guide · anti-cheat
How FiveM anti-cheat actually works
On FiveM, “anti-cheat” is not a single box. The client runs on the player’s machine, resource code is open, and no single tool can see every kind of cheat. What serious servers do is not hunt for one magic solution but stack layers that cover each other’s blind spots. This guide walks through those layers, what each one misses, and where the identity layer fits.
Why anti-cheat is hard on FiveM
The problem is architectural. The FiveM client runs on the player’s computer, which means the cheat software sits on the same machine, at the same privilege, as the defence. On top of that, most of the resources running your server are Lua and readable; an attacker can see exactly what they are playing against. This does not mean you are defenceless — it means there is no single wall you can install and forget.
The practical consequence: protection is a process, not a product. The four layers below are how real servers build that process. None is sufficient alone; together, they make a cheater’s job expensive and risky.
Four layers, and each one’s blind spot
Client-side detection
Resources that try to catch the cheat running on the player’s machine: mod menus, injectors, known signatures, abnormal function calls. It catches a great deal. Its blind spot: memory-only cheats, obfuscated injection, and an attacker reading the source and working around it. And because it runs on the machine, whoever controls that machine can work against it.
Server-side behaviour
Checks the server has authority over: impossible speed, teleporting, money or items the server never granted, events that should never be called. It is hard to bypass because it does not trust the client. Its blind spot: cheats that play “human” — light aim assist, exploits that stay near the rules — sit under the behaviour threshold.
Connect-time screening
A check performed as the player connects, before they enter the game. Unlike in-game detection, it looks not at what the person does this session but at who they are. It stops a known identity at the door. Its blind spot: it only catches identities it recognises — without an archive of history behind it, a new face is invisible to it.
Cross-server identity intelligence
The archive that gives connect-time screening its power. A single server’s own ban list knows only what it caught; the identity layer merges the records of many communities. Even if a player appears on your server for the first time, if they are banned elsewhere, carry a customer role in a cheat community, or are the alt of a banned account, this layer knows. Its blind spot: it only sees public traces in monitored communities; a cheater who has left no trace anywhere, it cannot see.
How the layers work together
The strength is in the overlap. A player who plays clean then turns cheats on is caught by client-side detection and behaviour checks. A player who is banned elsewhere and should be recognised the moment they connect is caught by the identity layer and connect-time screening — before the first shot. The first asks “what are they doing now”, the second “what did they do before”, and a cheater stays inside only if they can beat both at once.
So the right question is not which layer to swap for another, but which one is missing. Most servers already have the first two (a detection resource plus txAdmin/framework checks). What is usually missing is the third and fourth — because they require a shared archive that no single server can build on its own.
Where Argos fits — and where it does not
Argos is the third and fourth layers: identity intelligence and connect-time screening. Guard screens every connecting player against the archive — cross-server ban records, cheat-community memberships, customer and seller roles, alt-account clusters — and applies the action you choose: alert, kick, or reject the connection. The archive currently spans 400,000+ tracked identities and 110,000+ ban records, which is exactly the kind of data no single server can gather alone.
What Argos is NOT
Argos is not a client-side anti-cheat. It does not detect mod menus, injectors, memory tampering or aim cheats; nothing is installed on the player’s machine and it does not watch in-game behaviour. It does not replace the first two layers — it completes them. You still need a client-side detection resource and server-side behaviour checks on your server; Argos adds the history those layers structurally cannot see.
Which layer should you pay for
The decision to buy anti-cheat is usually made by asking "which is better", but the products do not do the same job. Work out which layer you are losing in first:
- "Cheats are still inside and never caught" → the missing layer is in-game detection. Client-side products (Electron, Phoenix AC, FiveGuard) are built for exactly that.
- "We banned them and they came back on a new account" → the missing layer is identity. Strengthening detection will not fix it; the new account looks clean because it is clean.
- "The same people keep circulating in our Discord" → the missing layer is entry screening; closing the game server still leaves the community open.
- "Two siblings connect from one house and keep getting flagged" → the missing layer is review: without an appeal path and an allowlist, every automated decision leaves permanent damage.
The layers do not replace each other; they run side by side. One server can run both in-game detection and a connect-time identity check — one catches cheating the moment it starts, the other stops a known player from getting in at all.
How detection actually works
Knowing what an anti-cheat does is knowing what its result proves. There are four mechanisms, and every one has a known blind spot. Cfx.re’s own security guide states the same limit: client checks can easily be overridden, which is why the value sits in server-side verification.
