Skip to content
KTP

Keep the Practice · anti-cheat

Eyes on, hands off.

An external client that runs beside Day of Defeat: it records your session and uploads a tamper-evident bundle for human review, and it never reads, writes, hooks, or injects into the game. Your own uploads — screenshots, configuration files, and device inventory — you can read back yourself at My AC data.

Get the client

Getting in

If you are on a Season 10 roster your SteamID is already registered. Enable your first login here, then download the client, enter your SteamID and press First Login — it asks you to pick your own password. No admin, no waiting.

Not registered yet? Own Day of Defeat on the Steam account you play KTP with, then ask in the KTP Discord — an admin adds your SteamID, and can authorise the first login at the same time.

Rule 4.1.e requires it for every match you play. A match is covered when your session is running before it starts and still running when it ends. A crash, a disconnect or an outage is not a violation — tell an admin before your next match. Say something when it misbehaves too; most of the release history was written from exactly those reports.

How a session works

five steps, in order

  1. 1Get itKTPAntiCheat.exeDownload and run — nothing installs.
  2. 2Log inYour SteamIDRostered players are already registered — enter your SteamID and pick a password.
  3. 3StartStart SessionWith DoD running, before your match.
  4. 4PlayLiveThe session records.
  5. 5StopStop SessionThe bundle seals and uploads itself.

Forgot to click Stop? The session is packaged and uploaded anyway the next time the client runs — nothing is thrown away silently, and a crash mid-match does not read as dodging the anti-cheat, as long as you tell an admin before your next match.

What it does — and never does

a verified statement, not a promise · re-audited in full before every release ships

How it watches

these channels, nothing else

  • Screenshots of the game

    Through Windows.Graphics.Capture, the same out-of-process capture API OBS and Xbox Game Bar use. Capture is aimed at the game window; when a whole-monitor method has to be used as a fallback, the frame is cropped to the game window's rectangle.

  • Input, observed passively

    Read-only system hooks that pass every event straight through, plus mouse motion read from the device itself. Motion is recorded only while DoD holds focus, and what's kept is movement distance per 10 ms — not cursor positions.

  • Game files, read-only

    SHA-256 fingerprints of your DoD install compared against the league's known-good set, opened with a share mode chosen so the running game is never blocked.

  • Steam's own files — where DoD is, and which account you're signed in as

    Two reads, both outside the game folder. Steam's list of library folders is read to find where DoD is installed, and finding the install is all that is taken from it. And, new in 0.8.3, the client records which Steam account your machine is signed in as: Windows' registry entry for Steam's signed-in user, or, when Steam is signed out, the account number of whichever login Steam's remembered-logins file marks as most recent. Nothing else from that file is kept, and no other account listed in it is recorded. It exists because several players were set up under one SteamID and play on another, which is invisible while the only check is the SteamID you typed against itself; if the running account and the one you typed disagree, that is noted for an admin and never blocks your session or your upload. If Steam isn't running, or the value can't be read, the bundle records that we couldn't tell rather than recording agreement. The same read also runs once when you type your SteamID on the login screen, so the client can warn you there if Steam is signed in as someone else — that check keeps nothing and sends nothing.

  • Your peripheral software's config files

    Where you run vendor software for your mouse or keyboard — Logitech G HUB, SteelSeries GG, Razer Synapse, Wooting Wootility, Corsair iCUE, HyperX NGENUITY — the client copies that program's own configuration files into your session bundle, fingerprints them, and parses some of them on our server, so an admin can confirm which firmware features (SOCD, Snap Tap, macros) were active during a match. Those files can hold your macros, your button rebinds and your lighting profiles, and several are taken whole rather than read selectively. Vendor login tokens, browser cookies and crash dumps sitting in the same folders are excluded, and have not been collected since 0.7.1. Since 0.7.10 the vendor's RGB-lighting, audio-mixer and clip-recorder databases are excluded from that copy too — those were previously taken whole, and while a name and a hash of each still leave your machine like any other file in these folders, their contents no longer do. Also since 0.7.10, these folders are read regardless of the Windows file attributes set on the files in them: the same folders, the same file types, and the same size and count limits as before. Windows' own desktop.ini folder-display files are excluded by name. 0.8.0 completes that change in the last two places it had not yet reached. 0.8.1 adds HyperX NGENUITY, which had no scan target before, and stops walking Razer's newer app-engine folder in full — it is now listed one level deep, so less of it is read than before.

  • Process names

    What's running, by name and image path only, through the same metadata tier Task Manager uses. No memory handles, and the general scanners skip the game and Steam themselves.

  • Your machine's DNS lookup cache — no longer read

    Nothing is read here any more. 0.7.8 stopped storing the list, and the read itself was removed along with the collector shortly after — the client no longer asks Windows what you have resolved, so there is nothing to keep or upload. The entry stays rather than disappearing, because sessions archived before 0.7.8 still hold the hostnames they collected at the time, and you are entitled to know what is in them.

