Kernel-Level Anti-Cheat Explained: What Games Like Valorant Actually Install on Your PC

Install a competitive shooter like Valorant, Fortnite, or Call of Duty and something unusual happens during setup: a separate piece of software gets installed alongside the game itself, one that starts running before Windows even finishes booting and keeps running in the background even when the game isn't open. That's kernel-level anti-cheat, and it's become the default approach for stopping cheaters in competitive online games, despite being one of the more controversial pieces of software a player willingly installs on their own PC. Understanding what it actually does, and why developers reach for something this invasive, explains both its effectiveness and the real concerns it raises.
What "kernel-level" actually means
An operating system like Windows runs software in two broad privilege tiers: user mode, where ordinary applications including most games run, and kernel mode, the deepest layer of the operating system with essentially unrestricted access to hardware, memory, and every other process running on the machine. Software running in user mode is sandboxed by the operating system and can only interact with other software through controlled, limited channels. Software running in kernel mode has none of those restrictions, it can inspect and modify the memory of any other running process, intercept hardware-level input, and operate with a level of system access normally reserved for the operating system's own core components and trusted hardware drivers. A kernel-level anti-cheat driver installs itself into this deepest layer specifically so it can see everything happening on the machine, including techniques cheat software uses to hide itself from a program running at the ordinary user-mode level.
Why developers need this level of access to catch cheaters
Cheat software has gotten sophisticated enough that user-mode anti-cheat, the older, less invasive approach, increasingly struggles to catch it. Modern cheats can hook directly into a game's memory to reveal enemy positions through walls, aim precisely without normal human imprecision, or manipulate what data the game receives, and many are specifically engineered to hide their own presence from software that's confined to the same user-mode privilege level they're running at, essentially two programs at the same permission tier trying to detect and evade each other. A kernel-level anti-cheat driver, operating from the deeper privilege tier, can see processes, memory access patterns, and driver-level manipulation that a same-tier detector simply cannot observe. It can also monitor for known cheat driver signatures being loaded into the kernel itself, catch attempts to tamper with the game's memory from an external process, and detect virtualization or debugging tools being used to reverse-engineer the game's anti-cheat logic, all before a match even starts. This is roughly analogous to why some malware detection tools also require deep system access, catching sophisticated threats increasingly requires operating at the same privilege level the threat itself operates at.
The legitimate concerns players raise
The tradeoff is real and worth taking seriously rather than dismissing. Software running with kernel-level privileges has, by definition, the technical capability to do far more than just watch for cheat signatures, it could theoretically read any file, monitor any other running process, or introduce serious system instability if it contains a bug, since kernel-mode code that crashes can crash the entire operating system rather than just the one misbehaving application, the notorious blue screen of death. This is why players and security researchers scrutinize these drivers closely: a poorly written or genuinely malicious kernel driver represents one of the most powerful forms of access malware could ever hope to achieve, and installing one means trusting the game developer's engineering and their security practices at a level well beyond what a typical application requires. Legitimate anti-cheat vendors address this by having their drivers digitally signed and certified through Windows' driver certification process, publishing details about exactly what data the software collects and when it runs, and in some cases allowing the driver to be manually removed after uninstalling the game, though not all anti-cheat systems handle removal equally cleanly, and some continue running at every system boot even when the associated game isn't installed anymore unless manually uninstalled.
Why it typically has to run before you even launch the game
Many kernel-level anti-cheat systems load automatically at system boot, before the game itself starts, rather than only when you launch the game. This design choice exists because cheat software can be engineered to load early too, sometimes before other security software has fully initialized, specifically to gain a head start hiding itself. An anti-cheat driver that only activates once the game launches would miss cheat tools already resident in memory from before that point. Loading at boot lets the anti-cheat establish a clean baseline of what's running on the system before a match ever starts, though this is precisely the design choice players find most invasive, since it means the software is technically active and monitoring system state even during long stretches when you're not actively playing the game it was installed for.
Does it actually work?
The honest answer is: meaningfully better than the alternative, but not perfectly. Games that adopted kernel-level anti-cheat have generally reported measurable drops in cheating rates compared to their previous user-mode-only systems, and competitive titles in particular have leaned into it specifically because the integrity of ranked and esports-adjacent play depends heavily on keeping cheating rare. It isn't a permanent solution, cheat developers continually adapt, sometimes exploiting vulnerabilities in the very drivers meant to stop them, which has occasionally forced anti-cheat vendors to patch their own kernel drivers reactively. It's an ongoing arms race rather than a solved problem, similar in spirit to how AI text detection tools face a continuously adapting target rather than a fixed one, where each generation of detection prompts a corresponding generation of evasion.
What this means for players deciding whether to install a game
For most players, kernel-level anti-cheat is simply a condition of playing a specific competitive game, uninstalled along with the game itself and largely invisible during normal play. For anyone with specific privacy or security concerns, checking which anti-cheat system a game uses, and how cleanly it uninstalls, before installing is a reasonable step, particularly since some systems are more transparent and better audited by independent security researchers than others. It's part of a broader pattern of software increasingly asking for deep system trust in exchange for stronger protection, a tradeoff worth weighing consciously rather than clicking through the installer without a second thought, especially compared to less invasive multiplayer protections used in cross-platform games that also have to keep matches fair across PC, console, and cloud players without necessarily requiring the same depth of system access on every platform.

