RELEASE HISTORY

Complete Changelog

This page covers all nine GitHub Releases. Each entry uses the release description, current patch, the actual diff from the preceding release patch, and related commits. Historical breaks that cannot be compared reliably are identified explicitly.

2026-07-16

KSwordARK Evaluation Version 5.1.2.4 — Signed R0

5.1.2.4
Previous tag5.1.2.3
Current tag5.1.2.4
Patch15b2842
Commits7

Actual changes

  • Fixed excessively wide thread-list status text by keeping a compact summary in the main interface and moving full diagnostics to a tooltip.
  • Reworked switching between the friendly process view and parent-child tree. Application groups can expand into real members and apply context-menu or batch operations to the entire group.
  • Reduced progressive slowdown after long refresh sessions by limiting active samples and icon caches, clearing network counters for exited PIDs, and downsampling charts to the drawing width.
  • Changed first-run defaults to maximized, not always-on-top, automatic elevation, with the Unlocker context menu enabled.
  • Added a nonpaged-pool compatibility layer that resolves ExAllocatePool2 at runtime and falls back to ExAllocatePoolWithTag(NonPagedPoolNx) on older Windows versions.
  • Removed repeated Kernel/R0 decoration badges and aligned selected states, active docks, dark chart titles, and axis text.
  • Rewrote system-language detection and fallback and revised many English and Chinese status, prompt, and toolbar strings.
  • Selected localized splash, welcome, and README branding by language; forced LICENSE into release packages; and added a GitHub menu entry.
Release description and correction

The release also emphasizes “Signed R0,” but that capability already existed in 5.1.2.3, so it is treated here as a continuing feature rather than a new change.

2026-07-15

KSwordARK Evaluation Version 5.1.2.3 — Signed R0

5.1.2.3
Previous tag5.1.2.2
Current tag5.1.2.3
Patch214f3fe
Commits35

Actual changes

  • Released the digitally signed KswordARK driver so R0 features no longer require Windows Test Mode.
  • Added the kernel debug-output capture pipeline: driver-side DbgPrint, DbgPrintEx, and KdPrintEx capture, IOCTL protocol, user-mode buffering, and Driver Dock display.
  • Expanded LanguageManager and the English and Chinese language packs across driver, kernel, hardware, file, log, and startup runtime text.
  • Improved driver service, integrity, trust, and signature-check pages together with driver errors, evidence refresh, and operation guidance.
  • Revised interactions and wording across Kernel Objects, callbacks, DynData, hooks, CID, IPC, and device management.
  • Added UI infrastructure including VisibleTableWidget and fixed multiple table, theme, and layout problems.
  • Corrected the i18n scanner to skip backup directories and release-metadata markers, reducing false positives.
Release description and correction

The release describes this as the first fully translated version and lists the Kernel Sign Checker, stability fixes, and issues #32–#40. The actual diff confirms that signing, debug output, internationalization, and driver pages were the main focus.

2026-07-13

KSwordARK Evaluation Version 5.1.2.2-4 — Signed R0

5.1.2.2
Previous tag5.1.2.1
Current tag5.1.2.2
Patch1744e8f
Commits44

Actual changes

  • Added the complete internationalization framework and zh-CN and en-US language packs with runtime binding and fallback for later full translation.
  • Added the plugin host, installation workflow, and one-click marketplace installation; fixed plugin installation and added structured scan interfaces.
  • Added VirusTotal, ThreatBook, sandbox-upload entry points, and related settings.
  • Expanded the file locker, R0 injector, file, handle, and process operations and their driver protocols.
  • Added the HWID Dispatch page and driver dispatch-hook implementation together with network auditing, process details, PTE, and memory evidence.
  • Extended driver auditing, integrity, DynData, callbacks, kernel hooks, devices, and storage evidence.
  • Added the registry optimization page and configuration loading.
  • Moved the project website from the main repository to the independent KSwordDEV/Website repository.
Release description and correction

The release explicitly lists a valid signature, plugin system, file locker, R0 injector, marketplace installation, and website migration. The diff additionally confirms internationalization, online scanning, and multiple R0 auditing expansions.

2026-06-28

Version 5.1.2.1 Stable Release

5.1.2.1
Previous tag5.1.1.1
Current tag5.1.2.1
Patche8f9b8b
Commits36

Actual changes

  • Greatly expanded the file manager and manual file-system parser with file properties, PE analysis, and holder scanning.
  • Added Device Manager and the R0 hardware-evidence page, unifying device nodes, driver chains, and low-level evidence.
  • Expanded kernel-object views with BaseNamedObjects, named pipes, symbolic links, communication endpoints, DriverObject and DeviceObject, recursive object directories, and object-type matrices.
  • Improved Kernel Callback, DynData, Driver Status, and object-query workflows.
  • Added the network firewall page and NIDS module.
  • Added Application Control, window capture protection, and more process-detail actions.
  • Expanded ArkDriverClient and the shared IOCTL protocol into a unified entry point for device, storage, security, network, and process auditing.
Release description and correction

The release description contains only a development-cost joke and no feature list, so this section is based mainly on the actual diff across 36 commits.

