FiveM anti-cheats explained: what servers run and what they look for
By the SERYX team · Published · 7 min read
Short answer
Client-side vs server-side anti-cheat
Anti-cheat checks run in one of two places.
| Client-side | Server-side | |
|---|---|---|
| Where it runs | On the player's PC, alongside the game | On the server (FXServer) |
| What it checks | The game client itself, such as code injected into it | What the client asks the server to do: events, spawned entities, position, money, items |
| Limitation | Runs on hardware the player controls | Only sees what reaches the server |
| FiveM example | Cfx.re's built-in anti-cheat | Checks in server scripts; Cfx.re's server settings |
Cfx.re's security guide for server developers makes the same split. Checks on the client help, but a cheating client can override them, so values that matter, like money, inventory, position and permissions, should be read on the server instead of taken from the client.
Third-party anti-cheats blur the line. They're installed as a server resource, and a FiveM resource can contain client scripts, which are loaded on each player's game, as well as server scripts. So most of them check on both sides. Each of the five described below is installed by the server owner as a resource on the server.
What FiveM itself does
Cfx.re runs its own anti-cheat; its developer docs call the team and the client component Adhesive. Its ban FAQ says the automated system detects external programs that try to inject into the FiveM or RedM client, and bans the linked account from both. That's the global ban.
Not every detection is a ban. The "Game integrity check failed" error means the anti-cheat found an anomaly in the game process and closed the game. Cfx.re says this doesn't mean you're banned. It suggests removing cheat software (even for other games), mods in the FiveM or GTA V folders and recently installed software that might interfere, then running an antivirus scan.
Cfx.re also gives server owners settings. The documented ones include:
- Pure mode (sv_pureLevel). Level 1 blocks modified client files except audio files and known graphics mods. Level 2 blocks all modified client files.
- Entity lockdown (sv_entityLockdown). Controls which entities clients may create: "relaxed" blocks script-owned entities created by clients, and "strict" blocks every client-created entity.
- Control-request filtering (sv_filterRequestControl). Can stop clients taking control of entities other players control, such as occupied vehicles.
- Event routing switches. Options to stop clients routing networked sounds, phone explosions and script entity state changes through the server. The docs say malicious players commonly abuse these.
- Backend check-ins. Settings that kick players whose game loses its connection to Cfx.re's CnL service for too long, and one that verifies server settings such as pure level through the anti-cheat. Cfx.re notes that a kick from these checks isn't automatically a global ban.
- Replay restriction (sv_disableClientReplays). Meant to reduce cheating options. It also disables the Rockstar Editor.
Cfx.re is open that its anti-cheat isn't the whole answer. Its security guide starts by saying the team keeps improving the anti-cheat but "sometimes things slip through", and that cheats can trigger events from the client. It tells developers to register networked events correctly and to check every request on the server. Its ban FAQ also asks anyone who has the files for a cheat they think is undetected to send them to Cfx.re support.
Third-party server anti-cheats
Because things slip through, many servers add their own anti-cheat. Below are five well-known ones, each described from its own website or documentation. We haven't tested them, features vary by plan and version, and the vendors' own descriptions are all we're going on. FiniAC, for one, deliberately doesn't publish a full list of its detections.
FiveGuard
FiveGuard's documentation centres on server events. Its Safe Events system adds a token to server events so the server can check that each call came through FiveGuard, and it can blacklist triggers and rate-limit how often an event fires. It also has a resource protection command aimed at Lua injection, entity, explosion and particle detections, an in-game admin menu, and server exports that take a screenshot or a screen recording of a player. Its configuration is stored in the cloud, and bans are kept with a ban ID.
WaveShield
WaveShield's documentation describes automatic protection for client and server events, which currently covers scripts written in Lua, and a function developers can call to check whether a client-side action, such as spawning an object, was executed legitimately. It whitelists networked objects, so a networked object that isn't on the list leads to a ban. It has a web configuration panel, ban and unban commands that work by ban ID, ban records that can include an evidence link and the player's identifiers, and optional IP bans, which its docs say to turn off on servers behind proxies.
Electron Anticheat
Electron describes itself as a server-side anti-cheat installed as a FiveM resource and managed from a cloud dashboard. It lists detection modules for aimbot, ESP, noclip, god mode, teleporting, speed changes, vehicle modifiers, weapon injection, cheat menus, explosion exploits, VPN use and server crash attempts. Its staff tools include a web panel, an in-game admin menu, a live map, watching several players' screens at once, session replay on some plans, and a player lookup across every server that runs Electron.
FiniAC
FiniAC describes event security for a server's economy, aimed at attempts to spawn items, duplicate rewards or inject in-game money, plus an entity firewall with allow and deny rules for spawned vehicles, peds and objects, and detections tuned for aimbot and silent aim. When a player connects, it rates them with a TrustScore built from more than 30 variables, and it links accounts that share identifiers, IP addresses, names or hardware IDs. Staff get a web panel, player screenshots, and on higher plans detection video clips and live streams of up to 16 players. Bans can be local to one server or global across FiniAC servers.
