Well, some things I can highlight, I've worked at GC (gamer's club) and I know exactly how anticheat's work and I'm impressed that RIOT took so long to apply this to LOL
But let's go first, first a large list of signatures of known cheats will be stored, making most of them detectable, in addition they have put in place several systems to capture drivers, executables that use the same build, so the probability of cheaters being detected It is very high (in the free case) that they use free drivers to create cheat mechanisms or sell similar builds to their customers.
How to get around:
Just like Vanguard (Valorant), the way to bypass and use a solid driver is unique and create unique .exe builds for each specific cheat executable (if shared), in addition to playing few games and with severe disguise mechanisms, such as use new keyboard key-binds, as the most used ones are easily recognized by Vanguard, do not perform any cheating with LOL open, inject before it is opened (since Vanguard's activity is lower while nothing is open that requires Vanguard) use spoffers that camouflage your serials as a tpm/secure boot spoffer (you need a driver for this) and among other "n" tools to maximize the percentage of improving the UD of your cheat executable
But let's go first, first a large list of signatures of known cheats will be stored, making most of them detectable, in addition they have put in place several systems to capture drivers, executables that use the same build, so the probability of cheaters being detected It is very high (in the free case) that they use free drivers to create cheat mechanisms or sell similar builds to their customers.
How to get around:
Just like Vanguard (Valorant), the way to bypass and use a solid driver is unique and create unique .exe builds for each specific cheat executable (if shared), in addition to playing few games and with severe disguise mechanisms, such as use new keyboard key-binds, as the most used ones are easily recognized by Vanguard, do not perform any cheating with LOL open, inject before it is opened (since Vanguard's activity is lower while nothing is open that requires Vanguard) use spoffers that camouflage your serials as a tpm/secure boot spoffer (you need a driver for this) and among other "n" tools to maximize the percentage of improving the UD of your cheat executable