Skip to content

Explosive Devices - Defuse Guide

This guide covers the response: finding a live device with the scanner, marking the scene, and working a defuse as a team. For planting bombs, see the Player Guide.

The responder scanner (WEAPON_KFDEFUSESCANNER) is restricted to whichever groups your server lists in Config.responderTools.groups. Leave the list empty to allow everyone.

Hold the scanner and it sweeps for bomb signals within its configured detection range. The beeping gets faster as you close in, and it confirms the signal at its configured confirmation threshold with Bomb signal confirmed.

The scanner picks up hazard zones from bombs that have already gone off too, so it doubles as a way to find the edge of a radiation zone before you walk into it. Which hazards show up is a per-preset setting, and radiation is the one visible by default.

While a bomb is live, responders can target it and choose Place Marker from within the configured marker range. Clear Marker takes it back off.

Markers are synced blips that only responders can see, in the responder colour.

Servers run Explosive Devices in one of two modes, set by defuseMode in config_defuse.lua.

Solo is the default. One player can work the whole bomb on their own, switching between the device and their own tablet with [Tab]. They still need a defuse tablet in their inventory, and they’re doing two jobs against the same clock, so it’s harder than it sounds. Other authorised players can also open the private tablet if they have a tablet item and stay in range.

Co-op requires another player with a tablet. The operator can’t open the rulebook at all, so someone else has to read the lookups to them. There is no join or ready step: the tablet viewer opens the rulebook while the operator works the device. If more than one active case is available, the viewer chooses the case from the tablet first; its device number helps identify it.

Solo mode keeps the resource usable on a quiet server. Co-op mode is the tighter scene if you’ve got the players for it.

A defuse has one operator and any number of transient tablet viewers; viewers do not join the defuse session or take a participant slot.

RoleHow you access itWhat you get
OperatorStarts the session with Defuse Device on the armed case.The case camera and the physical device. Does everything to the bomb.
Tablet viewerOpens the tablet while authorised, carrying kf_defuse_tablet, and within range of a case. If several cases are available, chooses one from the tablet.The private rulebook with the clues and lookup tables.

Only the operator can touch the device. In co-op mode the operator cannot open the rulebook, so a tablet viewer must relay it.

The operator and tablet viewers must be allowed by Config.responderTools.groups. Tablet viewers must also stay within tablet range of the case; leaving range closes their tablet without cancelling the operator’s defuse.

The operator gets a close-up view of the case:

Hover a component and click to interact [Backspace/Esc] Exit View

The wires, keypad, and switch are clickable parts of the model. The main device screen carries the clues and meter state, while the clue colour has its own case panel. Zoom Screen and Step Back move you in and out for a closer look.

Every case generates a fresh puzzle when it’s armed, so there’s nothing to memorise. What worked on the last bomb won’t apply to this one.

  1. The screen shows the payload type, a protocol code, a serial number, a symbol sequence, and a module ID. The clue colour is on its own case panel. Read all of it to your tablet viewer.

  2. The protocol, serial, and symbol lookups each point at a wire. Cut them in whatever order your tablet viewer works out.

    A wrong wire isn’t fatal, but the wire is spent and the configured time penalty applies.

  3. Short symbol sequences don’t need a code. Longer ones need a four digit code, which your tablet viewer finds by locating the exact sequence in the right colour folder. The same sequence turns up as a decoy in the other folders, so the folder matters.

    Enter it on the keypad. A wrong code normally applies the configured time penalty, but some bombs are generated with a rule that makes a wrong code detonate immediately. Your tablet viewer will know which kind you’re dealing with.

  4. Read the module’s current meter value and trend from the device screen. The module ID tells your tablet viewer which reading matters, and whether the switch needs flipping before the final cut, inside a timed window, or not at all.

  5. Once the non-final wires and any required code are done, Final Decrypt runs automatically and reveals the final wire on the tablet. There is no extra button to press on the device or tablet. The final wire is never the one the protocol pointed at.

  6. That’s the device defused and the session over.

Some servers enable an optional Summary tab in the rulebook. It unlocks once the protocol, serial, and symbol clues each identify a complete cut order, then shows the verified wire order and any numpad instruction.

Some bombs roll an extra condition on top of the normal sequence, and the tablet viewer’s rulebook lists whichever ones apply. You might get a countdown digit on the device that has to be visible when the final wire is cut, a limited window to make the final cut after entering the code, a limited window after flipping the switch, or a bomb where entering a code at all is the wrong move.

For the countdown-digit rule, the padded zero at the front of a timer such as 01:47 does not count. Any other matching digit in the countdown value does.

Read the extra rules before you touch anything. They’re the most common reason an otherwise correct sequence still detonates.

  • The countdown uses the configured duration, and it starts when the device is armed rather than when you start defusing.
  • Wrong wires and wrong codes use the configured time penalty unless a rule detonates the device immediately.
  • Timed final windows use their configured durations.
  • At zero the bomb goes off. Some servers set the timer to re-arm the device and start again instead.
  • Closing the operator view leaves the active session and any cut wires in place. Return to the device to continue the attempt.
  • Defuse: Cancel Attempt ends the session. The case re-arms and all your cut wires are wiped, so the next attempt starts from scratch on the same puzzle.
  • Closing a tablet only closes that viewer’s private view. The operator continues, and reopening the tablet during the same active session preserves its notes.
  • If the operator disconnects, the session is cancelled and any tablet viewers are closed.
  • Moving a tablet viewer out of range or losing defuse access closes that tablet. The operator’s own interaction still uses the case range and access checks.

If the bomb goes off, the scene isn’t over. The payload leaves a hazard zone behind, which depending on the payload is a fire, a biohazard cloud, a radiation zone, or an EMP blackout, and it keeps affecting anyone inside it for as long as it lasts.

The default pathogen biohazard can assign one of the configured progressive infections after exposure. Infectious strains may spread between players after they leave the cloud, so isolate exposed casualties instead of gathering everyone in one treatment area. A hospital outcome configured by the server can stabilise an infection temporarily, but it does not cure or clear it. Servers can use CS or KOG-23 as non-persistent alternatives with irritation or knockout effects.

Use the scanner to find the edge of a hazard zone before you go anywhere near it. Radiation and biohazard zones can be entered safely by players in protective gear when the server is set up to recognise it. Infection protection has to be verified by the server; a cosmetic outfit alone is not enough.

See Biohazard & Infection for the strain symptoms and configured gas effects.