DMA setup for Warzone: Ricochet, Secure Boot and TPM
Warzone runs RICOCHET Anti-Cheat and now lists TPM 2.0 and Secure Boot as requirements. Learn what each layer means for a two-machine DMA build.
Short answer
Warzone runs RICOCHET Anti-Cheat, a kernel-level driver plus server-side detections, and Activision requires TPM 2.0 and Secure Boot. A DMA build puts a card in the game PC and the reader on another PC, but the game PC must still satisfy Ricochet. The store sells an external Warzone cheat at /products/warzone and Slotted firmware that lists Warzone, but no Warzone DMA cheat of its own.
On this page10
- How Ricochet anti-cheat works in Warzone
- What Ricochet requires on the game PC
- Secure Boot is separate from virtualisation settings
- Which layers does a Warzone build need?
- The right order to start a session
- Warzone checklist before each match
- Common Warzone problems and fixes
- Warzone setup questions
- What to check before you buy
- Sources
How Ricochet anti-cheat works in Warzone
RICOCHET Anti-Cheat is built in-house by Activision rather than licensed from EAC or BattlEye, and Activision describes it in four parts. On the PC there is a kernel-level driver written specifically for Call of Duty, together with client-side detections that watch what runs on the machine during a session. On the server, behavioural models look for unusual patterns in how a player performs. Finally, in-game mitigations degrade a detected session instead of banning the player immediately. Since the Black Ops 7 launch, the stack has also included TPM 2.0 and Secure Boot. ReportedActivision says that layer checks hardware integrity before a session begins.
What Ricochet requires on the game PC
Some rows come from Activision's support article on TPM 2.0 and Secure Boot, which was last revised on 27 August 2026, and the rest come from the RICOCHET pages on callofduty.com. The third column shows what each item means for a two-machine build.
| Requirement | What Activision says it is | What it means for a DMA build |
|---|---|---|
| Secure Boot | A boot-chain check that runs before Windows loads and confirms the system has not been tampered with | A constraint on the game PC's BIOS, not on the card. If you disabled it while building the machine, expect the game to stop you |
| TPM 2.0 | Hardware-backed attestation used alongside Secure Boot to verify the machine's integrity | Nothing to do with reading memory. Everything to do with how firmly an enforcement action can be pinned to that machine |
| Kernel-level driver | A driver developed internally for Call of Duty that detects unauthorised programs interacting with protected titles | The reason the second-PC architecture exists at all: the driver sees the game PC, and the reader does not run there |
| Hardware and peripheral detection | Detection for third-party devices that alter gameplay, built to recognise classes of machine-driven input behaviour | The input-device layer is the scrutinised one. A device that moves the cursor in a way no hand produces is a behavioural signal, not a signature |
| Separate matchmaking | Players who do not meet the security requirements may be placed in separate matchmaking pools | A machine that fails the checks does not simply fail to launch — it can be quietly sorted elsewhere |
ReportedActivision has also announced a Secure Attestation Wizard, a first-party tool that confirms whether a PC meets the security requirements. Use the game's own tool to check this rather than relying on a forum post.
Warning
Secure Boot is separate from virtualisation settings
These two groups of settings are often confused, and the mix-up can waste days. Secure Boot and TPM are boot-chain and attestation features. IOMMU, VT-d, VT-x and SVM belong to a separate group of virtualisation settings, which are the ones that come up when a reader cannot locate a DTB. They are separate BIOS items with separate jobs, so getting one group right tells you nothing about the other. Change them one at a time, and get the game launching on its own before a reader goes near the machine.
Which layers does a Warzone build need?
Warzone is a battle royale, so most of the value sits in the information layer: player positions, loot and rotations shown on a second screen. That layer is read-only and needs no input device in the build at all. Aim assistance is a separate layer that needs a device the game PC accepts as an ordinary mouse, and that is exactly the layer Ricochet's peripheral detection targets. A fuser is the last and most optional layer. It only moves the overlay from a second monitor onto your main one and changes nothing about what is read.
The right order to start a session
Warzone ships through several storefronts, and its anti-cheat driver starts with the game, so first make sure the game runs properly on its own.
