---
name: anti-cheat-systems
description: Analyze layered anti-cheat architecture, detection evidence, telemetry, and enforcement tradeoffs. Use for system-level defense questions; use narrower skills for DMA, kernel, graphics, mobile, or server details.
---

# Anti-cheat systems

Map the protected asset, attacker capability, observation point, detector, and enforcement authority. Separate confirmed product behavior from general defensive patterns.

## Topic routing

- [Architecture and detection](references/architecture-and-detection.md) for products, client/kernel/backend layers, memory, process, behavior, and input signals.
- [Research and threats](references/research-and-threats.md) for analysis methods, bypass categories, platform interactions, protection, telemetry, and ethics.
- [Repository map](references/repository-map.md) and [repository resources](references/repository-resources.md) for collection-backed source selection.
- [Input provenance](references/input-provenance-and-measurement.md), [detector operations](references/detector-operations.md), or [network evidence](references/network-environment-evidence.md) for those specific evidence questions.

Use `dma-attack-techniques`, `windows-kernel-security`, `graphics-api-hooking`, `mobile-security`, or `game-server-security` when that boundary dominates. Apply `game-security-research-rigor` to consequential or disputed claims.
