Handling a cheater well is three steps done in order: confirm it with evidence you can show someone else, ban by the identifier that is hardest to replace (the platform account, not the name and usually not the IP), and record the ban with its reason somewhere that survives a reinstall. Most server owners do the middle step first, from a report in chat, and then find they cannot defend the ban, cannot make it stick against the second account, or lose the list in the next migration. The commands are easy; the order is what matters.
This post is the practical side: spotting, recording, banning, evasion and appeals, with the ban commands and files for the common games. The policy questions - what your rules say, how many staff you need, the warn-kick-ban ladder - live in server rules, moderation and staff. What the anti-cheat does and does not do for you is in BattlEye and Easy Anti-Cheat on servers.
Confirm before you act#
A report is a lead, not a verdict. Good players get reported as cheaters constantly, especially by the people they just beat, and a wrong ban on a regular costs you more than a missed cheater.
Signals worth taking seriously:
- Information they should not have. Pre-firing corners nobody could see, tracking a target through walls, digging straight to diamonds, finding hidden bases on the first night.
- Mechanics that are impossible, not just good. Snapping onto heads at inhuman speed, moving faster than the game allows, flying, never missing at range.
- Consistency across sessions. One unbelievable round is luck. The same pattern over a week is not.
- Several independent reports. Three unrelated players reporting the same behaviour is worth more than ten messages from one angry person.
Signals that are weak on their own: a high kill-death ratio, a new account, a name that sounds like a cheat brand, "everyone says so". Use them as reasons to watch, not reasons to ban.
The most reliable method is still to watch the player yourself, without them knowing. Spectate in vanish where the game allows it (Minecraft spectator mode or a vanish plugin, Rust's spectate, Source spectator slots), or review a recording afterwards. Watch for at least a few minutes of ordinary play, not just the moment in the report.
Making player reports useful
Most cheaters are found by players, not staff, so the quality of reports decides how much work each one costs you. A report that says "Steve is hacking" sends an admin hunting through an hour of logs; a report that says "Steve, around 21:10, round three on the second map, shot me through the wall at B" points at a demo timestamp.
- Ask for time, place and what happened. A short template pinned in your report channel or a
!reportcommand that captures the reporter, the target and the server time does most of the work. - Record the server time, not the reporter's local time. Players in different time zones report in their own time, and the logs are in the server's.
- Acknowledge every report, even with a one-line "looked at it, not enough to act on". Players who feel ignored stop reporting, and then you only hear about cheaters when the server is already empty.
- Never act on a report from a rival in the middle of a match. Look at it afterwards, calmly, with the recording.
SourceMod, Rust, FiveM and Minecraft all have plugins that add an in-game report command and post it to a staff channel with the server name and time attached, which is the cheapest improvement you can make here.
Evidence that survives an appeal#
An appeal is easy to answer when you can say "here is the recording at 21:14". It is miserable when you cannot. Capture evidence before you ban, because the moment a cheater is banned they stop producing it.
| Game | Built-in evidence | Common additions |
|---|---|---|
| CS2 and Source games | Server demos with tv_record | Demo review in game, admin plugin logs |
| Minecraft | Server log, commands | CoreProtect block and container history |
| Rust | Server log, combat log | Logging and report plugins |
| FiveM | Server console | txAdmin action log, screenshot resources |
| DayZ, Arma 3 | Admin log, BattlEye logs | Admin tool kill feeds with positions |
| Survival games generally | Server log | Screen recordings from staff |
On Source games and CS2, a server-side demo is the best evidence there is, because it can be watched from any player's perspective, including through walls. With SourceTV or GOTV enabled, tv_record <name> starts a recording and tv_stoprecord ends it; the .dem file lands in the game folder. CS2 GOTV and demos covers setting it up so recording is automatic rather than something an admin has to remember.