2026-06-16

Version 5.1.1.1 Evaluation Release

5.1.1.1
Previous tagα260427
Current tag5.1.1.1
Patch955981b
Commits81

Actual changes

  • Split user-mode driver access into ArkDriverClient modules for ALPC, callbacks, files, handles, kernel, keyboard, memory, processes, registry, sections, and capability queries.
  • Introduced a fuller DynData v4, driver capability matrix, error model, and protocol types so R0 features can degrade safely by capability.
  • Added device, network, storage, security, Win32k, thread, and process cross-view auditing.
  • Added process thread stacks, PDB Catalog, memory evidence, executable kernel-memory scanning, and page-table translation.
  • Added a disk editor, context-menu cleanup, startup expansion, Direct Kernel Call Monitor, and Risk Center.
  • Added the native Win32 KswordARKLight edition and its process, file, driver, kernel, and hardware modules.
  • Greatly expanded API Monitor hook targets and configuration and cleaned IDE temporary files while aligning the project structure.
  • Added test-signing assets, contribution guidelines, and more build and release support.
Release description and correction

The release says only “many updates; see commits.” The 81 actual commits show that this was a major transition from the early evaluation build to modern ArkDriverClient, a unified protocol, and the Light edition.

2026-04-28

KSwordARK Evaluation Version 260427 — Unsigned R0

α260427
Previous tag5.1_R3_Advanced
Current tagα260427
Patchdede6a1
Commits37

Actual changes

  • Added the x64 API Monitor Agent, named-pipe protocol, Hook Engine, and many WinAPI hook targets.
  • Added a custom title bar, Win32 splash screen, and globally themed message boxes.
  • Added kernel callback interception, rule serialization and validation, callback removal, SSDT, object namespaces, and runtime controls.
  • Added Boot Editor, Misc Dock, file-holder scanning, and a more complete hardware page.
  • Established the new KswordARKDriver directory, shared IOCTL protocol, and callback, file, process, and logging frameworks.
  • Added taskbar, HUD, website pages, and technical feature documentation.
  • The release PR also includes removal of external driver callbacks, Unlocker misclick protection, lazy loading, smooth scrolling, performance smoothing, absolute-path removal from builds, process-dump navigation, and expanded CPU and memory timelines.
Release description and correction

This is a prerelease and is explicitly marked as Unsigned R0. The complete comparison range is 5.1_R3_Advanced...α260427.

2026-04-04

KSwordARK Evaluation Version 5.1.0.4 Alpha

5.1.0.4 Alpha
Previous releaseStable Release
Current tag5.1_R3_Advanced
Patch1749d00
ComparisonHistory disconnected

Actual changes

  • Added HTTP and HTTPS listening, HTTPS parsing, a local HTTPS proxy, certificate generation and trust, system-proxy switching, and parsed-result display.
  • Added and improved HUD process and performance views.
  • Expanded startup inspection toward an Autoruns-style model covering registry, WMI, Winsock, scheduled tasks, services, and driver sources.
  • Added Window Station, Desktop, SessionId, SID, desktop switching, and context-menu actions to window and desktop management.
  • Added object-type mapping, detail decoding, readable access rights, and batch closing of same-type handles.
  • Added reverse lookup from file path to holder process with navigation to process details.
  • Upgraded selection, toolbar, interaction, and internal logic in the Hex editor.
  • Updated logos, app icons, PRE and DEV resources, and release scripts and removed test and build residue.
Release description and correction

This tag has no common ancestor with the preceding “Stable Release” tag, so GitHub cannot produce a reliable tag-to-tag diff. This entry uses the 14 commits and 127 files recorded in the release and does not invent comparison statistics.

2025-10-02

KSword v5.0.9.14 Stable Release

5.0.9.14
Previous tagInternal Test Release
Current tagStable Release
Patch074f2cb
Commits10

Actual changes

  • Added user-mode driver-control code and the independent KswordKernel project, INF, and kernel entry point.
  • Added ETW Monitor with event tracing and a monitoring page.
  • Greatly expanded DLL modules, module information, threads, memory regions, and breakpoint interfaces.
  • Expanded the process list, process details, memory viewer, and pointer window.
  • Added console helper components and new ARK Logo and Console resources.
  • Adjusted GUI configuration, project files, environment versions, and support functions.
  • Fixed D3D9 device-loss and icon-texture-cache problems, while the commit message acknowledges that not every bug was resolved.
Release description and correction

The original release text says only “Stable Release / the bugs are not all fixed.” The changes above come from the ten-commit diff between the Internal Test Release and Stable Release tags.

2025-08-15

v5.0.0.0-Alpha.0.1 Internal Test Release

5.0.0.0 Alpha.0.1
Release typeHistorical starting point
Current tagInternal Test Release
Patchfcd0eb3
ComparisonNo preceding release

Actual changes

  • The first public release and the internal-test starting point for the 5.x ImGui ARK.
  • Defined the four-part version number: main, major, minor, and minimum version.
  • Defined the purpose and examples of optional Alpha, Beta, LTS, and Limit suffixes.
  • The release contains no separate feature summary; the patch already includes early DLL, module, process, memory, and breakpoint implementations.
Release description and correction

This is the beginning of the public release history, so there is no earlier Release to compare.