Windows Community 0.3.31 · crash-resilient automatic monitoring · Defender-backed enforcement

Windows protection, made visible.

ZSEC Antivirus Community 0.3.31 combines Microsoft Defender real-time and on-access protection with automatic definition-health maintenance, a crash-resilient self-restarting post-change monitor, deterministic local checks, encrypted recovery evidence and a separately labelled signed advisory catalog.

Automatic protected-folder coverage Hourly Defender definition-health checks Local file inspection and quarantine

Accepted Windows archive: 33,854,891 bytes · SHA-256 3177951175510a0d992080f99dfa9d43f70d14ee4255492e1d7a8114c629752c · source 8b3d8f4da941dac1f0ca0945f58ab9155ec28390. Exact ZIP and all 1,107 manifest hashes passed. Plan-only and installed-runtime verification matched the packaged GUI and engine hashes, verified the companion process and startup entry, and left Microsoft Defender active and unchanged. ZSEC remains unsigned, user-mode and post-change; it is not a protected service and is not registered as the primary provider.

One auditable core. Three platform-specific Community packages.

Version 0.3.14 packages the same auditable core for each desktop and adds automatic signed data-only intelligence updates plus foreground post-change monitoring. Windows has a downloadable graphical Community client; the macOS and Linux Community archives remain unsigned self-contained command-line companions. None is a protected background service or primary provider.

Windows

Community 0.3.31 desktop: modern dark protection centre with native minimize/close-to-tray controls, persistent navigation, bounded local scans, an evidence-led scope/elapsed-time scan rail, crash-resilient self-restarting post-change monitoring, transactional startup repair, hourly Defender definition-health checks, encrypted quarantine, reports and settings. A fleet-jittered daily application-release check accepts only pinned-key Ed25519-signed, unexpired, non-rolled-back notification metadata; it never downloads or launches an installer. Expected vanished paths, symbolic links and Windows reparse exclusions stay visible without permanently degrading health, while inaccessible paths, special files, oversized files and missing protected roots remain fail-closed coverage gaps. The interface presents Windows real-time enforcement, ZSEC post-change monitoring and scoped coverage as independent evidence; it never turns a healthy companion into a primary or whole-device claim. The Windows protection page separately reports Windows Security and Defender posture without changing Defender preferences.

macOS

Community 0.3.14 unsigned CLI companion: native ARM64 tar archive with a reversible per-user LaunchAgent, FSEvents monitoring, bounded evidence and no root requirement. Tagged workflow provenance is available; activation remains unverified on physical macOS hardware.

Linux

Community 0.3.14 unsigned CLI companion: x86-64 tar archive with a hardened systemd-user companion, inotify monitoring, resource bounds and network denial. Tagged workflow provenance is available; activation remains unverified on a supported physical Linux desktop.

Native ZSEC replacement stays blocked; Defender handoff is separately gated

zero-security replacement-readiness --json still returns exit code 2, keep_existing_protection and no override because ZSEC is not a native primary provider. On Windows, a separate three-state handoff interlock can report operator-cutover eligibility only after Defender and Windows Security evidence passes. ZSEC does not uninstall a provider, change exclusions or register itself with Windows Security.

Accepted v0.3.31-windows Windows package identity

Download the 33,854,891-byte archive · checksum sidecar. Archive SHA-256: 3177951175510a0d992080f99dfa9d43f70d14ee4255492e1d7a8114c629752c. The package remains unsigned and Microsoft Defender supplies supported Windows real-time enforcement when live evidence confirms it active. These are bounded release facts, not independent certification or a clean-system verdict.

Archive validation covered all 1,107 manifest-declared payload files, found no missing or extra payload entry, recomputed every declared SHA-256 and passed ZIP integrity testing. The embedded clean source revision is 8b3d8f4da941dac1f0ca0945f58ab9155ec28390. Installed-runtime acceptance independently matched the packaged GUI and engine hashes, verified version 0.3.31, the companion process and per-user startup registration, and confirmed Defender remained active and unchanged. This is not independent malware-efficacy certification or a clean-system verdict.

Microsoft Store availability is not claimed

The earlier separately packaged unsigned 0.3.30 Store candidate recorded an overall WACK pass but remains unsubmitted. Version 0.3.31 Store copy is prepared as a draft only; no 0.3.31 Store package, Partner Center acceptance, Store signing, clean-VM Store installation or public Store availability is claimed by this direct-download release.

Automatic where it should be. Explicit where it matters.

Routine cryptographic key handling happens without password prompts. Community 0.3 keeps quarantine enablement and restore visible because automation must not hide consequential actions.

Start automatically

The Windows desktop companion protects Desktop, Documents and Downloads without a folder picker. The native observer starts before the automatic metadata inventory, so filesystem events remain covered while setup finishes.

React and reconcile

Create, modify and move-in events are debounced and checked locally; periodic reconciliation reduces missed-event risk.

Protect a match

When --quarantine is explicit, the implementation authenticates metadata and encrypts a verified recovery object before source removal.

