GuideTweak tabs
Mitigations
Up to 17 kernel, CPU side-channel, and app protections, each its own toggle, each with a real performance cost.
Up to 17 Windows security mitigations across kernel, CPU side-channel, and app protection, each as its own toggle. Turning a row on disables that mitigation for the performance gain, which is why the column header on the right says “Disable”.
How to use the tab
- Remember that turning off security protections can make your system less secure and more vulnerable to threats. Consider the risks before changing any setting.
- Each mitigation is its own toggle, so turn on the ones you want and leave the rest. Several rows can break kernel-level anti-cheat (see the warning below) and Meltdown is performance-blocked on AM5, so review those individually.
- Click Apply changes to write all selections at once.
- The app offers to create a restore point before applying. Take it.
These are real performance wins, not fine print. Disabling Memory Integrity (HVCI) and VBS can reclaim up to ~10% in some games, and turning off the CPU side-channel mitigations gives back cycles on every system call. The trade-off is security, since you're switching protections off, plus the anti-cheat requirements below, so weigh each row on its own rather than assuming it isn't worth applying.
Start with Spectre and Meltdown. They're among the biggest gains here and, unlike the HVCI, VBS and virtualization rows, carry no anti-cheat requirement. The one caveat is Meltdown, which is performance-blocked on AM5. The rest are worth applying too; just check the warning below first.
Kernel-level anti-cheat
Playing games with kernel-level anti-cheat? Several rows here can stop a game launching, kick you mid-match, or flag your account. Disabling DEP/NX affects Easy Anti-Cheat and BattlEye titles (Valorant needs NX too). A minority of anti-cheats require Memory Integrity (HVCI) on, namely Valorant (Vanguard), FACEIT, and Rainbow Six Siege (Ubisoft's new kernel-level anti-cheat and Shield Guard secure platform), so leaving HVCI, VBS, Hypervisor Launch, or VSM off blocks them (HVCI is built on all of them), as does disabling Control Flow Guard. The app flags each of these rows with a red warning sign. If a game stops working after applying, re-enable the affected row and click Apply again.
Note that HVCI and VBS also switch back on by themselves whenever CPU virtualization is enabled in BIOS, and Windows won't let you disable VBS while Hyper-V, Virtual Machine Platform, Windows Sandbox, or Memory Integrity are in use.
The firmware half of the same picture, VT-x, VT-d, SVM and IOMMU, is on the BIOS page with the matching anti-cheat rules.
App & download protections
Alongside the kernel and CPU mitigations, the manager holds the Windows protections that decide which apps and downloads are allowed to run. Disabling them removes prompts and a little launch latency at the cost of a safety layer, so skip them if you regularly download from random places.
- Disable SmartScreen turns off Windows SmartScreen so executables don't make a network call to Microsoft's reputation service before launching. Cuts cold-start latency on first-run binaries, but loses the “this app is unrecognized” prompt.
- Disable Mark of the Web stops Windows tagging downloaded files as “from the Internet,” so Office and other apps no longer show the “this file came from another computer” warning. In exchange it removes one friction layer against malicious downloads.
- Disable Smart App Control is one-way. Once off, Windows won't let you re-enable it from the app, and only a clean install or reset restores it. Turn it off only if you understand that.
If you disable Defender (for example with a third-party tool), disable Smart App Control here too. With SAC on but Defender off, Windows tries to validate every app launch and install against Microsoft's cloud reputation service through a missing local provider, so installs and launches can hang for minutes or never finish.