Reacting to detected cheating
Goal: You will learn how to get notified when someone tampers with your game, so you can react instead of only protecting silently.
The problem
Protecting your values is only half the job. Encryption and honeypots keep cheaters from succeeding, but if nothing happens when tampering is detected — no log, no warning, no flag — you cannot respond. You need a reliable way to know that cheating occurred so you can log the attempt, show a warning, remove the player from a match, or flag an account.
This guide builds directly on Protecting memory against Cheat Engine.
The solution
Hook into detector notifications. Every detector can tell you when it becomes suspicious: through an inspector event, a detection flag, or an observer subscription in code.
Step 1: Understand how a detection travels
Before reacting, it helps to understand how a detection makes its way through the system. There are three moving parts:
- Monitors observe your game and the player's device and publish raw data, for example the current game time or the state of a protected value. They only report what they measure; they do not judge anything.
- Detectors decide if a measurement looks like cheating. Most of them set
PossibleCheatingDetectedto true and leave it true. The game-time detector clears it again when the clock looks normal. - The AntiCheat-Monitor is subscribed to every attached detector. It combines all reported threats into one overall threat score and, once a threshold is passed, triggers the punishers.
In short, a detection flows like this:
Monitor -> Detector -> AntiCheat-Monitor -> Punisher / your reaction
You can plug your own reaction in at the detector level (the most common place) or, for a more technical approach, at the monitor level.
Step 2: React with an inspector event (no code)
Every detector exposes an On Cheating Detection Event in the inspector. You can assign your own callbacks there, without writing any code, exactly like a Unity button's OnClick event. This is shown in the Protecting memory against Cheat Engine guide, where the Primitive Cheating Detector inspector is described.
Step 3: Check the detection flag
Every detector has a PossibleCheatingDetected property. It starts as false and becomes true once cheating has been detected. This is handy when you just need a simple gate, for example before granting a reward:
var detector = AntiCheatMonitor.Instance.GetDetector<PrimitiveCheatingDetector>();
if (detector != null && detector.PossibleCheatingDetected)
{
// Someone tampered with a protected value at least once.
}
Step 4: Subscribe an observer (recommended for logic)
If you want to run your own code the moment cheating is detected, subscribe an observer to the detector. An observer implements IObserver<IDetectorStatus>, which gives you three methods. The important one is OnNext, which receives the detection status, including the ThreatRating and the PossibilityOfFalsePositive.
public class CheatingLogger : IObserver<IDetectorStatus>
{
public void OnNext(IDetectorStatus status)
=> Debug.LogWarning($"Cheat detected (threat={status.ThreatRating}, falsePositive={status.PossibilityOfFalsePositive}).");
public void OnError(System.Exception error) { }
public void OnCompleted() { }
}
Then subscribe it during your setup, for example in an Awake or Start method:
var detector = AntiCheatMonitor.Instance.GetDetector<PrimitiveCheatingDetector>();
detector.Subscribe(new CheatingLogger());
Subscribe returns an IDisposable. Keep it if you want to stop listening later; disposing it unsubscribes your observer.
Step 5 (optional): Subscribe directly to a monitor
For a more technical, lower-level approach, you can subscribe directly to a monitor. This lets you receive its raw readings before any detector judges them, which is useful if you want to build your own logic on top of the monitored data.
Monitors use the same observer pattern as detectors, exposing Subscribe(IObserver<IWatchedSubject>). Since there is no lookup helper for monitors on the AntiCheat-Monitor, you need a reference to the monitor component yourself, for example through a serialized field or GetComponentInChildren. This option is entirely optional; for most games, reacting at the detector level is enough.
The result
When tampering is detected, you are no longer left in the dark:
- Inspector callbacks can run with no extra code.
- Your game logic can gate rewards or features with
PossibleCheatingDetected. - Observers receive the detection status as soon as it happens, so you can log, warn, or flag the session.
Next steps
- Punishing cheaters — let AntiCheat react automatically once the threat score is high enough.
- Detector — all available detectors and how they attach to the AntiCheat-Monitor.
- Guides — pick another protection scenario if you have not covered it yet.