Rust - EAC and Server ban evasion
Practical Rust EAC and server-ban evasion guidance.
Permanent HWID spoofing#
Do this before you burn another account. The complete HWID spoofing guide has the actual motherboard, SSD, Intel/Realtek/Mellanox NIC, USB, EDID, router and TPM procedures, with the tools and screenshots included.
When every identifier survives a cold boot, come back here and finish the game-specific account, cleanup and server-tracking steps.
With how frequently EAC expands and improves their hardware identification system it has gotten significantly harder for the average user to keep track of what works and what does not when it comes to staying a step ahead of the hardware identification tracking game. Here comes a complete summary of how you evade EAC HWID bans as well as Servers tracking your previously banned alt accounts.
Recommended hardware setup:
Firmware: Be careful of emulated devices with easily identifiable Serial Numbers / MAC addresses, this includes majority if not all NVME or SATA firmware as well as Network Cards
AMD:
Storage: Priventive SSD, SSD with a Map 1202 controller, Any other SSD (Important to use Raid0)
Motherboard: Gigabyte, MSI, AsRock, EVGA, ASUS
GPU: Radeon, NVIDIA
note, EAC does currently not ban GPU serials but if that were to change in the future which it most likely will, go with Radeon.
Network: USB Nics (Realtek, ASIX), Intel, Realtek, and Mellanox Nics
Router: A GL.iNet running OpenWrt or any custom-flashed OpenWrt router.
RAM: Nulled serial RAM (Corsair, Geil, Trident Z)
Monitors: Dr.HDMI, Capture card that allows custom EDID (ex, Elgato HD60 X)
INTEL:
Storage: Priventive SSD, SSD with a Map 1202 controller, Any other SSD
Motherboard: Gigabyte, MSI, AsRock, EVGA, ASUS
GPU: Radeon, NVIDIA
note, EAC does currently not ban GPU serials but if that were to change in the future which it most likely will, go with Radeon.
Network: USB Nics (Realtek, ASIX), Intel, Realtek, and Mellanox Nics
Router: A GL.iNet running OpenWrt or any custom-flashed OpenWrt router.
RAM: Nulled serial RAM (Corsair, Geil, Trident Z)
Monitors: Dr.HDMI, Capture card that allows custom EDID (ex, Elgato HD60 X)
EAC Hardware bans#
Updated 2026-04-14
Currently Rust does not consistently ban hardware identifiers upon your first ban. That being said spoofing between every ban is still highly recommended.
EAC bans a lot of identifiers across your host system, the main ones being SSD serials and volume ID:s, that does not mean that does not mean that you can simply change your SSD to a brand new one and hope that it will be enough. You need to ensure everything in this guide is spoofed correctly to safely play again.
The confirmed identifiers are currently:
SSD Serials and Volume ID:s
Host Network card MAC addresses including passive Wi-Fi cards and Bluetooth adapters.
All non "Default Value" motherboard serials, most obvious one being UUID
Complete router ARP table
Identifiers that will cause definite flags:
Monitor EDID / Serial number
Although a lot of temporary spoofers say that they can reliably spoof all of the above identifiers it is a known fact that no temporary spoofing provider is reliable for gameplay long-term. The risk heavily outweighs the benefit of using temporary spoofing services, especially when you are using DMA. Permanently spoofing all identifiers is the way to go!
SSD and volume Spoofing#
The most reliable way to spoof all SSD identifiers across both AMD and Intel is by purchasing a priventive spoofable SSD (priventive.de), that being said purchasing / owning a SSD using a map 1202 memory controller has also been proven to work, these SSDs can be easily permanently spoofed using online tools / manufacturer tools.
Another way to currently bypass the SSD identifiers if and only if you have a AMD CPU is by using Raid0, which to our knowledge works on the vast majority of recommended motherboards. This works even if you only have 1 SSD in your system. For guidelines and help with doing this, please refer to your motherboard manufacturers manuals. If you want to do this on Intel you're simply out of luck, this would require a dedicated Raid card.
The raid0 drivers need to be pre-loaded upon windows installation otherwise this will not work.
Also note that some permanent spoofing services claim that they spoof your volume ID:s, but that is not enough alone to bypass your ban as it leaves the actual serial numbers.
Motherboard Spoofing#
This is another topic that already has a vast amount of online resources, majority of motherboards can be spoofed using public tools (AMIDEWIN), besides certain OEM motherboards and all ASUS motherboards which require dumping your bios rom and flashing the modified version. This comes with a certain risk of bricking your motherboard if done incorrectly, but there are so many resources out there already that this is likely the easiest identifier to spoof.
Consult with your spoofer provider if you have an ASUS motherboard as some providers are able to spoof it and some do not.
Network card spoofing#
Majority of network cards from Intel, Realtek and Mellanox allow modifying MAC through manufacturer provided tools that have been shared across various forums and websites. There is quite a few things to keep in mind when it comes to this, always make sure to backup a dump of your network card before doing any changes to avoid bricking it, there is also a set amount of times that you can actually spoof the MAC (around 20 ish times) until the flash is full and the tool no longer works.
The majority of permanent spoofer providers can spoof MAC for you as long as you have one of these 3 providers. Your best bet is to get an external USB network card that you can easily swap once the flash is full.
Router ARP spoofing
#
To spoof your ARP table on your router you need a router that has OpenWRT firmware flashed onto it, openwrt has a list of the routers they support on their website. Certain routers already come flashed with OpenWRT such as routers from GL.iNet. You can find these on Amazon for anywhere from 20-50$. This is something to easily overlook and expect to be fine without, but that is truly not the case.
