Evidence and Investigations
Good anti-cheat administration depends on evidence quality.
Alerts are not verdicts
An alert means that behaviour met a reporting or enforcement condition. It does not always mean the player cheated.
Possible alternative explanations include:
- Lag
- Desynchronisation
- Administrative tools
- Custom scripts
- Incorrect integrations
- Resource restart behaviour
- Server performance problems
- Legitimate high-intensity gameplay
Evidence to review
Where available, review:
- Detection category
- Timestamp
- Player identifiers
- Position
- Repeated events
- Strike history
- Risk-score changes
- Combat context
- Entity ownership
- Economy or inventory timeline
- Staff notes
- Server console logs
- Relevant gameplay footage
Confidence through correlation
Confidence improves when independent signals support the same conclusion.
For example, suspicious combat behaviour may be more meaningful when accompanied by:
- Repeated no-line-of-sight patterns
- Abnormal accuracy over time
- Prior related alerts
- Consistent staff observation
- Matching server logs
Recommended decision standard
For severe action:
- Verify that the alert is not explained by a known resource.
- Look for repetition.
- Compare multiple evidence sources.
- Preserve the timeline.
- Record the staff rationale.
- Apply the least disruptive appropriate action first where practical.
False-positive review
When a legitimate action triggers protection:
- Record the exact workflow.
- Identify the responsible resource.
- Reproduce it in testing.
- Adjust configuration or integration narrowly.
- Avoid globally disabling an entire protection layer unless necessary.