EAC, BattlEye and Vanguard Explained: How Anti-Cheat Systems Actually Work

How EAC, BattlEye and Riot Vanguard actually catch cheats: kernel drivers, memory scans and hardware bans explained.

EAC, BattlEye and Vanguard Explained: How Anti-Cheat Systems Actually Work

If you've ever bought a cheat and lost it within a week, the anti-cheat behind the game is almost always the reason. Easy Anti-Cheat, BattlEye and Riot Vanguard are the three systems you'll run into most, and while sellers talk about them constantly, most explanations stop at "it's kernel-level." That phrase alone doesn't tell you much. Here's what these systems actually do, how they differ from each other, and why that matters for how a cheat is built.

Why Anti-Cheat Moved Into the Kernel

Windows organizes what software is allowed to do into privilege levels, or rings. Ordinary applications, including the game itself and, for a long time, most cheats, run in Ring 3, the least privileged tier. Ring 0, the kernel, sits underneath the entire operating system and can see and touch everything: every process, every driver, every region of memory.

Cheat developers moved into the kernel first. Once user-mode anti-cheat got reliable at spotting Ring 3 cheats, some developers started writing their own kernel-mode drivers, which sit at the same privilege level as the operating system itself and are invisible to anything confined to Ring 3. Publishers followed the same path: if only kernel-level code can reliably see kernel-level software, the anti-cheat has to operate there too. That's the whole reason EAC, BattlEye and Vanguard all ship kernel drivers today.

Easy Anti-Cheat, BattlEye and Vanguard Side by Side

Easy Anti-Cheat (EAC)

Protects Fortnite, Apex Legends, Rust and Squad, among others. It loads together with the game, and the developer chooses whether it runs in kernel or user mode. It's been free for developers to license since Epic's acquisition of the company, which is a big part of why it protects more titles overall than any other system on this list.

BattlEye

Protects PUBG, DayZ, Escape from Tarkov, Rainbow Six Siege and Arma. It loads together with the game. It's one of the oldest anti-cheat systems still in active use, and it runs both user-mode and kernel-mode components.

Riot Vanguard

Protects Valorant and League of Legends. Unlike the other two, it loads at system boot, before Windows finishes loading most of its own services, and it can't be stopped without also closing the game it protects. That makes its load timing the most aggressive of the three.

The load-timing difference is the one that matters most in practice. EAC and BattlEye start their kernel driver when you launch the game and unload it when you quit, which gives a driver that loads earlier a window to hide before either one is watching. Vanguard's driver loads at boot and stays resident even when Valorant isn't running, specifically to close that window, which is also the reason it draws the most privacy criticism of the three.

What These Systems Actually Scan For

  • Signature scanning: checking running processes and loaded modules against a database of known cheat software, updated on a regular cadence.

  • Behavioral analysis: flagging patterns that don't look human, such as aim that snaps with inhuman consistency, reaction times below what's physically plausible, or movement that ignores normal input timing.

  • Driver and module verification: checking every driver loaded on the system against trusted signatures, which is exactly why kernel-mode cheats need valid or spoofed code-signing to avoid standing out immediately.

  • Hardware fingerprinting: collecting identifiers like CPU, GPU and disk serials so a banned device can be recognized even if the player creates a new account.

Detection Outcomes: Instant Bans, Ban Waves and Hardware Bans

Not every catch results in an immediate kick. A cheat flagged the moment it loads usually triggers an instant ban. But publishers frequently hold detections back and apply them in a batch, known as a ban wave, days or weeks later, partly to avoid tipping off a cheat developer about exactly which signature got caught, and partly to sweep up related accounts at once. That delay is also why a cheat that "worked fine for two weeks" can suddenly stop working with no warning: the flag was already recorded, the ban just hadn't landed yet.

Some bans go further than the account and target the hardware itself through an HWID (hardware ID) ban, which we cover in more detail in a separate guide on checking and dealing with HWID bans.

FAQ

Is Vanguard running even when I'm not playing Valorant?

Yes. Its driver loads at system boot and stays resident, which is the specific design choice meant to close the gap where a cheat could load before the anti-cheat is watching.

Can BattlEye or EAC be turned off?

Not while playing a game they protect. The driver is required for the game to launch. Some titles let a developer choose user-mode instead of kernel-mode EAC, but that's a decision made by the publisher, not something a player can toggle.

Why does a ban sometimes land weeks after the flag?

Publishers often batch detections into a ban wave rather than acting instantly, which makes it harder for cheat developers to isolate exactly which behavior or signature got caught.

Which of the three is hardest to deal with?

Vanguard's boot-level load timing is generally considered the most aggressive of the three, though BattlEye and EAC have both added kernel components and closed most of the gap over the past few years.

None of this is meant to be a checklist for evading detection. That's a moving target that changes every update, and any specific claim about it goes stale fast. What's worth taking away is the general shape: these systems watch at the same privilege level the operating system itself runs at, and the software you choose to run alongside a game needs to be built with that in mind.