OPEN SOURCE · WINDOWS X64 · GPL-3.0
Windows ARK, Kernel Debugging, and System Forensics Toolkit
KSword brings user-mode and kernel-mode evidence into one workflow for auditing processes, memory, networking, files, drivers, kernel objects, and system security.
Latest Update
5.1.2.4 Improves long-running refresh performance in the Processes page, process-tree and application-group actions, first-run defaults, legacy Windows driver compatibility, theme colors, language fallback, localized splash screens, license packaging, and GitHub access.
Core Capabilities
Process and Object Cross-view
Compare R3 and R0 process, thread, CID, and handle views to inspect hidden objects, structural differences, thread stacks, and detailed process information.
Memory and Page Tables
Browse memory regions, search hexadecimal content, scan executable kernel memory, collect evidence, and translate PTE and virtual addresses.
Drivers and Kernel Objects
Inspect DriverObject, DeviceObject, SSDT, hooks, callbacks, module cross-views, unloaded drivers, and PiDDB information.
Network Auditing
Provides packet capture, connection management, rate limiting, request construction, WFP firewall events, NIDS, and multi-layer network views.
Files and System Forensics
Combines file recovery, signature and PE analysis, file-lock inspection, storage stacks, the registry, startup entries, services, and device trees.
Security Policy Diagnostics
Inspect AppLocker, WDAC, Code Integrity, Defender, ASR, VBS, Hyper-V, and event-log status.
Components
Complete ARK, debugging, and auditing workflow
Qt 6 / ADSLow-resource environments and rapid response
Native Win32Unified R0 auditing protocol
WDK / IOCTLCompatibility checks and entry-point selection
Native Win32Automation, validation, and troubleshooting
Command lineUsage Boundaries
KSword includes system-level debugging, auditing, and administrative capabilities. Use it only on devices and environments for which you have explicit authorization. Confirm risks and rollback paths before unloading, deleting, patching, writing to disks, or modifying protection bits.



