If it's a simple flag in the executable file header, what stops a cheat program setting the same flag and getting into the sandbox?
Or a cheat program combining itself with the game executable, and setting the flag so other processes can't interrogate whether it contains a cheat.
You don't "get into the sandbox", if a cheat program opted in, they would be launched into a separate instance that's distinct from the game.
And you would sign your files, which get verified by the integrity platform and allow you to authenticate with the servers securely.