The GlitchMod knowledge base

Trainer Format

Trainers on the original Xbox are patch files with a .ETM extension. They alter memory or game logic at runtime, enabling features like infinite health, ammo, or debug displays. These are typically activated through in-game button combos o…

4 min readUpdated Oct 9, 2026

Trainers on the original Xbox are patch files with a .ETM extension. They alter memory or game logic at runtime, enabling features like infinite health, ammo, or debug displays. These are typically activated through in-game button combos or toggled in launchers such as XBMC.

Overview

An .ETM file is a binary structure written in C and encoded in little-endian format. It includes a compact header followed by pointers to various functional sections, such as toggle states, text labels, and actual patch instructions. The primary role of the trainer is to inject code or alter memory values at runtime in a way that the game accepts.

Trainers do not modify the game executable (.XBE) directly—instead, they hook or patch memory at specific offsets while the game is running. They are often created through disassembly and trial/error, and many follow similar internal structures.

.ETM File Structure

The trainer format begins with a small header that describes the internal layout. Below is a breakdown:

Header Section

Offset Size Name Description Notes
0x0000 0x0004 FileSize of Patch Total size of the .ETM file
0x0004 0x0002 Version Trainer format version Typically 0x0001
0x0006 0x0004 HeaderSize Marks where the header ends and body begins Typically 0x0023
0x000A 0x0004 Offset Pointer - OptionListToggle Offset location of trainer options to toggle on/off Bitflags for each trainer option
0x000E 0x0004 Offset Pointer - OptionTextPointers Offset location of the "OptionTextPointers" This section contains offset locations for "Patch Title", "Description" and "Option Name(s)"
0x0012 0x0004 Offset Pointer - TitleID(s) Offset location of a list of supported Title IDs Allows multiple Title IDs
0x0016 0x0004 Offset Pointer - EntryPoint Offset location that contains the patch instructions Usually assembled opcodes that replace bytes
0x001A 0x0004 Reserved Unused
0x001E 0x0004 Reserved Unused
0x0022 0x0001 MasterEnable Global enable switch (True/False) Typically 0x00 unless pre-enabled

Option List Toggle

Located via the pointer at offset 0x000A, the OptionListToggle section defines which trainer features are enabled at runtime. Each option typically occupies a byte or bitfield indicating its toggle state. The Default state is "00", and trainer managers manipulate this at run-time in their UI.

Option Text Pointers

Located via the pointer at offset 0x000E, this section maps to human-readable strings used in a trainer manager's UI to describe each cheat option. The pointers here are used to render trainer option names dynamically.

Title ID(s)

Located via the pointer at offset 0x0012, this section lists the unique Xbox game identifiers (Title IDs) the trainer supports. One .ETM can be used across multiple regional versions or game editions if the memory layout is compatible.

Entry Point (Patches)

Located via the pointer at offset 0x0016, this section is where the core functionality lives. It usually consists of compiled Xbox assembly instructions and/or memory writes. These are executed by the trainer engine at runtime. The structure is flexible enough to support various modifications like:

  • Overwriting memory to NOP instructions (e.g., disabling health subtraction)
  • Injecting jump instructions to new behavior
  • Writing fixed values like ammo counts or flags

Activating Trainers

Trainers are usually toggled through:

  • Toggled to enabled and launched via apps like XBMC, EvolutionX or Xored Trainer Launcher that support .ETM loading
  • Pressing button combination macros (hardcoded in the trainer) during gameplay

Creating Your Own Trainers

Crafting .ETM files usually involves:

  • Reverse engineering games using tools like Ghidra or IDA Pro
  • Finding code caves or unused memory regions
  • Identifying the game logic you want to manipulate
  • Assembling code or generating memory write instructions
  • Populating an .ETM header and sections accordingly

For more advanced patching workflows, you may want to study .XBE disassembly in detail and correlate memory addresses with .ETM injection logic.

Summary

.ETM trainer files act as structured memory patches for original Xbox games, enabling real-time game modifications without modifying the core executable. They use clearly defined offsets and internal sections for toggles, UI text, game compatibility, and patch injection.

Understanding the structure and layout is crucial for building stable, effective trainers that enhance games without crashing them.