How does this address the fact that windows has 100s of badly written drivers that allow r/w to kernel? This seems to only stop the most advance cheats that actually execute at or before boot.
Private cheats usually require being vouched in, sometimes with ID scans, sometimes physically shipping you hardware.