2026-07-16
KSwordARK Evaluation Version 5.1.2.4 — Signed R0
5.1.2.4Actual changes
- Fixed excessively wide thread-list status text by keeping a compact summary in the main interface and moving full diagnostics to a tooltip.
- Reworked switching between the friendly process view and parent-child tree. Application groups can expand into real members and apply context-menu or batch operations to the entire group.
- Reduced progressive slowdown after long refresh sessions by limiting active samples and icon caches, clearing network counters for exited PIDs, and downsampling charts to the drawing width.
- Changed first-run defaults to maximized, not always-on-top, automatic elevation, with the Unlocker context menu enabled.
- Added a nonpaged-pool compatibility layer that resolves
ExAllocatePool2 at runtime and falls back to ExAllocatePoolWithTag(NonPagedPoolNx) on older Windows versions. - Removed repeated Kernel/R0 decoration badges and aligned selected states, active docks, dark chart titles, and axis text.
- Rewrote system-language detection and fallback and revised many English and Chinese status, prompt, and toolbar strings.
- Selected localized splash, welcome, and README branding by language; forced LICENSE into release packages; and added a GitHub menu entry.
Release description and correctionThe release also emphasizes “Signed R0,” but that capability already existed in 5.1.2.3, so it is treated here as a continuing feature rather than a new change.
2026-07-15
KSwordARK Evaluation Version 5.1.2.3 — Signed R0
5.1.2.3Actual changes
- Released the digitally signed KswordARK driver so R0 features no longer require Windows Test Mode.
- Added the kernel debug-output capture pipeline: driver-side DbgPrint, DbgPrintEx, and KdPrintEx capture, IOCTL protocol, user-mode buffering, and Driver Dock display.
- Expanded LanguageManager and the English and Chinese language packs across driver, kernel, hardware, file, log, and startup runtime text.
- Improved driver service, integrity, trust, and signature-check pages together with driver errors, evidence refresh, and operation guidance.
- Revised interactions and wording across Kernel Objects, callbacks, DynData, hooks, CID, IPC, and device management.
- Added UI infrastructure including VisibleTableWidget and fixed multiple table, theme, and layout problems.
- Corrected the i18n scanner to skip backup directories and release-metadata markers, reducing false positives.
Release description and correctionThe release describes this as the first fully translated version and lists the Kernel Sign Checker, stability fixes, and issues #32–#40. The actual diff confirms that signing, debug output, internationalization, and driver pages were the main focus.
2026-07-13
KSwordARK Evaluation Version 5.1.2.2-4 — Signed R0
5.1.2.2Actual changes
- Added the complete internationalization framework and zh-CN and en-US language packs with runtime binding and fallback for later full translation.
- Added the plugin host, installation workflow, and one-click marketplace installation; fixed plugin installation and added structured scan interfaces.
- Added VirusTotal, ThreatBook, sandbox-upload entry points, and related settings.
- Expanded the file locker, R0 injector, file, handle, and process operations and their driver protocols.
- Added the HWID Dispatch page and driver dispatch-hook implementation together with network auditing, process details, PTE, and memory evidence.
- Extended driver auditing, integrity, DynData, callbacks, kernel hooks, devices, and storage evidence.
- Added the registry optimization page and configuration loading.
- Moved the project website from the main repository to the independent KSwordDEV/Website repository.
Release description and correctionThe release explicitly lists a valid signature, plugin system, file locker, R0 injector, marketplace installation, and website migration. The diff additionally confirms internationalization, online scanning, and multiple R0 auditing expansions.
2026-06-28
Version 5.1.2.1 Stable Release
5.1.2.1Actual changes
- Greatly expanded the file manager and manual file-system parser with file properties, PE analysis, and holder scanning.
- Added Device Manager and the R0 hardware-evidence page, unifying device nodes, driver chains, and low-level evidence.
- Expanded kernel-object views with BaseNamedObjects, named pipes, symbolic links, communication endpoints, DriverObject and DeviceObject, recursive object directories, and object-type matrices.
- Improved Kernel Callback, DynData, Driver Status, and object-query workflows.
- Added the network firewall page and NIDS module.
- Added Application Control, window capture protection, and more process-detail actions.
- Expanded ArkDriverClient and the shared IOCTL protocol into a unified entry point for device, storage, security, network, and process auditing.
Release description and correctionThe release description contains only a development-cost joke and no feature list, so this section is based mainly on the actual diff across 36 commits.
