IN ACTIVE DEVELOPMENT

Four layers.
Fewer blind spots.

Cerberus is a next-generation anti-cheat engine that combines kernel-level protection, behavioral AI, hardware fingerprinting, and network-level sentinel analysis into a unified four-layer defense system. No rootkit. No telemetry. No compromise.

v0.6.0.1a Latest release Kernel driver gen 2 is here →
0
Titles in Beta Testing
0
Threats Blocked
0
Sessions Protected
0
Pentest Scenarios Run
Engine --
Sigs: --
Regions: --/3 online
Last sync: --
True Positive Streak: -- days
Daily Digest
Today Yesterday 7-day trend
Protecting titles in closed beta
VANTAGE POINT CINDERCREST MOLTEN ANVIL Paperlight DRIFTWOOD SIGNAL

The gaps in current anti-cheat

Most solutions still rely on techniques designed for an earlier generation of cheats. Here's where they fall short.

Signature-Only Detection
Reactive • Always Behind

Most anti-cheat solutions rely primarily on signature databases — known cheat hashes that are matched at runtime. This means every new cheat version, every recompile, every obfuscation pass creates a window of zero detection. The cheat ecosystem moves faster than signature updates. Public cheats get caught, but paid providers deliver undetected builds within hours of each database update.

No Hardware-Layer Defense
Blind to Physical Attacks

DMA attack boards, firmware-spoofed devices, and external memory readers operate below the software layer entirely. No amount of kernel scanning can detect a cheat that reads game memory from a second machine over PCIe. This attack surface is growing — DMA hardware is cheaper and more accessible every year, and virtually no anti-cheat currently addresses it.

Privacy vs Protection Tradeoff
Always-On • Intrusive

Some solutions require boot-time kernel drivers that run 24/7 — even when you're not playing. This creates a permanent attack surface on every installed system, breaks third-party software like RGB controllers and overclocking tools, and raises serious privacy concerns. Players shouldn't have to choose between security and system integrity.

Four layers, every attack surface covered

Cerberus guards every layer of the stack — kernel, behavior, hardware, and network. No other anti-cheat operates across all four simultaneously.

01
🛡
Kernel Integrity
Deep ring-0 introspection that monitors every syscall, page table modification, and driver load in real-time. Detects threats before they touch game memory.
  • Hypervisor-assisted memory isolation
  • Syscall table tamper detection
  • Page table entry (PTE) manipulation detection
  • Vulnerable driver exploit blocking (BYOVD)
  • Manual map detection — PEB-unlinked executable memory scanning
  • Instrumentation callback & exception handler monitoring
  • Process hollowing & early bird APC injection detection
  • Driver stack integrity attestation
02
🧠
Behavioral AI
Multi-model ML pipeline analyzing input at 1000Hz+. Builds per-player behavioral fingerprints and detects anomalies no signature scanner can catch.
  • Temporal convolutional network (TCN) aim analysis
  • Micro-movement entropy scoring
  • Cross-session behavioral drift detection
  • Humanization bypass detection (jitter/noise)
  • Camera-movement correlation analysis
  • Trigger-timing spectral decomposition
  • Account-sharing & boosting detection
  • Adaptive model retraining per game title
03
🔍
Hardware Fingerprinting
Deep hardware interrogation — PCIe topology mapping, firmware attestation, IOMMU validation, and timing-based DMA detection that catches what device lists miss.
  • PCIe topology & BAR region mapping
  • IOMMU/VT-d configuration attestation
  • DMA timing-anomaly analysis
  • FPGA bitstream fingerprinting & TLP timing profiling
  • USB HID firmware attestation (KMBox/Arduino detection)
  • TPM 2.0 platform integrity attestation
  • GPU shader pipeline tamper detection
  • Multi-ban hardware identity linkage
04
🌐
Network Sentinel
Server-side traffic analysis and cross-player intelligence. Detects coordinated cheating, replay attacks, and packet manipulation that client-side systems can never see.
  • Real-time packet integrity validation
  • Server-side movement reconciliation
  • Cross-player statistical anomaly detection
  • Cheat-cluster & ring identification
  • Session replay forensic analysis
  • External AI inference pattern recognition (DMA + ML detection)
  • Global threat intelligence feed
  • Matchmaking integrity scoring

Watch the four layers respond

A simplified walkthrough of what happens, in milliseconds, when Cerberus evaluates a session. Real detections run continuously and silently — this just slows it down so you can see it.

