RELEASE HISTORY

Complete Changelog

This page covers the current 17 visible stable and prerelease GitHub Releases with their tags, comparison ranges, and actual updates. The newest assets are 5.1.4.3 (2026-08-28); the virtualization work that landed on main afterwards has not become a Release, so see the main-branch development snapshot. The repository also publishes rolling ci-build-* prereleases, which are not itemised here.

2026-08-28

KswordARK 5.1.4.3

5.1.4.3
Previous tag5.1.4.3Pre
Current tag5.1.4.3
Patch14cf41b
Commits63

Actual changes

  • Simplified the UI layout.
  • Fixed window border clipping and transparent styling on some tables.
  • Fixed the selection state when the log window refreshes.
Release description and correction

The published release note contains only the layout item; the other two come from the 5.1.4.3Pre..5.1.4.3 commit range. GitHub marks this release as a prerelease while 5.1.4.3Pre is not marked, so decide which build you need by its assets rather than by the label.

2026-08-27

KswordARK 5.1.4.3Pre

5.1.4.3Pre
Previous tag5.1.4.1-Alpha
Current tag5.1.4.3Pre
Patch8860b64
Commits188

Actual changes

  • New Kernel Knowledge center: 12 categories and 71 Windows kernel topics, with Chinese and English content, full-text search, official documentation references, R3/R0 live-evidence queries, and routing to the matching read-only evidence pages.
  • New kernel callback monitor page with live capture, filtering, pause, and drop statistics for process, thread, image, registry, object, and file callbacks; KswordCLI gained matching query and start/stop commands.
  • The HVM page became a lifecycle-guarded Intel VT-x/EPT resident monitoring mode, adding power-state, processor-topology, unload-interlock, and VMX state protection. It refuses to start on AMD, under an existing hypervisor, or when the guard conditions are not met.
  • The Processes page gained per-core CPU attribution with expandable charts, thread CPU affinity settings, dynamic history snapshots, and table snapshot comparison; startup entries support multi-select.
  • KswordARKLight reorganised its workspaces (performance and bus tools into Hardware, network and window tools into their main pages), completed process view fields and detail capabilities, switched the process list to incremental refresh without the refresh overlay, and fixed driver unload on exit.
  • The bugcheck diagnostics page and layout were rebuilt around Stop Code, key processes, candidate modules, and actionable evidence, and installation became an explicit “install now” or a configurable automatic install. Ordinary driver loads no longer scan BGP private paths or register diagnostic callbacks by default.
  • Detail and report pages moved to a unified structured report widget; title-bar global search became scope-tab filtering; combo popup re-entrancy crashes and high-frequency refresh stability issues were fixed.
  • Fixed the takeover conflict between SYSTEM/elevated restart and the single-instance guard; startup enumeration now publishes incrementally; the experimental storage controller driver and its UI were removed from the standard release chain.
Release description and correction

This is the first release asset to include the HVM resident mode. Residency is an experimental backend intended only for authorized lab and diagnostic environments; save your work before starting it. For the virtualization work that landed on main afterwards, see the development snapshot and the Nested HVM topology demo.

2026-07-22

KswordARK Evaluation Version 5.1.3.0-1 Alpha

5.1.3.0-1
Previous tag5.1.2.4
Current tag5.1.3.0-1
Patch160944d
Commits43

Actual changes

  • Refined the visual layout and enabled text and interface antialiasing by default; the main program is no longer always on top by default.
  • Reduced Processes-page stalls across disk sampling, packet capture, connection management, multithreaded downloads, process tracking, WinAPI, direct kernel calls, and secondary memory scans.
  • Fixed and expanded R0 registry paths, improved driver thread termination, and improved the Light process-termination path.
  • Refined QADS triggers, test-mode settings, scheduled-task startup deletion, and file ownership takeover.
  • Reduced Release size and updated project documentation.
Release description and correction

This was the first public evaluation build in the 5.1.3.0 line; the -2 and final builds continued the same line with lower-level enumeration, process actions, and performance work.

2026-07-24

KswordARK Evaluation Version 5.1.3.0-2 Beta

5.1.3.0-2
Previous tag5.1.3.0-1
Current tag5.1.3.0-2
Patch9b2b0e6
Commits77

Actual changes

  • Added process-tree termination to the context menu.
  • Added IPC enumeration, IDT/GDT enumeration, GUI handles, window timers, and DPC-related capabilities.
Release description and correction

The Release body is a short feature list; the comparison link preserves the actual tag relationship between this Beta and the preceding Alpha.

