<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Anti-Cheat · ArchWorks</title><link>https://archworks.co/tags/anti-cheat/</link><description/><language>en</language><lastBuildDate>Sun, 06 Sep 2026 00:00:00 +0200</lastBuildDate><atom:link href="https://archworks.co/tags/anti-cheat/index.xml" rel="self" type="application/rss+xml"/><item><title>Bypassing VM detection</title><link>https://archworks.co/posts/bypassing-vm-detection/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0200</pubDate><guid isPermaLink="true">https://archworks.co/posts/bypassing-vm-detection/</guid><description>Some software checks whether it is running in a virtual machine and changes what it does when it is - malware goes quiet, anti-cheat refuses to start. This is the week I spent making a KVM guest answer no, down to one detection out of 85. The hiding cost no measurable performance, and the thing that ate the most time was not a detection at all. It was a clock.</description></item><item><title>VM Detection Hardening</title><link>https://archworks.co/docs/vfio-native/</link><pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate><guid isPermaLink="true">https://archworks.co/docs/vfio-native/</guid><description>The full writeup: getting a KVM guest from 10/85 to 1/85 on VMAware - the packaged short path, domain XML, QEMU and KVM patches grouped by the detection each one clears, the host headroom that costs 85x on every timing call when you get it wrong, and how to measure both the score and the speed.</description></item></channel></rss>