Anti-cheat

What Is Kernel-Level Anti-Cheat? How It Works and Why

Kernel-level anti-cheat runs as a Windows driver with deep system access. What kernel level means, which games use it, what it can see and the trade-offs.

By the Elocarry team Support and product Last updated 4 min read
Quick answer
Kernel-level anti-cheat is anti-cheat that runs as a driver inside the core of Windows, the kernel, with the same access as your graphics or storage drivers. From there it can see every program and driver on the PC and protect the game's memory from them. Easy Anti-Cheat, BattlEye, Riot Vanguard, FACEIT and EA's Javelin all work this way. Valve's VAC does not.
On this page 7 sections

“Kernel-level” has become the most argued-about phrase in PC gaming. Every major competitive release now seems to ship with one, and every launch brings the same questions about privacy, crashes and whether it even works.

What “kernel level” means

Windows runs code at two main privilege levels.

User mode is where ordinary programs live: your browser, Discord, the game itself. Each program is kept in its own space and has to ask Windows for anything outside it.

Kernel mode is the core of the operating system. Drivers for your graphics card, storage, network and keyboard run here, with access to all memory and all hardware. Security people call it ring 0, from the way older processors numbered their privilege levels.

A kernel-level anti-cheat is one that installs its own driver and runs part of itself in kernel mode.

Why anti-cheats moved into the kernel

Cheats moved there first. A cheat running in user mode can be watched by an anti-cheat in user mode. A cheat with its own kernel driver could hide from it, read the game’s memory without asking Windows and block the anti-cheat’s view. The only place to watch something running in the kernel is from the kernel.

Running at the same level lets the anti-cheat:

  • see every process and every loaded driver on the system
  • stop other programs opening the game’s memory
  • check the game’s code and memory from a position cheats cannot easily fake
  • inspect how the PC booted and which security features are on

Which anti-cheats run at kernel level

Anti-cheatKernel levelGames that run it
Easy Anti-CheatYesRust, Apex Legends, ARC Raiders, Dead by Daylight, Fortnite
BattlEyeYesEscape From Tarkov, DayZ, PUBG
Riot VanguardYesValorant, League of Legends
FACEIT Anti-CheatYesCounter-Strike 2 on FACEIT servers
EA JavelinYesBattlefield 6, EA FC
VACNo, user modeCounter-Strike 2, Deadlock

What it means for your PC

Boot and security settings

Kernel anti-cheats increasingly care about how the PC booted. Requirements such as Secure Boot and TPM 2.0 exist so the anti-cheat can trust that nothing loaded before it. Battlefield 6 will not start without Secure Boot, and FACEIT made TPM 2.0 and Secure Boot mandatory for all players in late 2025.

Drivers it will not run beside

Kernel anti-cheats commonly refuse to run alongside drivers with known security holes, because cheats have abused exactly those drivers to get into the kernel. Old fan control, RGB and overclocking utilities are sometimes caught by this.

Two kernel anti-cheats at once

Some kernel anti-cheats, especially ones that load at boot, can clash with other software that also wants deep system access. That is why Elocarry’s troubleshooting guides ask you to uninstall boot-time anti-cheats such as Vanguard, FACEIT and ESEA before loading a build.

The trade-offs

Stability. A crash in a kernel driver crashes Windows. The CrowdStrike outage of July 2024, when a faulty security update took down millions of Windows machines, was not an anti-cheat, but it showed what a bad kernel-level update can do.

Security. A driver with full access is a target. A flaw in an anti-cheat driver can, in principle, be used by malware.

Privacy. Kernel access means the anti-cheat could see far more than the game. Vendors say they only look for what matters to cheating, and that is a matter of trust.

Compatibility. Kernel anti-cheats are why some games refuse to run in virtual machines, with debugging tools open or on Windows with driver signing switched off. Each of those is something a cheat could hide behind.

Effectiveness. Kernel access raises the bar, but it does not end cheating. Battlefield 6’s open beta drew plenty of cheaters despite Javelin’s kernel driver and Secure Boot requirement. Server statistics, reports and replays still do much of the work, as covered in how anti-cheat detects cheats.

What it means for cheats

Against a kernel anti-cheat, a cheat has to hide from something with the same level of access, and the details of that are where builds succeed or fail. It is also why no honest cheat provider guarantees anything. Our builds are written for the anti-cheat each game runs, rebuilt when it updates and paused the moment anything looks off, and live status is always public.

Frequently asked questions

Is kernel-level anti-cheat safe?

It is as safe as the company that writes it. A kernel driver has deep access, so a bug can crash Windows or, in the worst case, be abused. Mainstream anti-cheats are signed, widely used and patched quickly, but the trust you place in them is real, which is why the topic is debated.

Does kernel anti-cheat run all the time?

Many load when the game starts and unload when it closes, Easy Anti-Cheat and BattlEye among them. Others start with Windows, which is why they are called boot-time anti-cheats. Riot Vanguard is the best-known, though Riot began offering an on-demand mode in 2026 for PCs that meet stricter security requirements.

Can kernel anti-cheat see my files?

It has the access to look at a great deal of the system, including running programs, loaded drivers and memory. What it actually collects and sends is set by the vendor and covered by the game's privacy policy.

Does VAC run at kernel level?

No. Valve Anti-Cheat runs in user mode, the normal level ordinary programs use. Valve leans on delayed bans, server-side analysis and player review instead of a kernel driver.

Topics Kernel levelDetectionSecure BootWindows

First published 6 October 2026. Last updated 6 October 2026. We update Wiki pages when the game, the anti-cheat or the build changes, not on a schedule.

Still stuck?

Ask Barry first: he answers in Discord around the clock and fixes most things on the spot. For billing or account questions, open a ticket and a person follows up.