2026-07-25

KswordARK 5.1.3.0

5.1.3.0
Previous tag5.1.3.0-2
Current tag5.1.3.0
Patchf477355
Commits13

Actual changes

  • Enhanced and reorganized process details, adding process performance history and CPU-affinity settings.
  • Simplified ETW filters and strengthened the ETW collection UI for high-throughput data.
  • Added history comparison and stronger export support to all tables.
Release description and correction

The Release body is a short update summary; later main commits are not backfilled into this formal release entry.

2026-07-29

KswordARK 5.1.4.0

5.1.4.0
Previous tag5.1.3.0
Current tag5.1.4.0
Patchf40fca0
Commits41

Actual changes

  • Added the executable Cheat Engine plugin with themed launch, KSword memory bridging, marketplace installation progress, and update notices.
  • Expanded HTTPS analysis with process correlation, request/response events, content type, TLS/ALPN, timing, traffic totals, filters, statistics, clearing, and CSV export; system proxy settings can be restored after stopping.
  • Persisted CPU-affinity rules by full executable path and labeled cores by P-core, E-core, and logical-thread topology; added post-launch suspension for targeted monitoring.
  • Added process-detail context links to business tables, improved global-hotkey viewing, and added Shell file-association management.
  • Added global custom theme colors and fonts, wired elevation prompts into more features, and fixed startup initialization, settings stalls, light-theme menus, and CPU-monitor text.
  • Added Windows automation validation, driver builds, release-directory checks, and change-triggered subproject builds.
Release description and correction

This is the latest stable version in the current GitHub Releases list; the later Alpha, pre-release, and main snapshots must be read as prerelease or development states.

2026-08-08

KswordARK 5.1.5.0-pre

5.1.5.0-pre
Previous tag5.1.4.0
Current tag5.1.5.0-pre
Patch8f12a6c
Commits304

Actual changes

  • Added R0 thread suspension and experimental termination, system-thread and Kernel Work Queue views, and stronger thread, ETHREAD, APC, callback, and driver-unload lifetime handling.
  • Expanded R0 force-unload, unloaded-driver evidence, PiDDB cleanup, kernel-module dumps, driver-load strategy diagnostics, and signature/trust validation.
  • Expanded HAL, WDF/KMDF, Legacy File System Filter, i8042prt, IDT/GDT, IOCTL decoding, and WFP/DNS/HTTPS auditing.
  • Improved MFT recovery, Shell associations, Window Band/Z-order/DWM/Window Station diagnostics, table freezing, smooth scrolling, theme handling, and font restoration.
  • Fixed high-frequency tables, proxy restoration, plugin-license changes, ETW filter imports, PID reuse, R0 error callbacks, and multiple kernel-concurrency paths.
Release description and correction

This is a prerelease snapshot. The Release description still lists experimental table freezing, some Error 31 reports, and remaining field-tooltip limitations.

2026-08-10

KswordARK Evaluation Version 5.1.4.1-Alpha

5.1.4.1-Alpha
Previous tag5.1.5.0-pre
Current tag5.1.4.1-Alpha
Patch6631344
Commits124

Actual changes

  • Added IDT, code-integrity, VBS/HVCI posture, page-protection, SLAT/IOMMU, EPT/NPT, Hypervisor CPUID, and DMAR/IVRS cross-audits.
  • Added HAL, WDF/KMDF, i8042prt, object-type, special-callback, IoTimer, system-thread, work-queue, descriptor-table, and IOCTL-decoding capabilities.
  • Added MFT/IRP, R0 directory, five-tier deletion, raw-filesystem, physical-sector, and live file-recovery filtering paths.
  • Expanded process columns and custom views, process protection, DWM composition, clipboard/capture-protection/hierarchy-diagnostics/hotkey tools.
  • Added WFP packet capture and controls, system time and calibrated-clock paths, dump attribution, bugcheck protection, CPU power controls, render benchmarking, and Light modules.
  • Strengthened METHOD_BUFFERED snapshots, driver unload, callback, APC, ETW, network, process, and file-operation confirmation, timeout, rollback, and fail-closed semantics.
Release description and correction

Main continued to receive commits after this Alpha tag; the current main-branch additions are documented on the development snapshot page.

2026-07-16

KSwordARK Evaluation Version 5.1.2.4 — Signed R0

5.1.2.4
Previous tag5.1.2.3
Current tag5.1.2.4
Patch15b2842
Commits7

Actual changes

  • Fixed excessively wide thread-list status text by keeping a compact summary in the main interface and moving full diagnostics to a tooltip.
  • Reworked switching between the friendly process view and parent-child tree. Application groups can expand into real members and apply context-menu or batch operations to the entire group.
  • Reduced progressive slowdown after long refresh sessions by limiting active samples and icon caches, clearing network counters for exited PIDs, and downsampling charts to the drawing width.
  • Changed first-run defaults to maximized, not always-on-top, automatic elevation, with the Unlocker context menu enabled.
  • Added a nonpaged-pool compatibility layer that resolves ExAllocatePool2 at runtime and falls back to ExAllocatePoolWithTag(NonPagedPoolNx) on older Windows versions.
  • Removed repeated Kernel/R0 decoration badges and aligned selected states, active docks, dark chart titles, and axis text.
  • Rewrote system-language detection and fallback and revised many English and Chinese status, prompt, and toolbar strings.
  • Selected localized splash, welcome, and README branding by language; forced LICENSE into release packages; and added a GitHub menu entry.
Release description and correction

