Riot Vanguard vs VAC Live: Anti-Cheat Comparison 2026

Riot Vanguard vs VAC Live: Anti-Cheat Comparison 2026

7 min readDivine Team
vanguardvacanti-cheatcomparison
Quick Summary

Vanguard runs continuously at kernel level, VAC Live watches behaviour server-side. What those two opposite philosophies actually mean for a buyer.

Two systems, two philosophies: the short answer

Riot Vanguard and Valve's VAC Live try to solve the same problem through opposite approaches. Vanguard looks for the problem on the machine itself: it runs at kernel level and watches for as long as the system is on. VAC Live looks for the problem in the outcome of play: server-side, it compares player behaviour against data.

That distinction is not academic; it has a direct consequence for a buyer. On the Vanguard side, the assessment window is far wider than a game session. On the VAC side, assessment rests on data produced during play and accumulates over time. Our catalogue carries products for both sides; this article explains how the system you are up against works, before you decide which product to pick.

The first step in choosing the right product is knowing which anti-cheat logic the game runs on. Vanguard looks at the machine, VAC Live looks at the outcome; they ask different questions and they ask different decisions of the buyer.

This article contains no technical instructions for defeating any anti-cheat system. The aim is that a buyer evaluating a product knows which system they are up against and comes to the catalogue with the right question.

Riot Vanguard: kernel level and continuous operation

Vanguard is a driver operating at the Windows kernel level, and it is mandatory for Valorant. Three characteristics set it apart.

The first is the level it runs at. A kernel-level component can observe system states that user-level software cannot see.

The second is when it runs. Vanguard starts with the system rather than waiting for the game to open, and Valorant will not launch if it is disabled. That removes the limit of a game-session-only observation window.

The third is its scope. Vanguard assesses not only the game process but the general state of the system. Riot has defended this approach publicly and answered privacy debates within that frame.

Those three together define the ground a buyer evaluating Valorant products stands on. Products built specifically for that ground sit in our catalogue: the Valorant category holds five separate products, and what separates them is not a safety level but duration options, price band and scope. We broke down which one fits which usage scenario, and in what order to decide, in the Valorant cheat buying guide.

VAC and VAC Live: server-side behaviour analysis

Valve's approach starts somewhere else. Classic VAC rests on signature-based checks. VAC Live adds an assessment layer running server-side.

The logic is this: rather than recognising a piece of software, it asks whether the outcome produced in game is consistent with the distributions human players produce. The strength of the approach is that it can work against software never seen before; its weakness is that it works on probability and cannot produce certainty from a single session.

What distinguishes VAC Live is that this assessment can also run over live matches. We detailed the behavioural assessment channel, and why it is independent of the software, in the legit config article.

Side by side

Operating level

  • Vanguard: a driver operating at the Windows kernel level.
  • VAC Live: a user-level client component plus a server-side assessment layer.

When active

  • Vanguard: from the moment the system boots, including while the game is closed.
  • VAC Live: during the game session and the server-side analysis that follows it.

Primary detection approach

  • Vanguard: observation of system state and checks for known traces.
  • VAC Live: behaviour analysis over game data, alongside signature checks.

Against unknown methods

  • Vanguard: a wide observation window, but recognising a new method requires an update.
  • VAC Live: being behaviour-based, it can respond to methods never seen before, though the result is probabilistic.

Timing of enforcement

  • Vanguard: enforcement can follow detection quickly.
  • VAC Live: enforcement is often accumulated and applied in bulk. The reason is operational efficiency as much as a desire to control when the detection method becomes visible; applying in bulk keeps the method hidden longer than applying case by case.

The right question is not "which one is easier to defeat"

That is the most frequently asked question about this comparison. Sharpening the question works better than answering it, because the two systems share no common measure.

One has a wider technical observation window; the other has broader behaviour analysis. So the useful question is not "which is weaker" but "which channel am I assessed through in the game I play, and which product makes sense for that channel".

We offer no guarantee of defeating any anti-cheat system; such a guarantee would imply covering that system's future updates, and nobody can commit to that scope. Instead of a guarantee we give a measurement: the current state of every product in our catalogue is published openly on the live status page, you can look at it yourself before buying, and the page changes the moment the label changes. Few sites do this; we would rather you decided on the current state than on a claim. We explained what the labels there convey in the what undetected means article.