On Minecraft, CoreProtect turns "they found every diamond in an hour" into a query:
/co lookup user:Steve time:3d action:-block include:diamond_ore,deepslate_diamond_ore/co lookup user:Steve time:1d action:+container/co inspectThe first line lists every diamond ore they broke in three days with coordinates, which, set against the tunnels they dug to get there, is usually conclusive for x-ray. The second shows what they took from chests. Grief protection and anti-cheat for Minecraft covers the plugin and Paper's anti-xray.
Whatever the game, write the evidence down when you make the ban: who, what, when, the file or timestamp that shows it, and who decided. A ban without a recorded reason is one you will not remember the details of in three months, when the appeal arrives.
Choosing what to ban: account, IP or hardware#
Every ban targets an identifier, and the identifier decides how easy the ban is to evade and how much collateral damage it does.
| Identifier | Evasion cost | Collateral risk |
|---|---|---|
| Player name | Zero - change the name | High - someone else may pick it |
| Platform account (SteamID, UUID, licence) | Buying or borrowing another account | Low |
| IP address | Restart a router, use a VPN | Can hit a household, school or carrier |
| Hardware ID (where available) | Spoofing tools, new hardware | Can hit a shared PC |
Ban the platform account by default. It is what the game authenticates, it is cheap to apply, and it costs the cheater real money or effort to replace when the game is paid. Free-to-play games make account bans weaker, because a new account costs nothing; that is where IP and hardware identifiers earn their place.
Use IP bans as a temporary measure against an active evader, not as a permanent record. Home addresses change, mobile carriers put thousands of users behind one address, and a permanent IP ban can lock out an innocent family member or a whole student residence. If a game offers it, a time-limited IP ban alongside a permanent account ban is the sensible combination.
Never ban by name alone. On most games a name is a display label anyone can take.
Ban commands and files by game#
The vanilla commands are enough for a single server. For a network, or for temporary bans on games that do not support them natively, you will want a plugin - covered in global ban systems for communities.
| Game | Ban | Unban | Stored in |
|---|---|---|---|
| Minecraft | /ban <player> [reason], /ban-ip | /pardon, /pardon-ip | banned-players.json, banned-ips.json |
| Source (TF2, GMod, L4D2) | banid <minutes> <id> then writeid | removeid | cfg/banned_user.cfg |
| SourceMod | sm_ban <target> <minutes> [reason], sm_addban | sm_unban | Its database or the files above |
| Rust | banid <steamid> "name" "reason" | unban <steamid> | Saved by server.writecfg |
| Valheim | ban <name or ID> | unban <ID> | bannedlist.txt |
| 7 Days to Die | ban add <id> <duration> <unit> [reason] | ban remove <id> | Server admin file |
| Project Zomboid | /banuser "name" -ip -r "reason", /banid | /unbanuser, /unbanid | Server database |
| FiveM | txAdmin ban with duration | txAdmin | txAdmin database |
Some details that trip people up:
- Minecraft has no temporary bans in vanilla.
/banis permanent until/pardon. Plugins such as EssentialsX add/tempban, and ban plugins add durations, reasons and history. Vanilla bans are stored by UUID, so they survive a name change. - Source games keep bans in memory until you write them.
banid 0 STEAM_0:1:12345bans permanently but is lost at restart unless you runwriteid, andserver.cfgneedsexec banned_user.cfgandexec banned_ip.cfgto load them back. SourceMod'ssm_banhandles this for you. - Rust writes bans to the server's config folder only when
server.writecfgruns. Run it after a ban, or schedule it. - 7 Days to Die takes a duration and unit, such as
ban add Steve 7 days "x-ray", which makes graded bans easy. - FiveM bans through txAdmin record every identifier the player had, including hardware tokens, which makes evasion harder than on most games. FiveM server and txAdmin covers the panel.
On RE:NODE every one of these runs from the panel console, so a ban can be issued without the admin being in the game, and the ban files are ordinary files you can download, edit and back up from the file manager.
Ban evasion and alternate accounts#
A cheater who cares will come back. The signs are familiar: a new account that plays exactly like the old one, joins at the same times, knows things a newcomer would not, and heads straight for the same friends or the same base.