- Confirm that Warzone launches and reaches a lobby on the game PC with no reader attached
- Confirm that Secure Boot and TPM 2.0 are in the state the game expects, using the game's own security check if you have one
- Read today's status rows for your firmware tier and for the software you run, not last week's
- Boot the second PC and confirm the card enumerates before starting anything else
- Start the reader and attach it to the card
- Launch the game and let Ricochet finish its startup before touching the reader
- Attach to the game process once you are in a lobby
- If a fuser is in the video path, run borderless fullscreen at the monitor's native resolution and refresh rate so the display mode does not renegotiate mid-match
Warzone checklist before each match
- The game launches cleanly on its own and shows no security warning at startup
- Secure Boot and TPM 2.0 are enabled and detected on the game PC
- You have read today's status rows for your firmware tier and for the software you run
- The card is in its data port, and the reader was attached before the game started
- The game PC enumerates any input device as a standard mouse
- Borderless fullscreen is set if a fuser sits between the game PC and the monitor
- You know which season and build the game updated to, and when those status rows were last written
Common Warzone problems and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| The game refuses to start and names a security or hardware requirement | Secure Boot or TPM 2.0 is off, not detected, or was invalidated by a BIOS change | Restore the game PC to a state where the game launches on its own, then change one BIOS item at a time and retest. Use the game's own attestation check instead of guessing |
| Matches feel like a different playlist, with low lobby quality and odd matchmaking | ReportedThe machine may not meet the security requirements, and Activision states such players can be placed in separate matchmaking pools | Check that the game PC really meets the requirements, and treat odd matchmaking as a reason to investigate, not as proof of anything |
| The build stopped working, but the game has no new patch notes | Ricochet updates on its own schedule, separately from seasonal content patches | Compare the status row date with the game's last build date. If the game has not changed but the build has stopped working, assume a change on the anti-cheat side and wait for the status board |
| The overlay drifts or disappears when a match loads | Fullscreen-exclusive mode renegotiated the display mode through the fuser | Set borderless fullscreen and match the resolution and refresh rate on both machines, then re-check how the fuser handles EDID |
Warzone setup questions
Which anti-cheat does Warzone use?
Warzone uses RICOCHET Anti-Cheat, Activision's in-house system, which combines a PC kernel-level driver, client-side and server-side detections, and behavioural models. Since Black Ops 7 it has also included TPM 2.0 and Secure Boot.
Does Warzone really require TPM 2.0 and Secure Boot?
Activision's support article lists both as required for Call of Duty: Black Ops 7 and Call of Duty: Warzone. It also says that players who do not meet them may be placed in separate matchmaking pools. Check the article and the in-game security check for the current wording.
Does a DMA build put the reader out of Ricochet's reach?
No, and anyone who tells you otherwise is not being honest. The architecture moves the reader off the machine that the kernel driver watches, but that is the only thing it changes. Server-side behavioural detection, player reports, hardware attestation and manual review are not affected.
Do I need an input device for a Warzone build?
Only if the feature set moves the cursor. A read-only information build needs no input device at all, which also keeps you away from the layer that Ricochet's third-party device detection is built around.
How often will a Warzone build break?
Expect breakage with seasonal and midseason patches, with hotfixes, and with anti-cheat updates that come with no patch notes at all. Plan for downtime as a normal part of using a build, not as a fault.
Info
What to check before you buy
Ricochet's published architecture and Activision's stated rules are stable enough to write down, but how strictly those rules are enforced and whether a Warzone build works today are not. Read the live status board, compare its date with the game's last update, and ask support before you buy rather than after.
Sources
Everything else comes from bench work and changes with each season.
- 01Trusted Platform Module and Secure Boot (Activision Support)
the publisher's own TPM 2.0 and Secure Boot requirement
support.activision.com
Read next
- DMA setup for Call of Duty: one anti-cheat, a new game every year
- What are DMA cheats and how do they work
- BIOS settings for DMA on the game PC
- KMBox Net, KMBox B+, MAKCU, Teensy or Arduino: which input device to buy
- How to read the build status board
- DMA setup for Arena Breakout: Infinite: ACE and DMA Guard
- DMA setup for CS2: VAC, FACEIT and ESEA are three different problems
Still stuck? Open a ticket on Discord
All guides