← All posts

● cswatch / dispatches

Kernel Anti-Cheat Explained: Is It Safe to Install?

FACEIT, ESEA, and Vanguard run at the kernel level — the source of both their power and the 'rootkit' fear. An honest look at the real trade-offs and how to decide per-vendor and per-machine.

CSWatch Media6 min readguideanti-cheatsecurity

Sponsored by CSGORoll
Sponsored by CSGORollRemove Ads

FACEIT, ESEA, and Riot's Vanguard all use kernel-level anti-cheat — and every time one is mentioned, someone calls it a "rootkit." Are kernel anti-cheats actually safe to install? Here's an honest, non-hysterical look at the trade-offs.

What "kernel-level" means

Normal programs run in user mode, sandboxed with limited privileges. A kernel anti-cheat installs a driver that runs in ring 0 — the most privileged level, alongside the operating system itself. That deep access is exactly why it catches cheats user-mode VAC can't, as we cover in FACEIT Anti-Cheat vs VAC. Same access, though, is why people are wary.

The legitimate concerns

  • Total system access. A ring-0 driver can, in principle, see anything on your machine. You're trusting the vendor not to misuse it and not to be careless.
  • Attack surface. A buggy kernel driver is a serious vulnerability — if it's exploitable, it's exploitable at the highest privilege level. This is the most substantive risk, and it's happened to anti-cheats before.
  • Always-on designs. Some (notably Vanguard) run at boot, not just while the game is open. Others (FACEIT, ESEA) typically load with the client and unload after.
  • Stability. Kernel drivers can conflict with other low-level software and cause crashes.

The realistic perspective

"Rootkit" is technically loose but emotionally overblown. Reputable kernel anti-cheats from established companies are not secretly harvesting your data — their business depends on not being caught doing that, and they're heavily scrutinised. You already run other kernel drivers (GPU, peripherals, some game launchers) and trust them. The real question isn't "rootkit yes/no," it's do you trust this specific vendor with ring-0 access on this machine.

Practical guidance

  • From a major, established platform? The risk is low and the cheater-reduction is real. Most competitive players accept the trade.
  • Privacy-sensitive or shared/work machine? Reasonable to keep kernel AC (especially always-on ones) off that device and play it on a dedicated gaming rig.
  • Keep it updated and only install the official client — fake "anti-cheat" downloads are a malware vector.

The bottom line

Kernel anti-cheat is a genuine privacy/security trade for genuinely cleaner games. It's not malware, but it's not nothing either — decide per-vendor and per-machine. And remember it only protects you on that platform; in Valve matchmaking you're back to VAC's limits, where checking a suspicious player's history and reports is still your best tool.

Spotted a cheater you want investigated?

Use the free CS2 cheater checker to check any player's VAC bans, reputation, and community cheat reports — or submit a report with a demo for community Overwatch review.

Check a player for cheating