PC monitoring notice · version 2026-08-12

Devil-Guard PC is player-side software. The desktop tools configure the installation; the DevilGuardSentinel Windows service performs the actual monitoring while the configured DFBHD process is running.

Game presence and approved executable

Sentinel checks that the configured DFBHD executable is running from the approved location and can compare the executable hash with approved builds.

Runtime hook checks

Selected Direct3D/runtime function bytes can be compared with expected values to identify unexpected redirection or hooking.

Runtime executable memory

Sentinel can compare executable sections of the running DFBHD image with the selected on-disk executable and inspect executable memory regions for code changes or unbacked executable allocations commonly associated with runtime injection. Normal monitoring reports detection signals and metadata, not arbitrary game-memory contents.

Loaded modules

Sentinel can inspect modules loaded into the DFBHD process and report unexpected module names, paths, hashes, publishers or signatures as protection signals.

Game-directory integrity

Approved baseline information can be used to identify new, modified or missing protected game files.

Signed device identity

Machine identity, Windows GDID/MachineGuid where available, a device signing key, challenge nonce and signed report help the website determine whether a report belongs to the registered device rather than trusting a plain text identifier.

Playing on another server

Core monitoring follows the local DFBHD process, not the current server. If Sentinel detects a DLL injection, runtime hook, suspicious module or other core protection signal while the player is using a non-Devil-Guard server, the signed detection can still be submitted and retained by the Devil-Guard website. Devil-Guard cannot enforce on that third-party server.

Enhanced evidence

Separate from core detection

Core protection can report a detection without collecting every enhanced evidence type. Enhanced evidence should be enabled separately and only for the categories the user/operator has chosen.

Possible evidence types

Depending on enabled settings, evidence can include a DFBHD-window screenshot, process minidump, detected executable/module copy, selected Windows-event information or a relevant running-process list.

Restricted access

Council review is redacted. Sensitive attachments and complete paths are Admin-only and attachment access is audited. After a final council decision, detailed case evidence is purged under the retention policy.

Important boundary

Devil-Guard Server does not scan a remote player’s computer and cannot derive a Windows GDID from an IP address. A verified GDID is available only when Devil-Guard PC supplies a signed device identity that the website accepts.

Graphics wrappers and proxy DLLs

Sentinel checks the configured DFBHD directory for common DirectX/OpenGL/input/sound proxy DLL names and known ReShade or dgVoodoo2 artifacts, including files that were already present before the game started. Loaded game-directory proxies are retained in signed module evidence, while Direct3D 8 and Direct3D 9 system export integrity is checked separately at runtime.