SkedAC Documentation

Everything you need to deploy SkedAC across your organization and explain it to your players.

👤 Player guide — Installation

Your organizer asked you to install SkedAC to take part in the tournament. The process is simple and takes less than 2 minutes.

Requirements

  • Windows 10 or 11 (64-bit)
  • An active Discord account

Installation

  1. 1
    Download and install the software Your organizer shared a download link with you. Run the setup and follow the installation steps. Always run SkedAC as administrator — the software won't work without admin rights.
  2. 2
    Allow it to run if Windows asks Windows may show an "Unknown publisher" warning. Click "More info" then "Run anyway". This message appears for any software not signed by a major publisher.
  3. 3
    Select your organization On first launch, the software shows an organization selection screen. Choose "Other organization" (or your tournament name if it appears in the list), then select your organization from the list.
  4. 4
    Log in with Discord Click "Log in with Discord" and authorize the app from your browser. Next time, the software reconnects automatically.

Once connected, SkedAC runs in the background. It does not slow down your PC or your game. You can play normally.

Discord login

SkedAC uses your Discord account to identify you. You don't need to create a dedicated SkedAC account.

The first login opens your browser to authorize the app. After that, the software reconnects automatically — in one click, or even with no action if you were already logged in.

ℹ️

SkedAC only requests access to your Discord username and avatar. It does not read your messages, does not join your servers, and sends no notifications to your contacts.

What is monitored

SkedAC analyzes your machine during the game session. Here is what is collected:

All collected data is technical and hardware-related — SkedAC does not access your personal files, your history or your communications. For full details, see our Terms & Privacy Policy.

Data collected

  • Connected hardware — list of USB, PCIe and HID devices to detect suspicious devices
  • Active processes — names of software running during the session (not their content)
  • Screenshots — taken at random intervals during the session, visible only to your organization's admins, deleted after 48h
  • Windows security modules — state of Secure Boot, VT-x/AMD-V, Memory Integrity (HVCI), Vulnerable Driver Blocklist and IOMMU/VT-d
  • Machine ID — anonymized hardware fingerprint tied to your PC, independent of your identity

Data NOT collected

  • The content of your personal files
  • Browsing history
  • Data from your other accounts or apps
  • Any data outside active game sessions
📸

Screenshots — automatically deleted after 48 hours. Accessible only to authorized admins of your organization. They only contain what is visible on screen during your session.

Privacy & GDPR

Your data is processed in compliance with the GDPR. Every organization using SkedAC has signed a Data Processing Agreement (DPA) with Sked.

  • Data hosted in Europe
  • Full isolation between organizations — your data is only visible to your tournament's admins
  • Screenshots deleted after 48h, raw data after 2 to 30 days depending on the plan
  • You can request deletion of your data by contacting the organizer or hello@sked.gg

Uninstall

SkedAC installs via a Windows setup. To remove it, use the Windows program manager:

  1. Open Control Panel → Programs → Uninstall a program
  2. Find SkedAC in the list and click "Uninstall"
  3. Follow the uninstaller's instructions

To revoke the Discord access granted to the app, go to Discord Settings → Authorized Apps and revoke "SkedAC".

🛡️ Admin guide — Dashboard

The SkedAC dashboard is accessible from any browser. Your username and password were provided by the Sked team during your onboarding.

Overview

  • Active sessions — players currently connected, with real-time alerts
  • Session history — all past sessions, filterable by player or by date
  • Alerts — centralized log of all alerts, with day-by-day navigation
  • Player profiles — full history, Trust Score, admin notes, ban history

Reading alerts

Each alert has a severity level. Here is how to interpret them:

Severity levels

  • CRITICAL — known cheat software or hardware detected, requiring immediate investigation (e.g. DMA, modified client, identified cheat process)
  • HIGH — serious signal to verify with screenshots and the player profile (e.g. active VPN, memory manipulation tool)
  • MEDIUM — indicator to put in context (e.g. disabled security module, unknown device)
  • LOW — information to log, no immediate action required (shown in green on the dashboard)
💡

A single alert is not proof of cheating. Always cross-check the alert with the session screenshots, the player profile and the match context before making a decision.

