Skip to the content.

Architecture

Component model

Protected application
        |
        | PID and process identity
        v
anticheat.exe
  user-mode module inventory
  executable-memory classification
  bounded hashing and probing
        |
        | versioned METHOD_BUFFERED IOCTL
        v
AcTelemetry.sys
  process callbacks
  image-load callbacks
  thread callbacks
  process-handle callbacks (telemetry only)
  bounded nonpaged event queue
        |
        v
tamper-evident JSONL
        |
        v
telemetry shipper and remote receiver
        ^
        |
collector/shipper watchdog and terminal-state reporting
        |
        v
integrator storage, correlation, and policy

Kernel boundary

The driver registers documented process, image-load, thread, and Object Manager process-handle callbacks for one active target PID. It stores fixed-size records in a preallocated queue and does not perform target-memory scanning or access downgrading in callback context.

The device is exclusive and restricted to SYSTEM. Target registration is bound to a random protocol session ID. All requests use fixed-size structures and METHOD_BUFFERED.

User boundary

The collector validates process identity, opens the target with read-only process rights, inventories loader-visible modules, maps executable virtual memory, and emits classified findings.

The Win32 module, virtual-memory, and read APIs are not a trusted security boundary. Scan records identify this source as untrusted. Kernel image-load bases are correlated with the next module snapshot so cross-source omissions remain visible, subject to legitimate unload races.

The collector does not request process write, operation, terminate, or remote-thread rights.

Integrator boundary

Integrators own:

A hostile kernel driver can manipulate both callback and user-mode views. The architecture raises attacker cost but does not claim local authority against a same-ring adversary.

See the repository security model for the complete trust boundary.