ob_by_hud.py now scans seven readings of the same bytes and keeps a separate candidate set for each, as byte offsets: u32 big and little endian, u16 both endiannesses at both alignments, and u8. The big-endian u32 reading had been refuted, so widening rather than assuming is the point. u32le is much the tightest at 154 candidates against u32be's 4452. That is a hint about the encoding rather than a result, since a rarer bit pattern narrows faster regardless of meaning. The run is inconclusive. The HUD read 4 at every sample, so there was no second value to collapse the sets against, and from t=136 the candidate counts are byte-identical across five samples in all seven encodings, which is what a frozen guest looks like -- nothing in 32 MB changed at all. The probe had no stall witness, so the run cannot prove it either way. One is added now. Worth stating plainly: this is the fourth probe written without a witness and the third whose flat output could not be distinguished from a freeze. Each time the fix gets applied to that one script. The durable fix is the shared probe harness already noted in this file, and the lesson recurring four times is itself the argument for building it. What the hunt needs is unchanged: two HUD readings at different values in non-stalled samples. The counter moves on kills, which lands back on the combat limit, though the earlier 4 to 11 observation shows it does move.