Every serious HWID spoofer advertises itself as "kernel-level". Cheap ones run in usermode and quietly fail against modern anti-cheat. The difference between the two decides whether a spoofer actually hides your hardware or just changes what a few Windows tools display.
This guide explains what kernel-level means, why Easy Anti-Cheat, BattlEye and Vanguard can only be fooled at that level, how a spoofer driver works in plain terms, and what to check before you buy one.
Kernel Mode vs User Mode in 30 Seconds
Windows runs code at two main privilege levels, often called rings:
- User mode (ring 3): where normal apps run, including your browser, Discord and the game itself. Apps here can only see what Windows lets them see.
- Kernel mode (ring 0): where Windows itself and hardware drivers run. Code here talks to the hardware layer directly and can see and control everything above it.
The key point: anti-cheat runs in the kernel. Easy Anti-Cheat, BattlEye and Riot Vanguard all load kernel drivers. Anything running at a lower privilege than the anti-cheat can be seen past.
Why Usermode Spoofers Fail
A usermode spoofer changes values that ordinary programs read, for example by editing registry entries or intercepting calls inside user-mode processes. That can make a basic system info tool show new numbers.
But a kernel anti-cheat doesn't ask those programs. It queries the hardware information from the kernel side, below where the usermode spoofer operates, and gets the real values. Result: your "spoofed" PC still matches the banned fingerprint.
If a spoofer has no driver, it's usermode, and kernel anti-cheat will read straight past it. That's the most common reason "my spoofer worked but I got banned again".
How a Kernel Spoofer Works
A kernel spoofer loads its own driver, so it runs at the same level as the anti-cheat. From there it can intercept the requests made for hardware identifiers and answer them with spoofed values before the real ones are returned.
| Usermode Spoofer | Kernel Spoofer | |
|---|---|---|
| Runs at | Ring 3, like a normal app | Ring 0, as a driver |
| What it changes | What apps and some tools see | What the system reports, including to kernel anti-cheat |
| Against EAC / BattlEye / Vanguard | Read past | Can hide real identifiers |
| Setup | Simple | Needs admin rights and compatible security settings |
| Risk if badly made | Low | Crashes (BSOD) or conflicts with other drivers |
What a Kernel Spoofer Should Cover
- SMBIOS: motherboard serial, system UUID and BIOS details.
- Disk serials: answered at the storage driver level, not just the Windows volume ID.
- MAC address for every network adapter.
- GPU identifiers.
- Trace cleaning for the files, registry entries and logs anti-cheat left behind.
You can check whether all of these actually changed with built-in commands. See how to check your HWID.
Kernel Spoofers and Windows Security Settings
Because a kernel spoofer is a driver, it interacts with Windows security features that control which drivers may load, such as Secure Boot and Memory Integrity (part of Core Isolation). Different spoofers have different requirements, and different games have their own requirements too: Valorant on Windows 11, for example, requires Secure Boot and TPM 2.0 to be on.
The rule is simple: follow your spoofer's setup instructions for your specific game, and get help from its support team if your settings conflict. Our beginner's setup guide covers the general process and common errors.
Kernel Spoofer Red Flags
- No driver at all but claims to be "kernel-level".
- No support channel. Kernel software that breaks can crash your PC, and you'll want help.
- No updates after anti-cheat changes.
- Partial coverage, such as disks only or MAC only.
- Free downloads from forums or file hosts. A random kernel driver is the most dangerous thing you can install. Gaming tools are among the most common disguises for malware.
Kernel vs Permanent: Different Questions
"Kernel vs usermode" is about how a spoofer hides your IDs. "Permanent vs temporary" is about whether the change survives a reboot. The best setup for most players is a temporary kernel spoofer: full-strength spoofing with nothing written to your firmware. Read permanent vs temporary HWID spoofers for the full comparison.
TATEWARE HWID Spoofer: Kernel-Level
Kernel-level spoofing of SMBIOS, disks, MAC and GPU with full trace cleaning, for EAC, BattlEye and Vanguard games. Discord support for setup. From €5.99 for 3 days.
Get the SpooferFrequently Asked Questions
What is a kernel spoofer?
An HWID spoofer that runs as a kernel driver (ring 0), the same level as anti-cheat, so it can hide your real hardware identifiers from EAC, BattlEye and Vanguard.
Do usermode spoofers work?
Not against kernel anti-cheat. They change what normal apps see, but the anti-cheat reads your real values from the kernel side.
Can a kernel spoofer cause a blue screen?
A badly made or outdated one can, because it runs as a driver. That's why updates and support matter when choosing one.
What does ring 0 mean?
Ring 0 is kernel mode, the most privileged level where Windows and hardware drivers run. Ring 3 is user mode, where normal applications run.
HWID spoofer guides by game: Fortnite · Apex Legends · Rust · R6 Siege · PUBG · Valorant · Escape from Tarkov · DayZ · ARK · Squad · Elden Ring · Halo Infinite · Palworld · Naraka: Bladepoint
Bottom Line
Against kernel anti-cheat, only a kernel spoofer can hide your real hardware. Make sure it has a real driver, covers SMBIOS, disks, MAC and GPU, cleans traces, stays updated and comes with support, and confirm it worked by checking your IDs before you play.
Setup questions? Ask in the TATEWARE Discord.