Simulated session evaluation

Every layer reports independently to the verdict engine. A clean session clears all four; a flagged one gets isolated at whichever layer catches it first — no single point of failure, no single point of bypass.

Kernel Integrity
Idle
Behavioral AI
Idle
Hardware Fingerprinting
Idle
Network Sentinel
Idle

System architecture

Cerberus operates across four privilege layers — client and server — with zero persistent background processes. Each layer feeds into a unified verdict engine.

Ring 0 — Kernel Mode

EV code-signed minifilter (WHQL certification pending) with hypervisor-assisted memory isolation. Monitors syscall tables, PTE modifications, and driver stacks. Loads on launch, unloads on exit — zero residual footprint.

Ring 3 — User Mode

Multi-model ML pipeline running TCN-based aim analysis, entropy scoring, and behavioral fingerprinting at 1000Hz+. ~2 ms median scan latency, 0.3–0.9% frame-time impact in partner titles.

Hardware Layer

Deep hardware interrogation — PCIe topology mapping, IOMMU attestation, TPM 2.0 integrity verification, and timing-based DMA detection that catches what device lists miss.

Network Layer

Server-side traffic validation, cross-player anomaly correlation, cheat-ring detection, and global threat intelligence. Catches what client-side systems can never see.

Protection from launch to exit

Continuous monitoring across the entire game session. Loads on launch, scans during play, unloads on exit.

Phase 1 — Game Launch
Pre-Session Scan
  • Hardware device enumeration and verification
  • System integrity baseline established
  • Driver and module integrity verified
  • Signature database synced
  • DRM license validation (if applicable)
Phase 2 — Active Session
Continuous Monitoring
  • Real-time behavioral AI analysis
  • Continuous system integrity verification
  • Hardware anomaly detection
  • Process and memory protection
  • Confidence-based threat scoring
Phase 3 — Detection Event
Evidence Collection & Response
  • Session snapshot captured for review
  • Detection metadata logged (type, confidence, head)
  • Ban callback fired to game server
  • Borderline cases escalated to manual review
  • Webhook event sent to partner dashboard

What sets us apart

Built from the ground up to cover every attack surface — software, behavioral, and hardware — in a single unified solution.

Capability Traditional AC Cerberus
Kernel-level integrity protection
DMA / hardware attack detection
Real-time behavioral AI~
Firmware-level device verification
Zero telemetry / zero PII
Runtime-only (no always-on driver)~
DRM integrity verification
No third-party driver conflicts

Want the full breakdown, including where a lighter solution might still be the right call? See the full comparison →

Protection that scales with your title

Every plan runs the same engine across the same three regions. What changes is how many detection layers are switched on, how much history you keep, and how fast you can reach us.

Availability is covered by our 97% monthly uptime commitment.
See everything included in each plan →

Certified hardware support

Tested on the Intel, AMD and NVIDIA configurations our beta partners actually ship on. Driver conflicts are rare but not zero — every one we find is listed under Known Issues on the status page.

Intel
CPU & Chipset
AMD
CPU & Chipset
NVIDIA
GPU & Drivers
ASUS
Motherboard & RGB
MSI
Motherboard & OC
Gigabyte
Motherboard & RGB
ASRock
Motherboard
Corsair
Peripherals & iCUE
Logitech
Peripherals & GHub
Razer
Peripherals & Synapse
SteelSeries
Peripherals & GG
Samsung
NVMe & Storage

Cerberus never blocks third-party drivers. No broken RGB software, no disabled fan controllers, no forced reboots. Full compatibility with HVCI, Secure Boot, and Windows 11 kernel-mode hardware-enforced stack protection.

Live cheat landscape

Real-time monitoring of known cheat providers. Detection status, activity level, and threat scoring updated continuously from our research pipeline.

Built for competitive framerates

Cerberus was engineered to be invisible to performance. Every scan, every inference, every check — under budget.

