sep 24, 2026
what an anti-cheat knows about your pc
i used to make cheats, so i spent a long time on the other side of this. here's what gets collected, and which of it actually matters.
i used to make cheats. a big part of that job wasn't the cheat itself, it was keeping people from getting banned, which means you end up learning exactly how an anti-cheat recognises a machine. i don't do that anymore, but the knowledge stuck around, so i wrote it down as a tool instead: hwdump.
it pulls basically every hardware and os identifier windows will hand a user-mode process and lays the whole set out so you can see it. it only reads. no patching, no spoofing, nothing gets changed.
how a machine gets recognised
an anti-cheat doesn't trust one id. it stacks a pile of them into a fingerprint, keeps that on its own servers, and checks new logins against it. change one value and the rest still point at you.
most of the pile is trivially changeable: registry guids, mac addresses, volume serials. a few really aren't: the tpm key, cpuid, the real firmware smbios. knowing which is which is the whole game.
what's in the pile
- cpu: brand, cpuid signature, ProcessorId, core counts
- board and bios: baseboard and bios serials, smbios uuid, sku, chassis serial, read straight from firmware with
GetSystemFirmwareTable, not just wmi - firmware: uefi or legacy, secure boot on or off
- gpu: dxgi description, pci ids, adapter luid, real vram, plus the vulkan and nvml device uuid
- disks: model and serial, VPD page 0x83 id, nvme identify, gpt disk guid, wwn, every mounted volume and its serial
- ram: part number, serial, size and speed per stick
- network: every adapter's current and permanent mac
- peripherals: keyboards, mice, hid devices, audio, bluetooth, cameras, with instance ids
- pci tree: every pci device, its location and ContainerId
- usb history: everything that was ever plugged in, straight out of USBSTOR
- monitors: edid decoded from the registry, down to the vendor, serial and year
- windows identity: MachineGuid, SQMClient MachineId, HwProfileGuid, product id, install date, user and machine sids, timezone, locale
- tpm: manufacturer, spec, and the endorsement key, the one id actually burned into the board
the ones that matter
everything above is user-mode. kernel identifiers are left out on purpose: stuff like the intel and amd PPIN sits behind RDMSR, which is ring-0 and needs a signed driver. hwdump ships no driver.
the ids that really matter, the tpm endorsement key, the firmware smbios and the vulkan and nvml gpu uuid, sit below where a user-mode spoofer can reach. a real anti-cheat cross-checks them against each other and against what it already has on record.
why spoofing backfires
if you're here hoping to flip these and dodge a hardware ban, save your time. change the easy registry guids and the hard ids still match, now alongside values that no longer agree with each other. that mismatch is its own signal, so you end up a bigger target than if you'd done nothing.
that's the main thing years on the other side taught me. hwdump is read-only, it changes zero values, and it isn't half of a spoofer either. it's for seeing what your machine gives away.