StealthRadar uses a signed kernel driver to read CS2 memory from outside the game. Some Windows security features block vulnerable drivers by default. Follow the checklist below before running reader.exe.
Memory Integrity (a.k.a. HVCI) blocks known vulnerable signed drivers. The reader uses ASTRA64.sys, which Windows Defender will refuse to load while Memory Integrity is on.
If the toggle is grayed out, you may need to disable it via Group Policy or BIOS first.
Windows Defender may flag reader.exe or ASTRA64.sys as vulnerable driver software or unknown executable.
reader.exe.reader.exe and ASTRA64.sys.The reader sends game data over UDP to the hosted radar server. Outbound traffic is usually allowed, but strict firewall profiles may block it.
reader.exe and add it for both private and public networks.The reader creates and starts the ASTRA64 kernel service. This requires administrator rights. If you double-click normally, the driver will fail to load with DRIVER_LOAD_FAILED.
reader.exe.Unsigned or freshly built executables may show a SmartScreen block. Click More info then Run anyway. There is no installer; the zip is portable.
ASTRA64.sys is signed, so Secure Boot does not need to be disabled. If you disabled it for an older unsigned driver, you can leave it on for this build.
Some AV products flag vulnerable drivers harder than Defender does. If the driver fails to load and Memory Integrity is already off, check your AV quarantine and exclusions.
If reader.exe fails to start, it will open a troubleshoot page automatically. You can also open it manually: Troubleshoot →