~78%
Blended Detection Rate
Across all cheat categories (beta)
0.14%
False Positive Rate
Borderline cases escalate to manual review
<0.4%
CPU Overhead
Avg across all layers
~2.2 ms
Scan Latency
Median scan cycle today
22MB
Memory Footprint
Total runtime allocation
0.3–0.9%
Frame Impact
Frame-time impact, partner titles (v0.6 alpha)

Detection Coverage

Internal benchmark results from controlled pentest environments. Exact rates vary by cheat category and are continuously improving.

Aimbot / Aim Assist TCN aim-path analysis, micro-movement entropy
89.0%
Wallhack / ESP Occlusion checks, overlay and GDI hooks, pixel bots
84.0%
DMA External PCIe capture cards, firmware-spoofed hardware, IOMMU gaps
72.0%
Kernel Driver Ring-0 rootkits, BYOVD, DKOM, callback removal
78.0%
Speed / Teleport Movement validation, server-side physics deltas
65.0%
HWID Spoof Serial and firmware spoofing, hardware re-identification
58.0%
85% and above — on target
70–84% — acceptable, actively being improved
Below 70% — known weak spot, on the roadmap
v0.6.0.1a · Internal pentest environment · Real-world rates vary by title
32
Engineers building the future of game security
Kernel & Hardware AI & Detection SDK & Platform QA & Stability Infrastructure & DevOps
Meet the Team

Common questions

No. The kernel driver loads only when your game launches and unloads when it exits. Cerberus has zero presence on the system outside of active game sessions. No boot-time driver, no background processes, no tray icon.

Detections below 95% confidence are never auto-banned — they enter the manual review queue. A threat analyst reviews the full session replay within 4 hours (Cerberus tier SLA). If a ban is issued and appealed, review completes within 24 hours. Current false positive rate: 0.14%.

Zero PII. Cerberus processes hardware IDs, input patterns, and memory state locally on the player's machine. Only detection events (ban/flag) with anonymized session metadata are sent to the API. We don't track playtime, game history, browsing, or anything outside the active session.

The driver requires ring-0 access to monitor memory permissions, detect mapped drivers, and enumerate PCIe devices. It's EV code-signed (WHQL certification pending) and undergoes third-party security audits quarterly. The driver uses ObRegisterCallbacks for process protection — it cannot read or modify game memory itself.

Under 2 hours for Unreal Engine and Unity with our plugins. The raw C++ SDK is 4 API calls: Init, StartSession, EndSession, Shutdown. Full integration guide is available in our documentation.

The driver binary uses multiple layers of code protection and integrity verification. Critical detection logic runs server-side and is never exposed to client machines. We rotate protection schemes with each update.

Yes. Cerberus includes DRM integrity verification as part of the pre-session scan. It detects binary patching, license bypass attempts, loader modifications, and tampered game executables. This works alongside your existing DRM solution (Denuvo, Steam DRM, etc.) as an additional layer of protection.

On detection, Cerberus captures a session snapshot including the detection type, confidence score, which detection layer triggered, and anonymized session metadata. This evidence package is sent to the partner dashboard for review. High-confidence detections trigger an immediate ban callback to your game server. All data is retained for appeal review.

Windows 10 21H2+ or Windows 11 (x64). Secure Boot must be enabled in BIOS for full hardware verification. TPM 2.0 is recommended but optional. Players should keep Windows and GPU drivers up to date. No special BIOS configuration beyond Secure Boot is required. Not sure? Run the free Readiness Check — no account, no network access.

The kernel driver is EV code-signed (WHQL certification pending) and tested across 40+ hardware configurations. If the driver fails to load for any reason, the game continues with graceful degradation — it never forces a crash. In 8 months of beta testing, we've had no widespread BSOD issues. One incident involving Windows 11 24H2 preview was patched within 13 hours.

Players can submit ban appeals directly at cerberusac.dev/appeal using the 20-character appeal reference shown on their ban screen, or through your game's support flow. Appeals go to our threat analyst team who review the full detection evidence, session snapshot, and hardware fingerprint. Cerberus tier partners get 4-hour appeal SLA. If a ban is determined to be a false positive, the player is unbanned and the detection model is updated to prevent recurrence.

Ready to secure
your game?

Cerberus is currently in closed early access. Request access for your studio.

Simulated telemetry, no sign-up

Cerberus is in active development. Features and specifications are subject to change.