Automatic alert resolution

Alerts resolve automatically when the player fixes the detected issue. Each alert shows the trigger time and the clear time — useful for context (e.g. a VPN disabled mid-session before the match).

🚨 Alert types

⚙️ Security module disabled

A Windows security module is disabled: HVCI (kernel isolation), Secure Boot, TPM, Defender, etc. Some cheats require disabling these protections to work.

  • HIGH: HVCI (kernel isolation) disabled with no known reason — makes loading cheat drivers easier
  • MEDIUM: Secure Boot or real-time Defender disabled
  • LOW: HVCI disabled but a USB polling-rate driver detected (gaming mouse overclock) — legitimate reason

🔒 Defender tampering / VDB disabled

A specific alert for two situations:

  • 🔧 Defender tampering (dControl): Windows Defender antivirus was disabled via a third-party tool (dControl, Sordum, etc.) by modifying Windows registry keys. This is not a normal disable from Windows settings — it is a deliberate registry manipulation, often used to prevent Defender from blocking a cheat.
  • 🛡️ VDB (Vulnerable Driver Blocklist) disabled: Windows' vulnerable driver blocklist is disabled. This allows loading drivers exploited by some cheats (BYOVD technique = "Bring Your Own Vulnerable Driver").
  • HIGH: Defender tampered (registry keys modified), or VDB disabled together with HVCI disabled
  • MEDIUM: VDB disabled alone (HVCI still active)
ℹ️

If the player has a cheat-ready profile (see below), VDB and Tampering alerts are grouped into the cheat-ready profile to avoid duplicates.

🛡️ Cheat-ready profile

The player's PC shows a combination of disabled protections that exactly matches the configuration required by some cheat software. Individually each disabled module may have an explanation, but their combination is highly suspicious.

Example combinations: HVCI OFF + Defender OFF + VDB OFF + Firewall OFF = a configuration documented in cheat guides (Castro, etc.).

  • CRITICAL: High score (≥4 modules disabled) + Defender tampered — cheat config near-certain
  • HIGH: Medium score (3+ modules disabled)
  • MEDIUM: Low score (2 modules) — to watch
⚠️

Recommended action: Ask the player why these protections are disabled. If they have no legitimate explanation (incompatible driver, etc.), consider a preventive suspension.

🖥️ Virtual machine detected

The game runs inside a virtual machine (VirtualBox, VMware, Hyper-V). VMs allow bypassing all hardware protections and hiding the machine's identity.

  • CRITICAL: Always. VM = ban unless special authorization.

🔍 Security module inconsistency

Security modules are in a contradictory state. For example, HVCI active while CPU virtualization (VT-x) is disabled — that's physically impossible, which indicates manipulation of the reported values.

  • CRITICAL: Physically impossible combination — likely falsification
  • HIGH: Highly suspicious combination (cross-check failed)

⚠️ Suspicious process

A running program matches a known cheat, macro, or manipulation tool.

  • CRITICAL: Confirmed cheat software (Cheat Engine, WeMod, Extreme Injector, etc.) or AI aimbot with detected ML signature
  • HIGH: Macros, unauthorized remapping tools, AI aimbots (Aimmy, etc.), randomly-named program in temp files
  • MEDIUM: Unsigned program from a suspicious folder (Desktop, Downloads, Temp)

🎯 Memory handle on the game

A program opened direct access to the game process's memory. Internal cheats use this kind of access to read/modify game data in real time (wallhack, aimbot, etc.).

  • CRITICAL: Full access (PROCESS_ALL_ACCESS) by an unrecognized program
  • HIGH: Memory access by a suspicious program
ℹ️

Legitimate software like Razer Synapse, NVIDIA GeForce, Discord or Steam also open handles on games for their overlays — they are automatically excluded if signed by a trusted publisher.

⚙️ Suspicious driver

A driver loaded in Windows matches an exploit, DMA, or input-interception tool.