Inside the OpenWRT web-ui you can easily modify the MAC of each interface, we recommend just changing the last two digits in the MAC and be careful to not modify the vendor specific identifiers unless you know what you're doing. It's not the end of the world but stupid to do nonetheless.
RAM Spoofing
#
There is no reliable way to do this, simply purchase RAM from our recommended providers with nulled serials.
Monitor / EDID Spoofing#
This is yet another thing that is easy to overlook but is crucial for spoofing for EAC protected games. A lot of fusers allow for flashing custom EDID (refer to your fusers manual), if your fuser doesn't allow for custom EDID you're not totally out of luck, this can be easily bypassed by using a capture card like the Elgato HD60 X that allow for custom EDID inside of their software. To dump your current EDID you can use MonitorAssetManager to save your current monitors EDID as a BIN. You can modify this using HxD or other similar tools.
If you have a multi monitor setup you will need to get yourself a DrHDMI as it's not just one monitors EDID that gets banned it's all of them, these can be found on Amazon.
Beware that you can't just change the serial alone, there is certain structure that all EDIDs follow and checksums will fail if not done correctly which can be an easy way to get flagged, on top of that Elgato won't even accept EDID files in their software that are not correctly structured / corrupted. We have custom made tool that we can provide for anyone interested (create a discord ticket) that does this conversion automatically by just feeding the script your input BIN.
Rust Server bans and account tracking
#
Rust server owners and admins have a variety of tools at their disposal to identify your past accounts and bans, the most common and known of these being Battlemetrics.
Gameplay#
Be careful with how you play, the easiest way to get banned on a Rust server network is by simply being too blatant. Aimbot is rather easy to humanize, but if you're too consistent with your shots, tracking players flawlessly and doming every player you see then it won't require a brain surgeon to know you're cheating. Use mixed hitboxes, try to do some of the aiming yourself and most importantly of all, keep your ego in check. Even when using Alt-looking the servers and their Administration can still see what you are looking at, be careful with what items you pick up since they can often be planted there on purpose just to catch you. Don't take every fight you can see with perfect accuracy and be vary of your play-style and you will last a long time.
Battlemetrics#
Battlemetrics is the most common RCON tool for rust servers that provide their administration with a lot of player information such as your "real" playtime, previous accounts, accounts sharing the same IP, your risk score and much much more. A lot of rust servers have opted into their information sharing service which allows sharing of player information across servers on the Battlemetrics network. If you get banned it is very important that you ensure you think of these things:
Rust servers track:
Your IP and any IP that has played on that account on a Battlemetrics enabled server
Your playtime across all servers with Battlemetrics enabled, which they consider "real" hours.
Which servers you have visited within the Battlemetrics network
Past server actions taken on your account as well as IP, such as bans, kicks, flags and so on.
Who you have played with, this is done by tracking who you consistently end up being in a server with and who you team up with
Your kills, deaths,missed bullets, bullets fired, what hitbox you hit, what headshot percentage you have.
Is your IP a known VPN
It is very important to change IP after each account ban / account change. It is important to note that using a VPN will not help your case, just make stuff worse. Server administration is not clueless, they are aware when you have a VPN on and it doesn't help your case. Residential proxies are a decent way to avoid this but even then, they are usually shared proxies that other people with the same intention as you have used before.
Your safest bet is by either connecting your phone as a hotspot to your computer through Wi-FI or simply use your phone in tether mode. Or simply rotate your IP if you are lucky enough to have a dynamic IP, if you don't already have one you might be able to get one from your Internet Service Provider. This likely takes affect after turning off your router for 30-90 minutes, times can vary depending on your internet provider.
Other server tools#
Some other common tools that a lot of servers have started using as of recent are overwatch tools that let verified trusted members of a server community spectate a pre-recorded set of gameplay taken off what the server sees you doing and providing the trusted member with an option to analyze your gameplay to then give a verdict on your gameplay. The most popular and advanced of these are the ones on the ATLAS server network. In some cases a overwatch case is initiated on the first F7 or discord / website report you get and in other cases it might take a little while, but what we know for sure is that no matter what, someone will sooner or later be replaying your most suspicious moments.
Server administrators also have other tools that allow them to check your previous steam accounts by simply checking certain steam folder and registry files, we recommend you use Revo uninstaller and totally uninstall Steam and Rust while clearing all registry and leftover files after each account swap / ban.
Some known files they check are:
Computer\HKEY_CURRENT_USER\Software\Facepunch Studios LTD
Computer\HKEY_CURRENT_USER\Software\Valve
Steam\config\loginusers.vdf
Steam\config\config.vdf
Steam\config\coplay<steamid>.vdf (may not exist)
Steam\config\avatarcache<steamid>.png (may not exist)
Steam\steamapps\appmanifest<someid>.vdf ("LastOwner")
Manual reviews
#
Some Rust server also use interview styled manual reviews where they hop into your computer using a remote access tool (that you obviously have to opt-into). What they check during these manual checks depends a lot, sometimes you can get lucky and you end up getting handed a Admin or Support member that is rather new to this that ends up just checking your downloaded files, last activity viewer, search history and download history. But in other cases they really dive deep and go through registry files for known leftover cheat registry files (usually from external or internal cheats), your activity history through registry and a lot more. It's common that they even check your device manager, use RWEverything and other methods of detecting your DMA firmware, they even go into discord conversations.
Make sure to clear ALL your browsers, don't run spoofers with generic spoofer names (often just renaming the exe before you run it is enough), keep a spare discord account that you don't use for anything else but legit Rust servers, clear the files we mentioned above.