Review or restore

Entries remain inspectable. Restore refuses unsafe paths and never overwrites an existing destination.

No hidden deletion

Community 0.3 deliberately has no purge command. If the original cannot be removed safely, the operation is reported as incomplete rather than presented as successful quarantine.

Real malware definitions from Microsoft. Signed advisories from ZSEC.

Microsoft Defender and Windows Update remain responsible for the real-time engine and malware definitions. While Defender is active, ZSEC checks their health hourly and requests Update-MpSignature only when Defender itself reports stale or missing definition material. Separately, each installation checks a fixed TalkToAI HTTPS endpoint for a signed informational advisory catalog; that catalog creates no scanner rule and authorises no remediation.

Automatic advisory checks

Signed advisory channel

Data only
Client schedule
Daily advisory check; hourly Defender health verification
Canonical endpoint
/zsec/intelligence/v1/feed.json
Advisory gate
Ed25519 signature, schema, sequence, expiry and SHA-256
Failure behaviour
Keep the last valid advisory catalog; report the error; never install partial data
Privacy
No file sample, browsing history or device account is required
Software releases
Separate signed manifest at /zsec/updates/v1/stable.json

Definitions and advisories never share one vague badge

The Windows protection page reports Defender’s definition version, timestamp and out-of-date verdict. The advisory page separately reports its last check, last valid catalog, next schedule, sequence, expiry and last error. An unavailable or failed check never becomes green.

Established cryptography. No invented shortcuts.

Encrypted quarantine is implemented and regression-tested. Its security properties come from established primitives, key management and authenticated metadata—not a proprietary cipher claim.

Automatic device root

A random device key is created once. Windows protects it with CurrentUser DPAPI; the macOS/Linux filesystem-key profile is explicitly development-grade key custody.

Fresh key per entry

Each quarantined object receives a new random AES-256 content key instead of reusing one raw encryption key for every file.

Metadata bound to bytes

AES-256-GCM authenticates file bytes together with canonical identity, path, hash, size and lifecycle metadata as additional data.

Verify before publish

Restore reconstructs and authenticates the same metadata before any plaintext is made available at its destination.

ZBA provenance

Zero Boundary Algebra records typed quarantine, verification and recovery transitions. It is an audit vocabulary, not a substitute for cryptography.

Recovery remains separate

Community 0.3 does not export the raw device root or claim a recovery kit. Lost-key, revocation and hardware-key recovery require their own verified release profile.

Small components. Narrow authority.

The product architecture separates the unelevated Windows interface, read-only provider evidence, fixed Defender actions, supervisor and content work. Community 0.3.14 source contains the graphical client, user-scoped CLI companion and a path-free bounded exact-rule child process with independent broker SHA-256 verification. Defender remains the supported Windows enforcement provider when confirmed active. The ZSEC child still has the invoking user's authority; privileged ZSEC enforcement and reduced-privilege hostile-format parser workers remain outside this release.

  • The currently registered antivirus remains active alongside Community 0.3.
  • Feeds contain data, not remote commands.
  • Untrusted parsing belongs in bounded workers.
  • Invalid signatures, rollback records or schemas fail closed.
  • Updates need expiry, rollback and freeze protection.

Know exactly what is available.

A passing test proves a defined path works. It does not establish real-world malware-detection efficacy. ZSEC Antivirus separates implemented Community capabilities from the additional evidence required for primary-provider replacement.

Public foundation

Deterministic on-demand SHA-256 and exact-byte checks, signed data-only feed verification, structured reports and recoverable quarantine in ZSEC Shield.

Community 0.3

Automatic AES-256-GCM quarantine, Windows DPAPI key sealing, authenticated ZBA lifecycle records, per-user automatic companions, bounded health evidence, Defender-backed Windows status/actions and fail-closed handoff states.

Not claimed

ZSEC-native real-time enforcement, memory scanning, EDR, complete antivirus coverage, zero-day prevention, a clean-system verdict, Pegasus detection/immunity or guaranteed protection from attackers. Any verified Windows real-time state names Microsoft Defender as the provider.

A browser request layer beside—not inside—the antivirus companion.

ZSEC Browser Shields Community 0.5.2 adds 49,464 pinned EasyList network rules, 39 focused privacy rules, two link-cleaning rules, 19 selected EasyList-derived YouTube cosmetic selectors and optional High-Risk Browsing. Acceptable Ads is not included. When High-Risk Browsing is enabled with the master protection switch, two higher-priority local rules block top-level plaintext HTTP navigation and third-party scripts, subframes, objects and WebSockets before those requests are sent.

Browser decision point

The extension can block only the two disclosed request classes. It does not inspect messages, renderer memory, downloads or the operating system, and it does not decide that a site is malicious or safe.

Review High-Risk Browsing research and runtime evidence.

Filesystem decision point

ZSEC Antivirus Community 0.3 operates later and separately: it observes selected filesystem changes and runs configured local checks after the event. It does not turn the browser rules into malware detection or pre-access file protection.

