OPEN SOURCE · WINDOWS X64 · GPL-3.0

Windows ARK, Kernel Debugging, and System Forensics Toolkit

KSword brings user-mode and kernel-mode evidence into one workflow for auditing processes, memory, networking, files, drivers, kernel objects, and system security.

Latest Update

5.1.2.4 Improves long-running refresh performance in the Processes page, process-tree and application-group actions, first-run defaults, legacy Windows driver compatibility, theme colors, language fallback, localized splash screens, license packaging, and GitHub access.

View the full changelog →

MEDIA

Demos and Screenshots

Core Capabilities

Process and Object Cross-view

Compare R3 and R0 process, thread, CID, and handle views to inspect hidden objects, structural differences, thread stacks, and detailed process information.

Memory and Page Tables

Browse memory regions, search hexadecimal content, scan executable kernel memory, collect evidence, and translate PTE and virtual addresses.

Drivers and Kernel Objects

Inspect DriverObject, DeviceObject, SSDT, hooks, callbacks, module cross-views, unloaded drivers, and PiDDB information.

Network Auditing

Provides packet capture, connection management, rate limiting, request construction, WFP firewall events, NIDS, and multi-layer network views.

Files and System Forensics

Combines file recovery, signature and PE analysis, file-lock inspection, storage stacks, the registry, startup entries, services, and device trees.

Security Policy Diagnostics

Inspect AppLocker, WDAC, Code Integrity, Defender, ASR, VBS, Hyper-V, and event-log status.

Components

ComponentRoleTechnology
Ksword5.1

Complete ARK, debugging, and auditing workflow

Qt 6 / ADS
KswordARKLight

Low-resource environments and rapid response

Native Win32
KswordARKDriver

Unified R0 auditing protocol

WDK / IOCTL
Launcher

Compatibility checks and entry-point selection

Native Win32
KswordCLI

Automation, validation, and troubleshooting

Command line

Usage Boundaries

KSword includes system-level debugging, auditing, and administrative capabilities. Use it only on devices and environments for which you have explicit authorization. Confirm risks and rollback paths before unloading, deleting, patching, writing to disks, or modifying protection bits.