Question

Why does anti-cheat software run at kernel level?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Because cheats operate at that level too, and software can only reliably detect and block things running at the same privilege level or lower.

The privilege model. Operating systems separate user mode, where applications including games run with restricted access, from kernel mode (ring 0), where the operating system core and drivers run with essentially unrestricted access to memory and hardware.

Why this matters. A user-mode anti-cheat can inspect other user-mode processes, and that caught a generation of cheats. Cheat developers responded by moving into kernel drivers, from where they can read and modify game memory, hide themselves from user-mode inspection, and intercept system calls. A user-mode anti-cheat cannot see a kernel-mode cheat — it is structurally outmatched.

Kernel-level anti-cheat — Riot's Vanguard, Easy Anti-Cheat, BattlEye in some modes — installs a driver running at the same privilege level, allowing it to monitor memory access, detect unsigned or suspicious drivers, and identify manipulation that user-mode tools miss.

The objections are legitimate and worth stating:

It has total system access. A kernel driver can read anything on your machine. You are extending very high trust to a game publisher.

Attack surface. A vulnerability in an anti-cheat driver is a vulnerability with kernel privileges, and anti-cheat drivers have been exploited by attackers — including being used as a vector to disable security software.

Always-on operation. Some load at boot and run whether or not the game is open.

Stability. A faulty kernel driver can crash the whole system.

Privacy, given the breadth of what it could observe.

Why publishers persist. Cheating destroys competitive games and drives players away, and the commercial damage is real. Hardware-level cheats — a second computer processing a video feed — defeat even kernel anti-cheat, which is the limit of the approach.

Server-side detection and behavioural analysis are the complementary route.

Related Questions