On this page 10 sections
Every anti-cheat answers the same question: is this player running something they should not be? None of them answers it with a single check. They stack several layers, each catching what the others miss.
The layers at a glance
| Layer | What it looks at | What it catches |
|---|---|---|
| Signatures | Files and code on your PC | Known, widely shared cheats |
| Integrity | The game’s own code and memory | Changes made inside the game |
| System | Drivers, processes, windows, tools | Cheats running beside the game |
| Hardware and boot | Secure Boot, TPM, devices, IDs | Tampered systems, DMA cards, repeat offenders |
| Server and statistics | What happens in your matches | Impossible actions and abnormal performance |
| Players and replays | Reports and reviewed footage | Behaviour no scan can see |
Signatures: looking for known cheats
The oldest method is still one of the most effective. When an anti-cheat team gets hold of a cheat, it records distinctive pieces of it: file hashes, byte patterns in its code, the names of its windows or drivers. From then on, any PC carrying that pattern is flagged.
This is why public cheats die quickly. Thousands of people download the same file, and the anti-cheat only needs one copy to catch them all. Private builds that change their signature are far harder to catch this way. Elocarry builds are polymorphic, so their signature changes on every launch.
Integrity: checking the game itself
The anti-cheat knows what the game’s code and memory should look like. It checks for:
- code in the game’s process that the game did not load
- changes to the game’s functions, such as redirected calls
- unexpected threads and memory regions
- modified game files
These checks target internal cheats, which live inside the game’s process.
System checks: what else is running
Cheats that stay outside the game still have to touch it. Anti-cheats look for programs holding access to the game’s memory, drivers that should not be loaded, debuggers and memory tools, and windows drawn over the game that are not known overlays. Many anti-cheats refuse to start at all if well-known memory editing tools are running.
This layer is where kernel-level anti-cheat matters. Running as a driver gives the anti-cheat a view of the whole system rather than just the game.
Hardware and boot checks
Modern anti-cheats also check how the PC itself is set up:
- Boot security. Whether Secure Boot is on and the PC started normally. Battlefield 6 will not start without it.
- TPM. The TPM can prove how the PC booted. FACEIT and Javelin ask for TPM 2.0, and so does Vanguard on Windows 11.
- Devices. Hardware that could read game memory directly, the basis of DMA cheats, and memory protection settings that block it.
- Hardware identifiers. The serial numbers behind a HWID, which let a game recognise a PC that was banned before.
Server and statistical checks
Some cheating never shows on the PC at all, only in the match. The game server sees everything you do: movement speed, positions, shots and hits. It can flag actions that are impossible, such as moving faster than the game allows, and patterns that are merely improbable, such as reaction times or headshot rates far beyond human players.
Valve has run machine learning over Counter-Strike gameplay for years to spot aimbot patterns, and Counter-Strike 2’s VAC Live can cancel a match when it detects a cheater. This layer is the reason settings like smoothing and reaction delay exist: they keep in-game behaviour inside the human range.
Reports and replays
Finally, other players. Reports feed review systems, and in games with replays a human or an automated system can watch what you did. Tracking players through walls or snapping between heads is easy to see in footage even when no scan found anything. Marvel Rivals and Counter-Strike 2 both lean on this layer.
Why bans come later
A detection and a ban are separate events. Many anti-cheats record detections and act on them later, often in a ban wave where accounts flagged over days or weeks are banned at once. Valve designed VAC bans to be delayed for exactly this reason: an instant ban would tell the cheat’s developer what was caught.
What undetected really means
“Undetected” means no current detection is known. It is a statement about today, not a promise. Anti-cheats update constantly, and the only way a build stays undetected is by changing as quickly as they do and pausing the moment anything looks wrong.
That is how we run our builds. Every one is polymorphic, every one is rebuilt when its game or anti-cheat patches, and every status change is posted live. Check the status page before you load in, and if a build is flagged, wait for the green light. No method is ever guaranteed, and anyone who says otherwise is not being straight with you.
Frequently asked questions
Can anti-cheat see everything on my PC?
A kernel-level anti-cheat can see a great deal: running programs, loaded drivers and the memory of the game it protects. What it collects and sends back is decided by the vendor and described in the game's privacy policy, but the level of access is real.
Why do bans arrive weeks after a cheat was used?
On purpose. If every detection triggered an instant ban, cheat developers could tell exactly what was caught. Delaying bans and issuing them together in a ban wave hides that, and catches more users of the same cheat before it changes.
Does being detected mean I am banned?
Not necessarily. A detection means the anti-cheat has noticed something; the ban may come later or not at all. For Elocarry builds, a detection usually means we pause the build, and your account is fine as long as you stop using it.
Can a cheat be undetected forever?
No. Undetected means no known detection right now. Anti-cheats update constantly, so a build stays undetected only by changing just as quickly, and nobody can promise any method will never be caught.
First published 6 October 2026. Last updated 6 October 2026. We update Wiki pages when the game, the anti-cheat or the build changes, not on a schedule.
Related articles
What Is Kernel-Level Anti-Cheat? How It Works and Why
Kernel-level anti-cheat runs as a Windows driver with deep system access. What kernel level means, which games use it, what it can see and the trade-offs.
Updated 6 October 2026 Anti-cheatWhat Is a Ban Wave? Why Games Ban Cheaters in Batches
A ban wave is when a game bans many flagged accounts at once instead of one at a time. Why developers delay bans, what a wave means for you and what to do.
Updated 6 October 2026 Anti-cheatWhat Is BattlEye? How the BattlEye Anti-Cheat Works
BattlEye is the kernel-level anti-cheat behind Escape From Tarkov, DayZ and PUBG. Where it came from, how it works, its common errors and how its bans work.
Updated 6 October 2026 Anti-cheatWhat Is Easy Anti-Cheat (EAC)? How It Works
Easy Anti-Cheat is Epic's kernel-level anti-cheat used by Rust, Apex Legends, Fortnite and more. How EAC works, what its errors mean and how its bans work.
Updated 6 October 2026 Anti-cheatWhat Is VAC? Valve Anti-Cheat and VAC Bans Explained
VAC is Valve Anti-Cheat, used by Counter-Strike 2 and Deadlock. How VAC works, what VAC Live does, why VAC bans are delayed and what a VAC ban means.
Updated 6 October 2026More on Elocarry
Still stuck?
Ask Barry first: he answers in Discord around the clock and fixes most things on the spot. For billing or account questions, open a ticket and a person follows up.