Game presence and approved executable
Sentinel checks that the configured DFBHD executable is running from the approved location and can compare the executable hash with approved builds.
Devil-Guard PC is player-side software. The desktop tools configure the installation; the DevilGuardSentinel Windows service performs the actual monitoring while the configured DFBHD process is running.
Sentinel checks that the configured DFBHD executable is running from the approved location and can compare the executable hash with approved builds.
Selected Direct3D/runtime function bytes can be compared with expected values to identify unexpected redirection or hooking.
Sentinel can compare executable sections of the running DFBHD image with the selected on-disk executable and inspect executable memory regions for code changes or unbacked executable allocations commonly associated with runtime injection. Normal monitoring reports detection signals and metadata, not arbitrary game-memory contents.
Sentinel can inspect modules loaded into the DFBHD process and report unexpected module names, paths, hashes, publishers or signatures as protection signals.
Approved baseline information can be used to identify new, modified or missing protected game files.
Machine identity, Windows GDID/MachineGuid where available, a device signing key, challenge nonce and signed report help the website determine whether a report belongs to the registered device rather than trusting a plain text identifier.
Core monitoring follows the local DFBHD process, not the current server. If Sentinel detects a DLL injection, runtime hook, suspicious module or other core protection signal while the player is using a non-Devil-Guard server, the signed detection can still be submitted and retained by the Devil-Guard website. Devil-Guard cannot enforce on that third-party server.
Core protection can report a detection without collecting every enhanced evidence type. Enhanced evidence should be enabled separately and only for the categories the user/operator has chosen.
Depending on enabled settings, evidence can include a DFBHD-window screenshot, process minidump, detected executable/module copy, selected Windows-event information or a relevant running-process list.
Council review is redacted. Sensitive attachments and complete paths are Admin-only and attachment access is audited. After a final council decision, detailed case evidence is purged under the retention policy.
Devil-Guard Server does not scan a remote player’s computer and cannot derive a Windows GDID from an IP address. A verified GDID is available only when Devil-Guard PC supplies a signed device identity that the website accepts.