SOURCE-AVAILABLE · WINDOWS X64 · KSWORD COMMUNITY SOURCE LICENSE v1.6
Windows ARK, Kernel Debugging, and System Forensics Toolkit
KSword brings user-mode and kernel-mode evidence into one workflow for auditing processes, memory, networking, files, drivers, kernel objects, and system security.
Latest Update
main / e3d8106 development snapshot (as of 2026-09-08): 297 commits landed since the previous sync (848b6bb, 2026-08-16). This round is dominated by hardware virtualization: the resident VMM moved from “can enter and leave non-root” to staying resident, and on top of it the tree gained persistent EPT denial, split views, MSR/CR policy engines, execution domains, and R-1 process disposition — with the first runtime readings taken on a nested target.
The newest published releases are 5.1.4.3 (2026-08-28) and 5.1.4.3Pre (2026-08-27); the repository also publishes rolling ci-build-* prereleases. See the Nested HVM topology demo → Read the main-branch snapshot → View the complete changelog →
Core Capabilities
Hardware virtualization and the R-1 layer
A lifecycle-guarded Intel VT-x/EPT resident VMM: persistent EPT denial and split views, MSR/CR policy engines, EPT execution domains with VMFUNC, an R-1 memory channel, and address-space-scoped process freeze and termination. It can run as L1 under nesting, and reports the resulting capability downgrade honestly.
Processes, objects, and protection
Compare R3/R0 process, thread, CID, and handle views with near-Task-Manager columns, custom views, process-instance identity binding, and renewable process protection.
Drivers, kernel, and dynamic capabilities
Inspect drivers, hooks, callbacks, IDT, code integrity, VBS/HVCI, page protection, HAL/WDF/i8042, descriptor tables, IOCTLs, PDB/DynData, and kernel disassembly.
Crash dumps and system forensics
Analyze dump context, triage data, symbols, pool tags, crash timelines, secondary records, captured memory, and BlackBox evidence with a fail-closed bugcheck panel.
Files, disks, and raw storage
Combine MFT/IRP parsing, R0 directory mode, five-tier deletion actions, recovery, physical-sector reads, storage-stack evidence, and read-only-by-default raw-filesystem forensics.
Networking and security detection
Use R0 WFP packet capture and controls, connection management, DNS/HTTPS/WFP/NIDS auditing, plus DLL hijack, IFEO image hijack, and EXIT GhostSystemDriver-chain detection.
Light and system utilities
KswordARKLight now covers network, window, performance-bus, system, service, privilege, disk, and driver-recovery modules with confirmation, identity, and rollback boundaries for risky actions.
UI and runtime behavior
Use adaptive search scopes, table sorting, frozen rows and columns, smooth scrolling, taskbar notification filters, DWM/transparent backgrounds, dynamic themes, and long-running diagnostics.
Components
Complete ARK, debugging, and auditing workflow
Qt 6 / ADSLow-resource environments and rapid response
Native Win32Unified R0 auditing protocol
WDK / IOCTLCompatibility checks and entry-point selection
Native Win32Automation, validation, and troubleshooting
Command lineUsage Boundaries
KSword includes system-level debugging, auditing, and administrative capabilities. Use it only on devices and environments for which you have explicit authorization. Confirm risks and rollback paths before unloading, deleting, patching, writing to disks, or modifying protection bits.