What it never does

zero hits, verified with positive controls

  • Reads or writes the game's memory
  • Injects code into the game or any other process
  • Hooks the game or its rendering — no DirectX or OpenGL interception
  • Opens a memory or module handle to the game process
  • Loads a kernel driver, or asks for admin rights — it runs as a normal user program and requests no elevation
  • Produces input — not one keystroke, click, or mouse move. It observes input; the APIs that would synthesize it are deny-listed and absent
  • Moves, resizes, focuses, or messages the game window — the one documented exception is the standard "draw yourself" request used as a last-resort screenshot method, the same call Snipping Tool uses
  • Launches or closes the game
  • Writes anything into your Steam, Half-Life, or DoD folders — every write lands in the anti-cheat's own directories

Between those two columns sit four narrow, documented touches — looking the game window up by its class name, then reading that window's rectangle and its style bits to aim the screenshot crop, plus the last-resort "draw yourself" capture request above. All four are read-only metadata through documented APIs; none involves game memory, and a test pins the exact call sites so a fifth cannot appear unnoticed.

Receipts, not reassurance: the statement behind this section is re-verified against every release by two independent whole-codebase audits, the build itself refuses to compile a deny-listed API, and the client's full native-call inventory is pinned so it cannot grow unnoticed. In 0.7.8 that surface shrank — a capture path was removed outright, the first time this client's system-level footprint has gone down.

Your data

collected only during a session you start · readable back by you

What a session uploads

One bundle per session: the screenshots, input-timing records, the process and driver inventory, the file-check report, and your DoD config files with server and RCON passwords redacted out before anything is bundled. The bundle is encrypted on your machine before it leaves, and it is tamper-sealed — if anything changes in transit, the server rejects it.

The server does not take the client's word for anything: every session is re-scored server-side from the raw evidence, so a tampered client cannot claim clean — and your legitimate session is judged from the same evidence a reviewer sees.

uploaded → re-scored on the server → flagged sessions read by a person → outcome

See it yourself

Sign in at My AC data with your client SteamID and password for a read-only view of your own uploaded sessions — screenshots, configs, device list — with a download button so you can keep your own copy. Your sessions only, never anyone else's, and never verdicts or detection detail.

Public setups opt-in

Off by default — you appear nowhere unless you turn Public profile on in the client. Opting in publishes your setup (resolution, netcode CVARs, sensitivity, peripherals) on the Setups directory; making it private again deletes your entry.

Common questions

the machine-behaviour answers come from the audited VAC-safety statement

Is it safe to run on my main Steam account?VAC

Yes — play on your normal account. The standing, audited statement: the client does not read, write, inject into, hook, or open a memory or module handle to the Day of Defeat / Half-Life game process. It interacts with the game through four channels only — screen capture via the same API OBS and Xbox Game Bar use, passive read-only input observation, read-only file hashing, and process-name enumeration.

That statement is re-verified against every release by two independent whole-codebase audits, run before the build is published, and nothing found contradicts it. VAC's concern is software that opens the game's process and memory; this client structurally never does.

Does it log my keyboard and mouse outside the game?input

The input hooks are Windows low-level hooks — system-wide by construction — and they are strictly read-only: every event is observed and passed straight through, never blocked, altered, or synthesized. Collection only happens during a session you start; the client's in-app disclosure panel lists exactly what is kept.

Mouse motion is read from the device stream and recorded only while Day of Defeat holds focus, as movement distance per 10 ms — not cursor positions. And the client never produces input of its own: the APIs that would (SendInput and friends) are deny-listed and appear nowhere in the shipped binary — it detects synthesized input, it never makes any.

Will screenshots show my desktop, second monitor, or other windows?capture

Capture is aimed at the game window. The client works down a ladder of capture methods, and the window-targeted rungs point at DoD's window specifically; when a whole-monitor method has to be used as a fallback, the client reads the game window's rectangle and crops the frame to it. No capture path injects anything or reads game memory — it's the same out-of-process mechanism screen recorders use.

I play exclusive fullscreen and my screenshots come back black. Is that a problem?capture

It's recorded honestly rather than ignored. On legacy exclusive-fullscreen OpenGL setups, every safe capture method can come up blind — since 0.7.8 the client records an honest "no frame captured" for those stretches, and that raises the session's coverage flags: a reviewer sees a gap in the visual evidence instead of a false clean pass. It is a coverage note for a human to weigh, not an accusation — and the file check reads your disk, not your screen, so it works the same in any display mode.

If you want your screenshots to actually land, run DoD borderless-windowed — the capture handles that natively. Add -window -noborder to DoD's launch options in Steam and set the in-game resolution to your desktop's.