- Client-side memory and signature scanning: reads processes and known cheat signatures on the player’s machine. Blind spot: cheats that live only in memory with an unknown signature are invisible, and the client is under the player’s control.
- Server-side behaviour analysis: reads impossible movement, abnormal damage and event calls from server data. Blind spot: a cheat used slowly and carefully leaves no behavioural trace.
- Event and trigger verification: blocks protected events from being called by a cheater. Blind spot: it covers protected events only; anything not on the list stays open.
- Pre-join and identity checks: gather data about the player at connect time and match it against past records. Blind spot: a cheater with no record is invisible, and records only come from communities that share them.
That is why "which anti-cheat is best" has no single answer: each mechanism sees a different kind of cheat and misses a different kind. The useful question is which kind dominates on your server.
Frequently asked
Is there a single anti-cheat that is enough on FiveM?
No. The FiveM client runs on the player’s machine and resource code is open even on the server side; no single layer can see every kind of cheat. Serious servers solve it with layers: client-side detection, server-side behaviour checks, connect-time screening, and cross-server identity history. Each layer covers another’s blind spot.
Is Argos a client-side anti-cheat?
No, and the distinction matters. Argos does not detect mod menus, injectors, memory tampering or running processes; nothing is installed on the player’s computer. Argos is the identity layer: it screens a connecting player against cross-server ban records, cheat-community memberships and alt-account links. If you want client-side detection, separate resources exist for that; Argos does not replace them, it runs alongside them.
I already run txAdmin and a detection resource — what does Argos add?
txAdmin and detection resources look at the player’s current session — what is running on the machine, how they behave in game. Argos looks at the player’s history before the session: are they banned on other servers, do they hold a customer role in cheat-selling communities, are they the alt of a banned account. One sees the present, the other the past. The first catches a player who plays clean then turns cheats on; the second catches the one who should be recognised the moment they connect.
Does connect-time screening slow players down?
Argos Guard screening runs during the connection handshake and the decision is measured in milliseconds — players do not notice it. For a player over the threshold you choose the action: alert only, kick, or reject the connection. A rejected player never enters the server, so there is no in-game delay either.
Which layer catches someone who bought a cheat but was never banned?
Client-side detection cannot — they may not have turned the cheat on yet. A ban list cannot — they have not been caught yet. The only trace that makes them visible is the customer role in the cheat sellers’ Discord, and that shows only at the identity layer. That is why Argos reads those roles.
Can FiveM anti-cheat be bypassed entirely?
Any single layer can always be bypassed: client-side detection by memory-only cheats, behaviour checks by careful play, a single server’s ban list by a fresh account. Stacking layers does not make bypass impossible, but it makes it expensive — and the identity layer is the hardest to beat, because a new Discord account cannot rewrite its history, its alt links or its customer roles.
Does FiveM have anti-cheat?
Yes — Cfx.re has its own anti-cheat team and server-side protections. On FXServer build 8450 and above most of them are enabled by default: a connection check that verifies client settings and pure level, a filter blocking control-request routing, trust and variance thresholds for identity providers (`sv_authMinTrust`, `sv_authMaxVariance`), and the CnL check that kicks a player who falls out of the timeout window. There is also a global ban list applied for violations.
What are the FiveM anti-cheat options?
There are three groups. In-game detection products catch cheat software while it runs and ship an admin panel. Verification or prevention layers check a player before they join (VPN, account age, precheck lists). The identity layer looks at a player’s cross-server history. We keep the product-by-product comparison on /alternatives, and we only state a vendor’s price when it could be read from their own site.
How does FiveM anti-cheat detect cheats?
The mechanism depends on the layer. Client-side detection reads processes, memory layout and known cheat signatures on the player’s machine. Server-side behaviour checks read impossible movement, abnormal damage and event calls from server data, trusting nothing the client claims. Precheck layers gather data about the player at connect time (VPN, account age). The identity layer ignores behaviour entirely: it matches identifiers against past records. Knowing which one is in use determines what a result actually proves.
Is FiveM anti-cheat worth paying for?
If cheating is a real problem on your server, yes — provided you pay for the right layer. If the recurring complaint is "they were banned and came back on a new account", the problem is identity, not detection, and another detection system will not fix it. If the complaint is "cheats are still inside and never caught", what is missing is in-game detection. Work out which layer you are losing in first; the two can run together.
Related: Argos Guard — connect-time screening · Pre-whitelist vetting · Player lookup · Alt account detection · Banned on other servers? · Protection layers and comparisons
Source: Cfx.re — Secure Your Events