  • CRITICAL: PCILeech, LeetDMA, Cheat Engine kernel driver, kernel mappers
  • HIGH: BYOVD (vulnerable driver exploited by a cheat), input interception, controller emulators with no physical controller
  • MEDIUM: Vulnerable driver used by legitimate software (Corsair iCUE, MSI Afterburner, etc.)
  • LOW: ViGEmBus + console controller (DS4Windows/Steam Input), HidUsbF for polling rate

💉 DLL injected into the game

A suspicious software library (DLL) was detected in the game process or in a temp folder. Internal cheats inject into the game as a DLL.

  • CRITICAL: Known cheat DLL injected into the game process
  • HIGH: Unknown DLL in the game process
  • MEDIUM: Suspicious DLL in temp files (potential payload)

📝 Cheat traces in the registry

Traces of cheat software were found in the Windows registry — even if the software is not active at scan time. This indicates it was installed on this machine.

  • CRITICAL: Cheat Engine, PCILeech, HWID Spoofer, Extreme Injector
  • HIGH: Other cheat software

🌐 VPN detected

A VPN or proxy is active during the session. It can hide the player's real location or bypass IP restrictions.

  • HIGH: Unknown VPN or active proxy
  • MEDIUM: Popular commercial VPN (NordVPN, ProtonVPN, etc.) — common privacy use
  • LOW: Gaming network optimizer (ExitLag, WTFast, etc.) — legitimate tool

🖼️ Suspicious overlay

A transparent window (overlay) is shown on top of the game. Some cheats use overlays to display a wallhack, a radar or an ESP (see enemies through walls).

  • HIGH: Unknown or suspicious overlay active over the game
  • LOW: Authorized overlay (external crosshair approved by staff)
ℹ️

Legitimate overlays (Discord, Steam, Xbox Game Bar, NVIDIA, Rainmeter, etc.) are automatically ignored.

🔌 Suspicious hardware

A suspicious hardware device is plugged into the PC (DMA, mouse/keyboard adapter, Arduino, etc.).

  • CRITICAL: DMA device (PCILeech, FPGA), XIM/Cronus/Titan/ReaSnow adapter
  • HIGH: Unidentified suspicious device, duplicated machine

🌐 Suspicious network connection

Unusual UDP connections are detected on the local network, indicating a possible KMBox Net (mouse/keyboard driven over the local network).

  • MEDIUM: Suspicious UDP connections on LAN

🌲 Suspicious game launcher

The game was launched by an unrecognized program. Normally a game is launched by its official launcher (Steam, EA App, Battle.net, etc.). An unknown launcher may be a cheat injector.

  • CRITICAL: Known injector (Cheat Engine, WeMod, Extreme Injector)
  • MEDIUM: Unrecognized parent program still active

📁 Suspicious file in the game folder

Suspicious files (unsigned DLLs, unknown executables) were found in the game's install folder. Internal cheats often copy themselves into the game folder.

  • HIGH: Suspicious DLL in the game folder
  • MEDIUM: Suspicious DLL in temp files

🔑 Machine change

The player's hardware ID (Machine ID) changed between two sessions. This may indicate use of a HWID spoofer — a tool that hides the PC's real identity (often to bypass a ban).

  • CRITICAL: Frequent changes (several machines in a short time = likely spoofing)
  • HIGH: New machine detected for this player

🔧 Modified SkedAC client

The SkedAC software file on the player's PC was modified or does not match an official version. May indicate an attempt to falsify the data sent.

  • CRITICAL: Unknown signature — client potentially tampered
  • HIGH: Version or signature does not match
  • MEDIUM: Incomplete data (bypass attempt)

📊 Missing data

The SkedAC client is not sending all expected data (process list, security state, hardware). May indicate deliberate blocking or a malfunction.

  • CRITICAL: Several data types missing after 3+ minutes
  • HIGH: One data type missing

Sessions & screenshots

Each session corresponds to one player connecting to the software. You can open the detailed view of a session from the history.

In the session view you'll find:

  • The alerts triggered during the session
  • The list of active processes
  • The player's hardware inventory
  • The screenshots taken during the session (available for 48h)
  • The machine used (Machine ID)
⚠️

Screenshots are confidential. Only share them with authorized staff members. They may contain personal information of the player visible on screen.