The release also emphasizes “Signed R0,” but that capability already existed in 5.1.2.3, so it is treated here as a continuing feature rather than a new change.

2026-07-15

KSwordARK Evaluation Version 5.1.2.3 — Signed R0

5.1.2.3
Previous tag5.1.2.2
Current tag5.1.2.3
Patch214f3fe
Commits35

Actual changes

  • Released the digitally signed KswordARK driver so R0 features no longer require Windows Test Mode.
  • Added the kernel debug-output capture pipeline: driver-side DbgPrint, DbgPrintEx, and KdPrintEx capture, IOCTL protocol, user-mode buffering, and Driver Dock display.
  • Expanded LanguageManager and the English and Chinese language packs across driver, kernel, hardware, file, log, and startup runtime text.
  • Improved driver service, integrity, trust, and signature-check pages together with driver errors, evidence refresh, and operation guidance.
  • Revised interactions and wording across Kernel Objects, callbacks, DynData, hooks, CID, IPC, and device management.
  • Added UI infrastructure including VisibleTableWidget and fixed multiple table, theme, and layout problems.
  • Corrected the i18n scanner to skip backup directories and release-metadata markers, reducing false positives.
Release description and correction

The release describes this as the first fully translated version and lists the Kernel Sign Checker, stability fixes, and issues #32–#40. The actual diff confirms that signing, debug output, internationalization, and driver pages were the main focus.

2026-07-13

KSwordARK Evaluation Version 5.1.2.2-4 — Signed R0

5.1.2.2
Previous tag5.1.2.1
Current tag5.1.2.2
Patch1744e8f
Commits44

Actual changes

  • Added the complete internationalization framework and zh-CN and en-US language packs with runtime binding and fallback for later full translation.
  • Added the plugin host, installation workflow, and one-click marketplace installation; fixed plugin installation and added structured scan interfaces.
  • Added VirusTotal, ThreatBook, sandbox-upload entry points, and related settings.
  • Expanded the file locker, R0 injector, file, handle, and process operations and their driver protocols.
  • Added the HWID Dispatch page and driver dispatch-hook implementation together with network auditing, process details, PTE, and memory evidence.
  • Extended driver auditing, integrity, DynData, callbacks, kernel hooks, devices, and storage evidence.
  • Added the registry optimization page and configuration loading.
  • Moved the project website from the main repository to the independent KSwordDEV/Website repository.
Release description and correction

The release explicitly lists a valid signature, plugin system, file locker, R0 injector, marketplace installation, and website migration. The diff additionally confirms internationalization, online scanning, and multiple R0 auditing expansions.

2026-06-28

Version 5.1.2.1 Stable Release

5.1.2.1
Previous tag5.1.1.1
Current tag5.1.2.1
Patche8f9b8b
Commits36

Actual changes

  • Greatly expanded the file manager and manual file-system parser with file properties, PE analysis, and holder scanning.
  • Added Device Manager and the R0 hardware-evidence page, unifying device nodes, driver chains, and low-level evidence.
  • Expanded kernel-object views with BaseNamedObjects, named pipes, symbolic links, communication endpoints, DriverObject and DeviceObject, recursive object directories, and object-type matrices.
  • Improved Kernel Callback, DynData, Driver Status, and object-query workflows.
  • Added the network firewall page and NIDS module.
  • Added Application Control, window capture protection, and more process-detail actions.
  • Expanded ArkDriverClient and the shared IOCTL protocol into a unified entry point for device, storage, security, network, and process auditing.
Release description and correction

The release description contains only a development-cost joke and no feature list, so this section is based mainly on the actual diff across 36 commits.

