QBCore Anticheat Setup: Protect Your FiveM Server

Step-by-step Tosun Anticheat setup for QBCore servers — money/inventory protection, RedEngine detection and web panel. Go live in 10–15 minutes.

Short answer: Select the QBCore profile in the panel, ensure the resource — detections appear instantly.

Try the live demo

Common QBCore exploits: money printing via banking/inventory, weapon spawn, godmode and executor menus. Tosun Anticheat validates QBCore events on client and server.

QBCore-specific protections

Setup steps

  1. Create an account at tosundev.com and get your license key.
  2. Upload Tosun Anticheat resource to your server.
  3. Add ensure line to server.cfg (after framework).
  4. Select the correct framework profile in the web panel.
  5. Test for false positives, then go live.

Recommended server.cfg (QBCore)

ensure oxmysql
ensure qb-core
ensure [tosun-ac]
# Load Tosun AC AFTER qb-core

Why Tosun Anticheat for QBCore?

The Four Most Common QBCore Exploits

The QBCore ecosystem is large, and so is its attack surface. These four patterns dominate in practice:

  1. Bank/cash event abuse — calling the money-granting event of qb-banking or an inventory script from the client with forged parameters.
  2. Item duplication — duplicating items by triggering the inventory move event concurrently.
  3. Job/gang permission bypass — an unauthorised player calling police/gang events to obtain vehicles, weapons or money.
  4. Executor menus — RedEngine/Eulen combining godmode, aimbot and weapon spawn at once.

How Tosun Validates the QBCore Event Chain

When the QBCore profile is selected in the panel, Tosun listens to the framework money and inventory events server-side. Every call gets a source check, a context check (is the player actually in a position to perform this action) and a rate limit. The authority is the player state on the server, not the amount sent by the client — which is why the economy stays protected even if the client anticheat is disabled.

The First 24 Hours After Install

  1. Start detections in log-only mode — observe your normal server behaviour before banning.
  2. Whitelist legitimate scripts that trigger falsely (garages, jobs, shops).
  3. Tune thresholds to your economy pace; limits differ on high-payout servers.
  4. Define staff bypass and exemption zones.
  5. Then enable automatic action (strike + ban).

A Note on QBCore + ox_inventory

If you run QBCore with ox_inventory, inventory events arrive under different names. Tosun recognises both inventory stacks; you only need to select the inventory type in the panel. A wrong choice makes detections stay silent — after setup, move a test item and confirm it appears in the log.

Create free accountDocumentation See pricing

Frequently Asked Questions

QBCore Legacy vs Qbox?

All QBCore-based stacks are supported — select QBCore profile in panel.

Using ox_inventory?

Yes — QBCore + ox_inventory is supported.

Running ESX instead?

See our ESX Anticheat Setup guide.

Related: ESX · Standalone · vRP · OX/Qbox · All Framework Guides · RedEngine Detection