+ --hlds-e7-scan Probe HLDS HIT 0xE7 cache/memdump bases only;
+ writes JSON and does not crack seeds or dump data
+ --hlds-e7-subcmd-sweep Probe HIT 0xE7 subcommands/address candidates only;
+ writes JSON and does not crack seeds or dump data
+ --hlds-e7-memrange-sweep Sweep wider HIT 0xE7 subcmd 0x01 address ranges;
+ writes JSON and does not crack seeds or dump data
+ --scan-log <file> JSON output path for --hlds-e7-scan
+ --scan-dump-prefix <prefix> Optional raw 0xE7 window dump prefix for --hlds-e7-scan
+ --hlds-profile-report <file> Write selected HLDS profile/evidence JSON
+ --redump-dat-dir <dir> Directory containing canonical Redump DAT files
+ (default: executable-relative redump_dat, then current directory)
+ --redump-report <file> Write atomic Redump evidence JSON
+ --no-redump-verify Disable automatic post-dump DAT verification
+ --xgd1-layout-probe <file> Read-only locked/unlocked XGD1 boundary probe;
+ writes atomic JSON and does not create an ISO
+ --xgd1-raw-id-probe <file> Modified-firmware cache-flushed, block-aligned raw-ID probe;
+ maps logical LBAs to decoded physical sector IDs