2026-06-16

Version 5.1.1.1 Evaluation Release

5.1.1.1
Previous tagα260427
Current tag5.1.1.1
Patch955981b
Commits81

Actual changes

  • Split user-mode driver access into ArkDriverClient modules for ALPC, callbacks, files, handles, kernel, keyboard, memory, processes, registry, sections, and capability queries.
  • Introduced a fuller DynData v4, driver capability matrix, error model, and protocol types so R0 features can degrade safely by capability.
  • Added device, network, storage, security, Win32k, thread, and process cross-view auditing.
  • Added process thread stacks, PDB Catalog, memory evidence, executable kernel-memory scanning, and page-table translation.
  • Added a disk editor, context-menu cleanup, startup expansion, Direct Kernel Call Monitor, and Risk Center.
  • Added the native Win32 KswordARKLight edition and its process, file, driver, kernel, and hardware modules.
  • Greatly expanded API Monitor hook targets and configuration and cleaned IDE temporary files while aligning the project structure.
  • Added test-signing assets, contribution guidelines, and more build and release support.
Release description and correction

The release says only “many updates; see commits.” The 81 actual commits show that this was a major transition from the early evaluation build to modern ArkDriverClient, a unified protocol, and the Light edition.

2026-04-28

KSwordARK Evaluation Version 260427 — Unsigned R0

α260427
Previous tag5.1_R3_Advanced
Current tagα260427
Patchdede6a1
Commits37

Actual changes

  • Added the x64 API Monitor Agent, named-pipe protocol, Hook Engine, and many WinAPI hook targets.
  • Added a custom title bar, Win32 splash screen, and globally themed message boxes.
  • Added kernel callback interception, rule serialization and validation, callback removal, SSDT, object namespaces, and runtime controls.
  • Added Boot Editor, Misc Dock, file-holder scanning, and a more complete hardware page.
  • Established the new KswordARKDriver directory, shared IOCTL protocol, and callback, file, process, and logging frameworks.
  • Added taskbar, HUD, website pages, and technical feature documentation.
  • The release PR also includes removal of external driver callbacks, Unlocker misclick protection, lazy loading, smooth scrolling, performance smoothing, absolute-path removal from builds, process-dump navigation, and expanded CPU and memory timelines.
Release description and correction

This is a prerelease and is explicitly marked as Unsigned R0. The complete comparison range is 5.1_R3_Advanced...α260427.

2026-04-04

KSwordARK Evaluation Version 5.1.0.4 Alpha

5.1.0.4 Alpha
Previous releaseStable Release
Current tag5.1_R3_Advanced
Patch1749d00
ComparisonHistory disconnected

Actual changes

  • Added HTTP and HTTPS listening, HTTPS parsing, a local HTTPS proxy, certificate generation and trust, system-proxy switching, and parsed-result display.
  • Added and improved HUD process and performance views.
  • Expanded startup inspection toward an Autoruns-style model covering registry, WMI, Winsock, scheduled tasks, services, and driver sources.
  • Added Window Station, Desktop, SessionId, SID, desktop switching, and context-menu actions to window and desktop management.
  • Added object-type mapping, detail decoding, readable access rights, and batch closing of same-type handles.
  • Added reverse lookup from file path to holder process with navigation to process details.
  • Upgraded selection, toolbar, interaction, and internal logic in the Hex editor.
  • Updated logos, app icons, PRE and DEV resources, and release scripts and removed test and build residue.
Release description and correction

This tag has no common ancestor with the preceding “Stable Release” tag, so GitHub cannot produce a reliable tag-to-tag diff. This entry uses the 14 commits and 127 files recorded in the release and does not invent comparison statistics.

2025-10-02

KSword v5.0.9.14 Stable Release

5.0.9.14
Previous tagInternal Test Release
Current tagStable Release
Patch074f2cb
Commits10

Actual changes

  • Added user-mode driver-control code and the independent KswordKernel project, INF, and kernel entry point.
  • Added ETW Monitor with event tracing and a monitoring page.
  • Greatly expanded DLL modules, module information, threads, memory regions, and breakpoint interfaces.
  • Expanded the process list, process details, memory viewer, and pointer window.
  • Added console helper components and new ARK Logo and Console resources.
  • Adjusted GUI configuration, project files, environment versions, and support functions.
  • Fixed D3D9 device-loss and icon-texture-cache problems, while the commit message acknowledges that not every bug was resolved.
Release description and correction

The original release text says only “Stable Release / the bugs are not all fixed.” The changes above come from the ten-commit diff between the Internal Test Release and Stable Release tags.

2025-08-15

v5.0.0.0-Alpha.0.1 Internal Test Release

5.0.0.0 Alpha.0.1
Release typeHistorical starting point
Current tagInternal Test Release
Patchfcd0eb3
ComparisonNo preceding release

Actual changes

  • The first public release and the internal-test starting point for the 5.x ImGui ARK.
  • Defined the four-part version number: main, major, minor, and minimum version.
  • Defined the purpose and examples of optional Alpha, Beta, LTS, and Limit suffixes.
  • The release contains no separate feature summary; the patch already includes early DLL, module, process, memory, and breakpoint implementations.
Release description and correction

This is the beginning of the public release history, so there is no earlier Release to compare.