Reaper AntiCheat
Reaper describes network-level event protection that blocks spoofed triggers and event abuse before they reach a server's scripts, and aimbot detection based on movement and aim analysis. It says every detection is recorded as a video, kept as evidence for ban appeals, and that staff can watch players' screens live from its web panel. Servers install it as a resource called ReaperV4.
| Anti-cheat | Type | What its site says it focuses on | Staff tools it lists |
|---|---|---|---|
| Cfx.re (built in) | Client-side, in every FiveM client, plus server settings | Programs injecting into the game client; modified game files; some networked events | Global bans; server settings |
| FiveGuard | Server resource with client-side checks; cloud config | Event protection (Safe Events), trigger blacklists and rate limits, Lua injection, entities, explosions, particles | Admin menu, screenshots and screen recordings, ban IDs |
| WaveShield | Server resource with client-side checks; web config panel | Automatic event protection for Lua scripts, execution checks, networked-object whitelist | Ban and unban by ID, evidence links, optional IP bans |
| Electron | Server-side resource; cloud dashboard | Aimbot, ESP, noclip, god mode, teleport, speed, weapon injection, menus, explosions, VPNs, crash attempts | Web panel, in-game menu, live map, screen monitoring, session replay, cross-server lookup |
| FiniAC | Server resource; web panel | Economy event security, entity firewall, aimbot and silent aim, TrustScore, linked accounts | Screenshots, detection clips, live streams of up to 16 players, local and global bans |
| Reaper | Server resource; web panel | Network-level event protection, aim and movement analysis | Video of every detection, live screen view |
What they look for, in plain terms
- Events. FiveM scripts talk to the server through events. Cfx.re's guide warns that cheats can trigger them, so an event that pays out money or gives items is a target. Four of the five products above describe event protection.
- Entities. Vehicles, peds, objects, explosions and particle effects created by a client, checked against whitelists or rules.
- Injected code. Code running in the game that didn't come from the server's own resources, such as Lua injection.
- Behaviour. Movement and aim that don't fit normal play: noclip, teleporting, god mode, speed changes, aimbot.
- Identity at the door. VPN checks, IP bans, trust scores and linked accounts, so a player banned once is recognised again.
What server staff do on top of software
Software flags; people decide. On roleplay servers, staff are usually the last step.
- Reports. Players report each other, usually with a ticket in the server's Discord, often with a clip attached.
- Clips and streams. Plenty of players record or stream their sessions, and staff review that footage.
- Spectating and logs. txAdmin's in-game menu lets admins spectate and freeze players, and its activity log records joins, kills, chat and explosions.
- Screenshots and live views. Cfx.re's screenshot-basic resource lets a server script capture a player's game view. The anti-cheats above add screenshots, recordings, live screen views and replays.
- PC checks. Some servers' rules let staff ask a suspected player to join a voice call and share their screen while staff look at running programs and files. This happens outside FiveM and outside any anti-cheat. Whether a server does it, and what happens if you refuse, is up to that server's rules.
Vendors build human review into their ban lists too. FiniAC's staff review the evidence before a server's local ban becomes a global one, and Reaper keeps detection videos for appeals. FiveM bans explained covers the kinds of ban and how appeals work.
Where SERYX stands
We don't claim SERYX is undetected by, or bypasses, any anti-cheat on this page. Detections change, and no menu can promise you won't be banned. The status page shows which SERYX products are working and on sale right now, and the changelog lists every update with its date.
We checked every source below on 8 October 2026. FiveGuard and WaveShield are described from their documentation sites. Vendor descriptions are what each vendor says about its own product; we haven't tested them.
Sources
- Cfx.re Support: FiveM/RedM Community Server Ban FAQ
- Cfx.re Support: Game integrity check failed error in FiveM
- FiveM docs: Secure Your Events (server security guide)
- FiveM docs: server commands (sv_pureLevel, sv_entityLockdown, sv_filterRequestControl and others)
- FiveM docs: resource manifest (client_script, server_script)
- Cfx.re on GitHub: screenshot-basic
- txAdmin: README (in-game menu, activity log)
- FiveGuard docs: Manual Safe Events
- FiveGuard docs: Events (blacklisted triggers, rate limiter)
- FiveGuard docs: Resource protection
- FiveGuard docs: Server-side exports (screenshots, screen recording)
- FiveGuard docs: Server commands (bans, entity logs)
- FiveGuard docs: FAQ
- WaveShield docs: Trigger client/server events
- WaveShield docs: WaveShieldAPI.IsValidExecution
- WaveShield docs: Objects
- WaveShield docs: Exports (ban records)
- WaveShield docs: Commands
- WaveShield docs: I get other ban than mine (IP bans)
- Electron Anticheat: homepage
- Electron Anticheat: FAQ
- Electron Anticheat: product summary (llms.txt)
- FiniAC: homepage
- FiniAC docs: Bans
- FiniAC docs: TrustScore
- FiniAC docs: Entity Firewall
- FiniAC docs: Identities
- Reaper AntiCheat: homepage