2026-06-16
Version 5.1.1.1 Evaluation Release
5.1.1.1Actual changes
- Split user-mode driver access into ArkDriverClient modules for ALPC, callbacks, files, handles, kernel, keyboard, memory, processes, registry, sections, and capability queries.
- Introduced a fuller DynData v4, driver capability matrix, error model, and protocol types so R0 features can degrade safely by capability.
- Added device, network, storage, security, Win32k, thread, and process cross-view auditing.
- Added process thread stacks, PDB Catalog, memory evidence, executable kernel-memory scanning, and page-table translation.
- Added a disk editor, context-menu cleanup, startup expansion, Direct Kernel Call Monitor, and Risk Center.
- Added the native Win32 KswordARKLight edition and its process, file, driver, kernel, and hardware modules.
- Greatly expanded API Monitor hook targets and configuration and cleaned IDE temporary files while aligning the project structure.
- Added test-signing assets, contribution guidelines, and more build and release support.
Release description and correctionThe release says only “many updates; see commits.” The 81 actual commits show that this was a major transition from the early evaluation build to modern ArkDriverClient, a unified protocol, and the Light edition.
2026-04-28
KSwordARK Evaluation Version 260427 — Unsigned R0
α260427Actual changes
- Added the x64 API Monitor Agent, named-pipe protocol, Hook Engine, and many WinAPI hook targets.
- Added a custom title bar, Win32 splash screen, and globally themed message boxes.
- Added kernel callback interception, rule serialization and validation, callback removal, SSDT, object namespaces, and runtime controls.
- Added Boot Editor, Misc Dock, file-holder scanning, and a more complete hardware page.
- Established the new KswordARKDriver directory, shared IOCTL protocol, and callback, file, process, and logging frameworks.
- Added taskbar, HUD, website pages, and technical feature documentation.
- The release PR also includes removal of external driver callbacks, Unlocker misclick protection, lazy loading, smooth scrolling, performance smoothing, absolute-path removal from builds, process-dump navigation, and expanded CPU and memory timelines.
Release description and correctionThis is a prerelease and is explicitly marked as Unsigned R0. The complete comparison range is 5.1_R3_Advanced...α260427.
2026-04-04
KSwordARK Evaluation Version 5.1.0.4 Alpha
5.1.0.4 AlphaActual changes
- Added HTTP and HTTPS listening, HTTPS parsing, a local HTTPS proxy, certificate generation and trust, system-proxy switching, and parsed-result display.
- Added and improved HUD process and performance views.
- Expanded startup inspection toward an Autoruns-style model covering registry, WMI, Winsock, scheduled tasks, services, and driver sources.
- Added Window Station, Desktop, SessionId, SID, desktop switching, and context-menu actions to window and desktop management.
- Added object-type mapping, detail decoding, readable access rights, and batch closing of same-type handles.
- Added reverse lookup from file path to holder process with navigation to process details.
- Upgraded selection, toolbar, interaction, and internal logic in the Hex editor.
- Updated logos, app icons, PRE and DEV resources, and release scripts and removed test and build residue.
Release description and correctionThis tag has no common ancestor with the preceding “Stable Release” tag, so GitHub cannot produce a reliable tag-to-tag diff. This entry uses the 14 commits and 127 files recorded in the release and does not invent comparison statistics.
2025-10-02
KSword v5.0.9.14 Stable Release
5.0.9.14Actual changes
- Added user-mode driver-control code and the independent KswordKernel project, INF, and kernel entry point.
- Added ETW Monitor with event tracing and a monitoring page.
- Greatly expanded DLL modules, module information, threads, memory regions, and breakpoint interfaces.
- Expanded the process list, process details, memory viewer, and pointer window.
- Added console helper components and new ARK Logo and Console resources.
- Adjusted GUI configuration, project files, environment versions, and support functions.
- Fixed D3D9 device-loss and icon-texture-cache problems, while the commit message acknowledges that not every bug was resolved.
Release description and correctionThe original release text says only “Stable Release / the bugs are not all fixed.” The changes above come from the ten-commit diff between the Internal Test Release and Stable Release tags.
2025-08-15
v5.0.0.0-Alpha.0.1 Internal Test Release
5.0.0.0 Alpha.0.1Actual changes
- The first public release and the internal-test starting point for the 5.x ImGui ARK.
- Defined the four-part version number: main, major, minor, and minimum version.
- Defined the purpose and examples of optional Alpha, Beta, LTS, and Limit suffixes.
- The release contains no separate feature summary; the patch already includes early DLL, module, process, memory, and breakpoint implementations.
Release description and correctionThis is the beginning of the public release history, so there is no earlier Release to compare.