Why the update rhythms differ

The two systems also behave differently on updates, and that explains why product states change at different speeds from game to game.

Updating a kernel-level component is a heavier process on the operating system side; a server-side assessment model, by contrast, can be updated without sending anything to the client. In practice that makes changes on the VAC side less visible from the outside.

We quote no fixed turnaround for how long a product takes to work again after an update; that calendar sits with the anti-cheat side. What we did do is lighten the cost of waiting on the buyer's side: a licence period starts the moment you first activate the key inside the loader, not at purchase. Waiting out an update therefore does not burn the days you paid for.

Which systems the other major games use

Vanguard and VAC are not the whole anti-cheat world. The two large independent providers on the market are Easy Anti-Cheat and BattlEye, and they are used across many games either separately or together.

Fortnite is a special case in that picture, because it runs both systems at once. We covered separately what that means and what ground it creates for a buyer in the Fortnite cheat buying guide.

That variety is also why one product does not produce the same result in every game. Software working in one game does not mean it will work the same way in another game running a different anti-cheat. This is exactly why the catalogue is split by game: every product page states which game it was built for and shows its compatibility information directly, so you never have to guess.

A similar variety applies on the hardware identity side: different systems read hardware identity at different depths, and enforcement applied in one game does not directly affect another. Risk assessment therefore has to be made game by game.

The practical takeaway for a buyer

Three practical conclusions follow from this comparison.

First, the choice of game changes the risk profile. The same behaviour is assessed through different channels in different systems, and the right product is the one chosen for the anti-cheat logic of the game you actually play.

Second, technical detection and behavioural detection are separate channels, and a product's status label covers only the first. The label tells you the current technical state of the software; in-game behaviour remains in your hands.

Third, everything after the decision is handled for you. The moment payment confirmation reaches the system your licence key is allocated automatically and delivered through two channels at once: it is sent to your email address and written into the order history in your account area at the same time. There is no manual queue, which is why delivery usually completes within minutes. If no key is left in stock the order is not cancelled; it moves to "awaiting stock" and stays open until the key is delivered. We described that whole flow in the licence key delivery and activation article, and the wider decision framework in the game cheat buying guide.

Frequently Asked Questions

Which is stronger, Vanguard or VAC Live?

Comparing them directly is misleading because they share no common measure. Vanguard runs at kernel level and watches for as long as the system is on, giving it a wider technical observation window. VAC Live rests on server-side behaviour analysis and can respond to methods never seen before, though its result is probabilistic. Neither substitutes for the other; they ask different questions. The practical upshot for a buyer: you pick the product for your game, which is exactly why our catalogue is split by game.

Can both anti-cheat systems be defeated?

We offer no guarantee of defeating any anti-cheat system; such a guarantee would imply covering that system's future updates, and nobody can commit to that scope. We give it as a measurement rather than a promise: the current state of every product is published on the live status page and you can check it yourself before buying. So the answer to this question is not a fixed yes or no, it is the product's label at that moment.

Why does Vanguard run as soon as the computer boots?

Vanguard is a kernel-level driver and starts with the system so that its observation window is not limited to the game session. Valorant will not launch if it is disabled. The design keeps preparations made while the game is closed within the scope of assessment, and Riot has defended the approach publicly.

How long do products take to come back after an anti-cheat update?

We cannot quote a fixed turnaround, because that calendar sits with the anti-cheat side. Updating a kernel-level component and updating a server-side model are different processes; the second can change without sending anything to the client. What we do is keep the process visible: the moment a product's state changes, its label changes too, so you can follow it rather than guess. And because a licence period starts at first activation rather than at purchase, waiting does not spend the days you bought.

Does the choice of game affect my ban risk?

Yes, because the same behaviour is assessed through different channels in different systems. A system running continuously at kernel level and one watching behaviour server-side rest on different data, and their enforcement timings differ too. A risk assessment valid in one game therefore does not transfer directly to another, and the compatibility information on product pages exists precisely to make that distinction visible.

Back to All Posts