything stays as smooth as the untouched client, so sessions feel seamless where other tools crawl.

0.24ms
Median frame cost
4.1s
Cold attach
99.94%
Session success
128
Instances per host

FAQ

Questions we get asked

Running and analysing Luau against a game client you are authorised to test — reproducing crashes, building regression harnesses, checking that an anti-cheat rule actually fires, and reading compiled modules. It is a research and QA tool: there is no script marketplace and nothing exploit-shaped ships with it.

Set up a workspace in five minutes.

One product, no tiers. Buy a day to try it, and any time you buy later stacks straight on top.

Build 1.4.2 — patched 40 minutes after the last client update