Skip to content

Recommendation

Leave as default

For a modern system, leave it enabled, especially if the computer is used for work, study, unknown files or corporate access.

Disabling is acceptable only after a measurable A/B test of a specific game and an assessment of the threat model.

Shown
Windows 10 only
Main effect
Disabling kernel protection
FPS and memory
See the research

VBS (Virtualization-Based Security) uses hardware virtualization to isolate critical protection components from the regular Windows kernel. The setting disables VBS and its parts on Windows 10 — according to the BoosterX description, together with Hypervisor-Protected Code Integrity. Kernel protection weakens: code in the kernel is no longer verified by the hypervisor.

The setting is intended for Windows 10: on Windows 11 BoosterX hides it and instead shows the batch setting VBS (Memory Integrity, DeviceGuard, HVCI, CG). The separate Memory Integrity feature on Windows 10 is moved out of this setting because of anti-cheats.

Application warning: when disabling VBS, BoosterX warns that the EAC and FaceIt anti-cheats may refuse to work — for EAC the application points to the disabled kernel patch protection. If a game with such anti-cheats stops launching, turn VBS back on.

BoosterX also notes that after major Windows updates the parameter may return to its default value. The result of disabling depends on the CPU, firmware and drivers: a noticeable gain is not guaranteed on every system.

After the change, restart the computer and open Settings → Update & Security → Windows Security → Open Windows Security → Device security → Core isolation details: the isolation state must match your choice. The state of the other protection components can be checked in the Windows Security window itself.

In BoosterX, open “Optimization” → “Security” → “Hardening (VBS/UAC)” → “VBS (Virtualization Based Security)” and set the toggle to “Off”: BoosterX will apply the default Windows state with VBS enabled. Click “Apply” at the bottom of the page; with “Instant apply” enabled, the change is applied immediately. After applying, restart the computer and check core isolation via the path above. To disable VBS together with Hypervisor-Protected Code Integrity, use the “On” position; to return to the default state, set it back to “Off” and restart.

Last verified: 2026-09-19.