Managing sessions — duration & organization

A common question: "Should the player keep SkedAC running for the whole tournament, or only enable it during their matches?"

Both work technically. Here's the recommendation:

💡

Best practice: ask players to start SkedAC just before their match and close it right after. Each connection creates a new session — this lets you precisely tie each session to a match, and easily find the data if a dispute arises.

If the player keeps SkedAC running continuously, the whole evening becomes one long session. That's valid, but less readable for your admins — alerts and screenshots will be mixed across matches.

The rule to communicate to your players in your tournament ruleset: "Start SkedAC before your match and close it at the end. Only restart it for the next match."

Player profiles

A player's profile centralizes their entire history: sessions, alerts, machines used, admin notes and bans.

Trust Score

The Trust Score is an indicator from 0 to 100 computed over the player's full history. The lower it is, the more suspicious signals the player has accumulated. This score is indicative and does not replace your judgment.

Admin notes

You can add private notes on a player — visible only to your organization's admins. Useful to log a check you performed, a specific context or a verbal agreement.

Direct Discord contact

From a player's profile, a button lets you open a Discord conversation with them directly. Handy to ask for an explanation or notify a ban.

Banning a player

The ban is tied to the player's Machine ID, not their Discord account. A banned player who comes back with a new Discord account will be recognized immediately and an alert will be triggered.

  1. 1
    Open the player's profile From a session, an alert or the player list.
  2. 2
    Click "Ban" Add a reason (optional but recommended for your internal history).
  3. 3
    Confirm The ban is recorded. If the player tries to reconnect, a CRITICAL alert is triggered automatically.

Enhanced monitoring

Enhanced monitoring enables more frequent screenshots for a specific player, even outside active match sessions.

To enable it: open the player's profile → click the "Enhanced monitoring" toggle. The player is flagged and monitoring intensifies on their next connection.

ℹ️

The Community plan limits enhanced monitoring to 10 players at once. The Pro plan makes it unlimited.

⚙️ Onboarding — Set up your organization

SkedAC onboarding is handled by our team. Here's what happens after your access request:

  1. 1
    We receive your request We reply within 24h (often much less). We confirm the creation of your space and send you your dashboard credentials.
  2. 2
    Initial configuration Logo, colors, targeted game process — we configure your organization or guide you to do it yourself from the dashboard.
  3. 3
    You receive the software We share the download link for the software configured for your organization. You can immediately distribute it to your players.
  4. 4
    First tournament Share the software link with your players. Supervise from the dashboard. Your organization is up and running.

Game process

SkedAC monitors the game process defined in your configuration. To change the targeted process:

  1. Go to the dashboard → Organization settings
  2. Edit the Game Process field with the exact executable name (e.g. FC26.exe, cod.exe)
  3. Save — the change takes effect on the players' next connection

Common process examples

  • EA FC / FIFA: FC26.exe
  • Call of Duty: cod.exe or ModernWarfare6.exe
  • League of Legends: League of Legends.exe
  • Valorant: VALORANT-Win64-Shipping.exe
  • Rocket League: RocketLeague.exe

Manage staff admins

You can create as many staff accounts as needed from the dashboard → Manage admins.

  • org_admin — full access to all your organization's features
  • org_staff — can view sessions, alerts and profiles, but cannot ban or change the configuration

Each admin must sign the DPA (Data Processing Agreement) on their first login.

Discord & webhook alerts

Players connect to the software via Discord OAuth2. The SkedAC app is not part of any Discord server — players simply authorize access to their identity (name + avatar). You have nothing to configure on the Discord side for player login.

💡

From the dashboard, each player's profile shows their Discord handle. One click opens a Discord conversation with them directly — useful to reach them quickly on an alert.