What helps:
- Check the IP history. Many admin plugins and frameworks log the address each account connected from. A banned account and a new one from the same address within a day is a strong signal - though not proof, since households share addresses.
- Check platform account age and history. On Steam, a profile created yesterday with one game and no friends, joining an hour after a ban, is worth a look. Some games and plugins can also check whether a game was borrowed through Steam Family Sharing, which is a common way to play from a fresh account.
- Use hardware identifiers where the game provides them. FiveM's are the best-known example.
- Gate trusted features behind playtime. Kits, ranks, base claims and voice access that unlock after some hours make a fresh account much less useful to an evader.
- Ban the new account for evasion when the evidence is clear, and record the link between the two.
What does not help is banning broad IP ranges or entire countries. It mostly punishes people who did nothing.
Keeping ban lists for the long run#
Ban lists are data, and they get lost the same ways other data does: a reinstall, a migration to another host, a wipe that deleted more than it should, a plugin swap that did not import the old database.
- Back up the ban files with everything else.
banned-players.json,bannedlist.txt,banned_user.cfg, the plugin database. Backup slots are on every RE:NODE plan and can be scheduled, so this happens without anyone remembering. - Keep reasons and evidence references with the ban. "Cheating" is not enough six months later; "x-ray, CoreProtect query 2026-10-03, see evidence folder" is.
- Export before you change ban plugins. Most ban plugins can import from vanilla lists or from each other, but only if you have the old data.
- Review temporary bans. A list where every ban is permanent fills up with people who would have behaved after a week.
Moving ban lists to a new server or host
The ban list is one of the things people forget to bring when they move. A world gets copied carefully, and the next day a cheater banned a year ago is back. Before any migration, list the ban data for your game and copy it with the world:
- Vanilla files -
banned-players.jsonandbanned-ips.jsonon Minecraft,bannedlist.txton Valheim,banned_user.cfgandbanned_ip.cfgon Source games, the server'scfgfolder on Rust. - Plugin databases - a ban plugin with a database needs a dump of that database, not just its config file. Database backups and restores covers taking one.
- The evidence folder, so appeals after the move can still be answered.
After the move, test it: try to join with a banned test account if you have one, or check that the ban count in the plugin matches the old server. Moving a server without losing players covers the rest of the move.
Appeals without drama#
An appeals process is how you correct your own mistakes, and having one makes the bans you keep more credible.
- Make it one channel. A form, a Discord ticket or an email address - not DMs to individual staff.
- Answer with the evidence you recorded. If the evidence is clear, say so briefly and close it. If it is not, lift the ban; the cost of a wrong ban to your community's trust is higher than the cost of one cheater.
- Have someone other than the banning admin decide. It keeps the process fair and protects the admin from accusations.
- Do not debate cheat detection details. Explaining exactly what gave someone away teaches the next one what to avoid.
- Say what you cannot overturn. Anti-cheat global bans, VAC bans and developer bans are not yours. Point the player at the right place and close.
FAQ#
Should I ban for the first offence or warn?
For confirmed cheating, a ban. Warnings are for rule-breaking that a player can stop doing; cheating is a deliberate choice that takes effort. A temporary first ban with a permanent second one is a reasonable middle ground on casual servers.
Is a kill-death ratio enough evidence?
No. It is a reason to watch, not to ban. Many legitimate players have extreme statistics, and many cheaters keep theirs deliberately ordinary. Base bans on what the player did, shown in a recording or log.
Why did a player I banned come straight back?
You banned the name or IP instead of the account, a Source ban was never written to disk with writeid, or a Rust ban was lost because server.writecfg was not run. Otherwise, they are on a second account, which is an evasion case.
Should I publish a public list of banned cheaters?
Usually no. It invites arguments, can be wrong, and puts personal identifiers and accusations in public. Keep the list private, record it carefully, and share it only where you have a clear reason and a legitimate basis.
Can I ban someone who has never joined my server?
On most games, yes, by account ID: sm_addban, Rust banid, Valheim's bannedlist.txt and Minecraft's /ban with a name the server can resolve to a UUID all work for absent players.




Comments
Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.