SOURCE-AVAILABLE · WINDOWS X64 · KSWORD COMMUNITY SOURCE LICENSE v1.6

Windows ARK, Kernel Debugging, and System Forensics Toolkit

KSword brings user-mode and kernel-mode evidence into one workflow for auditing processes, memory, networking, files, drivers, kernel objects, and system security.

Latest Update

main / e3d8106 development snapshot (as of 2026-09-08): 297 commits landed since the previous sync (848b6bb, 2026-08-16). This round is dominated by hardware virtualization: the resident VMM moved from “can enter and leave non-root” to staying resident, and on top of it the tree gained persistent EPT denial, split views, MSR/CR policy engines, execution domains, and R-1 process disposition — with the first runtime readings taken on a nested target.

The newest published releases are 5.1.4.3 (2026-08-28) and 5.1.4.3Pre (2026-08-27); the repository also publishes rolling ci-build-* prereleases. See the Nested HVM topology demo → Read the main-branch snapshot → View the complete changelog →

MEDIA

Demos and Screenshots

Core Capabilities

Hardware virtualization and the R-1 layer

A lifecycle-guarded Intel VT-x/EPT resident VMM: persistent EPT denial and split views, MSR/CR policy engines, EPT execution domains with VMFUNC, an R-1 memory channel, and address-space-scoped process freeze and termination. It can run as L1 under nesting, and reports the resulting capability downgrade honestly.

Processes, objects, and protection

Compare R3/R0 process, thread, CID, and handle views with near-Task-Manager columns, custom views, process-instance identity binding, and renewable process protection.

Drivers, kernel, and dynamic capabilities

Inspect drivers, hooks, callbacks, IDT, code integrity, VBS/HVCI, page protection, HAL/WDF/i8042, descriptor tables, IOCTLs, PDB/DynData, and kernel disassembly.

Crash dumps and system forensics

Analyze dump context, triage data, symbols, pool tags, crash timelines, secondary records, captured memory, and BlackBox evidence with a fail-closed bugcheck panel.

Files, disks, and raw storage

Combine MFT/IRP parsing, R0 directory mode, five-tier deletion actions, recovery, physical-sector reads, storage-stack evidence, and read-only-by-default raw-filesystem forensics.

Networking and security detection

Use R0 WFP packet capture and controls, connection management, DNS/HTTPS/WFP/NIDS auditing, plus DLL hijack, IFEO image hijack, and EXIT GhostSystemDriver-chain detection.

Light and system utilities

KswordARKLight now covers network, window, performance-bus, system, service, privilege, disk, and driver-recovery modules with confirmation, identity, and rollback boundaries for risky actions.

UI and runtime behavior

Use adaptive search scopes, table sorting, frozen rows and columns, smooth scrolling, taskbar notification filters, DWM/transparent backgrounds, dynamic themes, and long-running diagnostics.

Components

ComponentRoleTechnology
Ksword5.1

Complete ARK, debugging, and auditing workflow

Qt 6 / ADS
KswordARKLight

Low-resource environments and rapid response

Native Win32
KswordARKDriver

Unified R0 auditing protocol

WDK / IOCTL
Launcher

Compatibility checks and entry-point selection

Native Win32
KswordCLI

Automation, validation, and troubleshooting

Command line

Usage Boundaries

KSword includes system-level debugging, auditing, and administrative capabilities. Use it only on devices and environments for which you have explicit authorization. Confirm risks and rollback paths before unloading, deleting, patching, writing to disks, or modifying protection bits.