Does it change anything on my PC?footprint

Its file access to your game is read-only — hashing, with a share mode chosen so the running game is never blocked — and zero writes, copies, moves, or deletes ever target the game tree. Every write lands in the anti-cheat's own locations: its update directory, its app data, and the session bundle.

It runs as a normal user program: no installer, no kernel driver, no elevation requested, no debug privilege. It never launches or closes the game.

Which files does it read?files

In the game tree: your DoD install is fingerprinted (SHA-256) against the league's known-good list. An unexpected DLL in the game directory gets its version metadata read — the same information Explorer's Details tab shows — and an unexpected or hash-mismatched file may be byte-copied into your session bundle so a human can look at it, rather than the client guessing.

The complete collection inventory — including the peripheral-software config files used to recognize your mouse and keyboard — is in the client's own disclosure panel (the "What we collect" button on the main window), which is corrected in step with every release.

Is the server watching me too?server-side

The game server scores some things on its side — for example, aim geometry derived from the ordinary network traffic the engine already requires to play. The client neither produces, reads, nor transports that data; nothing on your machine is touched for it. Server-side measures of that kind run measure-only, carrying no verdict weight, until they've been validated.

What happens if my session gets flagged?review

A flag is a request for human review, not a verdict. The server re-scores every session from the raw evidence, and a person reads every flagged session before anything happens. Legitimate hardware and setups trip detectors sometimes — Hall-effect keyboards, custom HUDs, sound mods — and the release history is full of exactly those cases being fixed in the detector, not held against the player. If a result looks wrong to you, ping a KTP admin in the Discord and they'll walk through the evidence with you.

How do I know my download is the real build?signing

Every release is Authenticode-signed with KTP's certificate — thumbprint 6CBE28B800C52073A27A3B6A4B7A2F07A7236A28 (right-click the exe → Properties → Digital Signatures). The root is KTP-issued rather than a commercial CA, so Windows may call the chain untrusted; that's expected. The enforcement is in the client itself: it pins that thumbprint and checks it on every update it installs, so a tampered or unsigned update is refused rather than applied. It does not re-check the copy already sitting on your disk, so on a build you did not get from this page, verify the signature yourself.

Why isn't the source code public?trust

Cheat-evasion prevention: public detector code is a study guide for the people it's meant to catch. What's public instead is the part that concerns your machine — the audited interaction statement this page is built on, re-verified every release. And the guarantees aren't just prose: the build gate refuses to compile a deny-listed API, and the client's full native-call inventory is pinned, so the surface can't grow without the change being declared and audited.

Can I play on a Mac?macOS

No — there is no macOS build to download. The client is published for Windows only; that is what the build and release scripts produce. Some macOS support exists in the source, but nothing is shipped, so there is nothing to install. VAC does not run on macOS either, and modern macOS needs a compatibility layer to run DoD at all. Play on Windows.

A question this page does not answer? Ask in the KTP Discord — specific concerns (“does it read X?”) get specific answers, and if the answer belongs here, it gets added.

Troubleshooting

the short list of known first-run snags

SmartScreen blocks the first launchexpected once

SmartScreen builds reputation from download volume, and this client is low-volume by design — so "Windows protected your PC" can appear even on the genuine signed build. Click More info, then Run anyway; it won't ask again. To check the build first, compare the signature thumbprint against the one in the download panel above.

Windows says the download "is not a valid Win32 application"download

Check the size of the file you downloaded before anything else. The download panel above lists what it should be — about a hundred megabytes. If yours is only a few kilobytes, an antivirus or a browser stopped the download partway and left you a fragment, and Windows reports a fragment as the wrong sort of program — so it reads like you were handed a build for the wrong kind of PC. You weren't. Delete what you have, allow the download in your antivirus, and fetch it again.

Upload fails or the bundle looks truncatedantivirus

Real-time antivirus scanning can grab the bundle while the client is still writing it. Add exclusions for %USERPROFILE%\Documents\KTP Anti-Cheat\ and %TEMP%\KTPAntiCheat\ — in Defender: Virus & threat protection → Manage settings → Exclusions. Other AV products have the same menu in roughly the same place.

"Update required" loops on every launchupdates

Re-download the current build from this page, replace your local KTPAntiCheat.exe, and restart it. If the loop persists, the update server isn't reachable from your network — ping a KTP admin in the Discord.

Login rejected: SteamID not registeredaccess

The SteamID is the one you type into the client — it isn't read from Steam, so a typo looks exactly like not being registered. Check it character for character against the ID you registered with; if it matches, ask in the KTP Discord and an admin adds you. After a failed login the button cools down for sixty seconds before you can retry.

My cursor disappears in DoDdisplay

The capture setting that could cause this has been off by default since 0.7.4. If it still happens, the usual culprits are a GPU-driver update or a multi-monitor setup — update or reinstall the driver, or run DoD borderless-windowed (-window -noborder). This is cosmetic; it never affects your result.

Elsewhere at KTP

your data, and what the field runs