Real-time Discord alerts (Pro & Enterprise plan)

The Pro plan includes automatic delivery of CRITICAL and HIGH alerts to a Discord channel of your choice via webhook. To enable it:

  1. 1
    Create a webhook on your Discord server In your Discord channel for alerts → Channel settings → Integrations → Webhooks → New webhook. Copy the webhook URL.
  2. 2
    Paste the URL into your SkedAC dashboard Dashboard → Organization settings → Discord Webhook URL field. Save.
  3. 3
    Test with a match As soon as a HIGH or CRITICAL alert is triggered, a message appears automatically in your Discord channel with the player's name, the alert type and a link to the session.

Interactive Discord bot (Pro & Enterprise plan)

The SkedAC bot can be invited to your Discord server to let your staff supervise sessions in real time, directly from Discord — without accessing the dashboard.

🛡️

The bot exposes no sensitive data (no IP, no machine ID). It is designed for staff use without full admin access.

Available commands

Command Description Data shown
/check List of active SkedAC sessions Handle, match ON/OFF, module state (Secure Boot, VT-x/AMD-V, Memory Integrity (HVCI), Vulnerable Driver Blocklist, IOMMU/VT-d), open alerts

More commands will be added in upcoming versions of the bot.

  1. 1
    Invite the bot to your Discord server From your SkedAC dashboard → Settings → Discord Bot, click the "Invite the bot →" button. Accept the requested permissions on your Discord server.
  2. 2
    Enter your Discord Server ID in the dashboard The bot needs to know which SkedAC organization your Discord server maps to. Without this link, the bot can't respond to commands. In the dashboard → Settings → Discord BotDiscord Server ID field.
    To find this ID: enable developer mode in Discord (Settings → Advanced), then right-click your server icon → Copy Server ID.
  3. 3
    Configure who can use the commands By default, only Discord server Administrators can use /check. To open it to your staff, go to:
    Discord server settings → Integrations → SkedAC → click /check
    You can add authorized roles there (e.g. "Staff", "Referee") and restrict the command to specific channels (e.g. #skedac-staff).

🔐 Command permissions

SkedAC uses Discord's native permission system. By default, /check is reserved for server Administrators. Each org can then fine-tune access from Discord settings:

What you can configure How
Add an authorized role Integrations → SkedAC → /check → Add a role or member
Restrict to a channel Integrations → SkedAC → /check → Channel overrides
Block a role or channel Same menu → click ❌ on the role or channel
💡

Tip: create a private #skedac-staff channel for your team, then in /check permissions, add that channel as an authorized override and remove All channels. Only your referees will be able to run the command from that channel.

💳 Billing — How it works

The Community plan is free, with no credit card required. The Pro and Enterprise plans are monthly or annual subscriptions paid via Stripe, the secure payment solution used by millions of businesses.

ℹ️

After your access request, our team emails you a secure Stripe payment link. You pay online (credit card or SEPA transfer), and your plan is activated immediately after payment confirmation.

What's included in the price

  • Full access to the features of the subscribed plan
  • Hosting and maintenance of the infrastructure
  • Updates to the client software and dashboard — continuous and automatic, with no action required from you
  • Email support (priority on Pro, dedicated on Enterprise)

What's not included

  • Pay-as-you-go AI credits (add-on available separately)
  • Extra player slots beyond the plan limit (add-on available)

For any question about your invoice or subscription, contact hello@sked.gg.

Automatic renewal

SkedAC subscriptions are auto-renewing. Your card is charged automatically at each due date:

  • Monthly plan — charged the same day each month (e.g. subscribed on March 15 → charged April 15, May 15…)
  • Annual plan — charged once a year on the anniversary date

You receive a confirmation email at each renewal with the transaction summary and a link to your invoice.

⚠️

If a payment fails (expired card, insufficient funds…), Stripe makes 3 more attempts over 7 days. On persistent failure, your plan is downgraded to Community and you are notified by email.

Cancel or change plan

Cancel a subscription

To cancel your SkedAC subscription, send an email to hello@sked.gg with the subject "SkedAC subscription cancellation". We process requests within 24 business hours.

After cancellation:

  • Your plan stays active until the end of the period already paid
  • No pro-rata refund for the current period (except exceptional cases)
  • Your organization automatically switches to the Community plan at the due date
  • Your data stays accessible under the Community plan rules

Move to a higher plan (upgrade)

Contact us at hello@sked.gg. We create a new payment link for the pro-rata difference, and the new plan is activated immediately.