Read the browser privacy contract.

Two bounded layers do not equal complete protection.

Neither product detects mercenary spyware, inspects memory, stops an unknown browser or operating-system exploit chain, proves that a device is clean, or replaces the registered antivirus and native platform protections.

Your files stay local by default.

File hashing, configured rule matching and quarantine processing happen on the device. Community 0.3 has no automatic sample upload, advertising identifier, account requirement or remote-control channel.

Local-first does not mean pretending a connected product never uses a network. Update checks may disclose only the documented product, version, platform, architecture, channel and coarse rollout cohort.

Uploads remain off by default

  • Separate opt-in for each selected item.
  • Visible purpose and destination.
  • Retention, region and sharing terms before transmission.
  • No filenames, local paths or file contents in routine diagnostics.
  • Crash reporting remains a separate opt-in.

Auditable where trust is earned. Private where secrets must stay private.

Open source means source can be viewed and modified under its licence. ZSEC Antivirus does not call hidden code “open source,” and it does not treat compilation, minification or obfuscation as a security boundary.

Public and auditable

  • ZSEC Shield deterministic scanner.
  • Signed data-only feed format and verifier.
  • Encrypted quarantine format and ZBA records.
  • Threat models, privacy contracts and test fixtures.
  • Packaging manifests and update specifications.

Separately licensed or private

  • Third-party OEM engines and proprietary signatures.
  • Production signing keys, HSM policy and release credentials.
  • Optional managed reputation, sync and fleet services.
  • Customer-support systems and private operational data.
  • Privileged Windows, macOS and Linux components that are not part of Community 0.3.

No shortcuts around trust.

Primary-antivirus status must be earned through platform integration, independent testing and exact-release evidence—not a polished dashboard.

Publisher identity

Authenticode/Microsoft driver signing, Apple Developer ID and notarization, and signed Linux packages/repositories—each backed by protected signing infrastructure and provenance.

Windows integration

Supported services and drivers, Microsoft onboarding, HVCI compatibility and safe uninstall/coexistence behaviour.

macOS integration

Approved Endpoint Security entitlement, system-extension consent, Keychain vault, Universal 2 hardware coverage and Gatekeeper/XProtect coexistence.

Linux integration

Exact distro/kernel/filesystem support, fanotify mediation, confined services, signed native packages and verified package-manager rollback.

Measured efficacy

Dated, reproducible methodology plus maintained independent detection, false-positive, performance and compatibility evidence.

Safe operations

Signed staged updates, health halts, tested rollback, false-positive appeals, vulnerability intake, incident response and reliable support.

ZSEC Antivirus FAQ

Does ZSEC Antivirus replace Microsoft Defender, Malwarebytes or another antivirus?

ZSEC does not become the registered primary provider. On Windows, Community 0.3.31 can verify Microsoft Defender as the supported real-time enforcement engine and expose fixed Defender intelligence-update and scan actions. Its fail-closed handoff interlock reports blocked, operator-cutover-eligible or verified from live evidence, but ZSEC does not select or remove providers. Keep one supported primary provider active throughout any handoff. On macOS and Linux, keep native platform protections and any endpoint agent active.

Does ZSEC Antivirus upload my files?

No. File hashing, configured rule matching and quarantine processing occur locally. Community 0.3 has no sample-upload path; any separate opt-in service would require explicit destination, purpose, retention and sharing terms.

Is quarantine encryption automatic?

After an operator explicitly enables quarantine for a scan, Community 0.3 creates and protects the required key automatically. Scan scope, quarantine enablement and restore remain visible operator choices.

What does ZBA do in ZSEC Antivirus?

Zero Boundary Algebra supplies typed lifecycle and provenance records for events such as quarantine, verification and recovery. Cryptographic security comes from established authenticated encryption, signatures and operating-system key protection—not from ZBA labels alone.

How does ZSEC Antivirus update desktop security intelligence?

Each installation checks the fixed ZSEC intelligence endpoint on its own daily schedule; it does not connect to the developer’s computer. A data-only updater validates the Ed25519 signature, schema, sequence, expiry and SHA-256 before atomic installation. The last valid feed stays active after a failed check, and advisory text never becomes an automatic malware signature or remote command.

Is every ZSEC Antivirus component open source?

No. ZSEC Antivirus follows an open-core model. The scanner, data-only feed verifier, quarantine format, ZBA records, browser rules and public specifications are intended to remain auditable. Optional OEM engines, signing infrastructure and managed services may be separately licensed and are labelled as such.

Download it. Verify it. Start with a test folder.

Community 0.3.31 packages the Windows graphical client; the separate Windows, macOS and Linux core CLI companions remain 0.3.14. No release-specific installed-runtime result is claimed for the 0.3.31 direct archive; macOS and Linux archives have tagged workflow provenance but remain unsigned and unverified on physical target desktops. Keep the existing primary provider and native platform protections active.