Move to a lower plan (downgrade)

Same process by email. The downgrade takes effect at the next billing date — you keep your current plan's features until then.

Switch to annual

If you're on monthly and want to switch to annual (to get the 33% discount), contact us. We cancel the monthly plan and issue an annual link, credited with the remaining pro-rata of the current monthly plan.

Invoices

Each payment automatically generates a PDF invoice sent to your account's email address. Invoices are issued by Sked and mention SkedAC as the product.

If you need:

  • An invoice with your VAT number or company details → write to hello@sked.gg with your information
  • To retrieve an old invoice → we send you the PDF on request
  • A specific format for your accounting → contact us
🔒

Payments are processed exclusively by Stripe. SkedAC never stores your card data. Stripe is PCI DSS Level 1 certified.

🔐 Windows security modules

SkedAC checks the state of 5 Windows security modules on the player's machine. Each module blocks a distinct family of cheat techniques — together they guarantee a fair gaming environment:

Module What it actually blocks
Secure Boot Checks the signature of components loaded at boot. Blocks bootkits / rootkits that install before Windows to evade antivirus.
VT-x / AMD-V Enables CPU hardware virtualization. Not a protection in itself — it's a hardware prerequisite needed for HVCI and kernel DMA protection.
Memory Integrity (HVCI) Isolates the Windows kernel and blocks unsigned or modified drivers. Defeats kernel cheats that want to write into game memory (kernel aimbots, triggers, real-time data manipulation).
Vulnerable Driver Blocklist (VDB) Blocks by hash a public list of signed but vulnerable drivers that cheats hijack (BYOVD technique = "Bring Your Own Vulnerable Driver"). Notably prevents ESP / wallhacks that read game memory via a hijacked legitimate driver.
IOMMU / VT-d (Kernel DMA Protection) Protects system memory against unauthorized direct access. Blocks attacks via external device (Thunderbolt DMA cards, external FPGAs).
💡

HVCI vs VDB — why both matter
Many confuse these two modules because the Windows interface groups them under "Core isolation". Technically, they are complementary:

HVCI blocks unsigned or modified drivers → stops kernel cheats that want to write to game memory (automated aimbots).
VDB blocks signed but vulnerable drivers → stops cheats that hijack a legitimate driver to read game memory (wallhacks / ESP).

Having HVCI enabled without VDB leaves the door open to modern BYOVD cheats. Both are necessary.

If a player has one of these modules disabled, SkedAC triggers an alert on connection. Most recent PCs already have them enabled — but some players will need to enable them manually in their BIOS or in Windows Security.

📖

Full step-by-step activation guide:
We wrote a detailed guide for each module, by motherboard brand, with illustrated BIOS steps.

→ Read the Windows security modules guide

Share this link directly with your players before the tournament — it is available in French and English.

ℹ️ Data retention

Data Community Pro Enterprise
Visible sessions 7 days 30 days Unlimited
Raw data (hw, processes) 2 days 7 days 30 days
Alerts Unlimited Unlimited Unlimited
Screenshots 48 hours 48 hours 48 hours

Technical FAQ

Does the software require administrator rights?

Yes, mandatory. SkedAC must be run as administrator — without admin rights, it won't start. Right-click the SkedAC shortcut → "Run as administrator". To avoid doing this every time, you can check "Always run as administrator" in the shortcut properties → Compatibility.

Does the software work with an antivirus?

SkedAC may be flagged by some antivirus software due to its system analysis capabilities (behavior similar to a monitoring tool). You can add an exception in your antivirus for the SkedAC.exe file.

What if a player can't connect?

Make sure the player is using the .exe file you distributed (and not an old version). If the issue persists, contact hello@sked.gg with the visible error message.

Does SkedAC work on Mac or Linux?

No. SkedAC is exclusively available for Windows 10 and 11 (64-bit), because the hardware and system analyses are specific to the Windows architecture.

A question not covered here?

Contact us at hello@sked.gg or join the Sked Discord — our team replies directly.