Windows graphical client
A full local dashboard with a verifiable Community package.
The Community 0.3.31 client exposes overview, scans, an evidence-led scope/elapsed-time scan rail, crash-resilient bounded automatic monitoring, native tray controls, transactional startup repair, encrypted quarantine, hourly Defender definition-health maintenance, separate daily signed advisory checks, reports, evidence-backed Windows Security health, up to 20 sanitized local Defender Protection History records, three fixed Defender actions, read-only Defender Network Protection posture, security/YubiKey status, replacement blockers, settings and bounded review-only PE, Authenticode, script-chain and ZIP safety evidence in one interface. Protection History omits affected paths, process names and usernames; inaccessible history remains unavailable rather than clean. Concurrent health readers no longer terminate monitoring, transient Windows path-resolution races are retried, lifecycle path-boundary tests pass on Windows, Ubuntu and macOS, and persistent scope gaps remain a visible amber coverage review. Review observations never authorise quarantine, and ZSEC does not silently change Defender preferences.
Implemented in the prepared package
- Modern dark protection centre with persistent navigation, responsive evidence cards, animated operation status and reduced-motion support.
- Indeterminate scan evidence rail shows real scope and elapsed time without inventing a completion percentage; final severity comes only from the validated report.
- Bounded local Defender Protection History includes detection/remediation status while omitting file paths, processes and usernames.
- Concurrent bounded event ingestion during baseline, coalescing repeated activity without silently losing coverage.
- Five-control authenticated recovery self-test: encrypted copy, restore, no-overwrite, tamper rejection and device-key recovery.
- Path-free bounded exact-rule worker with independent broker SHA-256 verification and fail-closed protocol outcomes.
- Automatic companion installation with executable, process, startup registration and fresh-heartbeat verification.
- Windows PowerShell 5.1 clean-install paths tested with omitted roots; explicit empty roots fail closed.
- The package contains no provider-removal or Defender-preference automation.
Primary-provider replacement readiness
- No publisher Authenticode signature or trusted timestamp.
- The exact-rule worker is same-user process separation, not an AppContainer hostile-parser sandbox.
- No protected service, kernel pre-access mediation or Windows Security provider registration.
- No independently validated efficacy or false-positive benchmark and no provider removal path.
Windows desktop release notes and provenance
Microsoft Store boundary: the earlier separately packaged unsigned 0.3.30 Store candidate recorded an overall WACK pass but remains unsubmitted. Version 0.3.31 Store materials are draft-only; this direct-download page does not claim a 0.3.31 Store package, Partner Center acceptance, Store signing, clean-VM Store installation or public Store availability.
Install the graphical client: extract the verified ZIP into a new folder, review DESKTOP.md, open Windows PowerShell in that folder and run .\Install-ZsecAntivirusDesktop.ps1 -PlanOnly. Review the plan, then run .\Install-ZsecAntivirusDesktop.ps1 -Open. The installer preserves the existing Windows protection provider and activates the per-user companion transactionally.
Archive: 33,854,891 bytes · SHA-256: 3177951175510a0d992080f99dfa9d43f70d14ee4255492e1d7a8114c629752c
Checksum sidecar: 115 bytes · SHA-256: d7fa3c39278b03853eb98050300ce2fa1977bfb6d60115c2c3b4f7111fb67e9f. The package and both ZSEC executables remain unsigned.
Update boundary: Microsoft supplies Defender’s real malware definitions. ZSEC checks active Defender health hourly and requests a definition refresh only when Defender reports stale or missing material. The separately signed ZSEC catalog is advisory-only and creates no malware rule. Application updates remain notification-only until publisher signing is available. ZSEC does not register as the primary provider.
Protection boundary: Microsoft Defender supplies supported Windows real-time and on-access enforcement when live evidence confirms it active. ZSEC adds a native observer, fast automatic metadata inventory, content hashing for new and changed files, periodic full-content reconciliation, deterministic exact rules, encrypted quarantine and recovery evidence. Application or advisory metadata cannot disable, remove, select or reconfigure the active provider.
Verification evidence: ZIP integrity testing passed. All 1,107 manifest-declared payload files were present with no extra payload entry, and every declared size and SHA-256 matched. Installed-runtime acceptance independently matched the GUI and engine hashes and version, verified companion process, integrity, heartbeat and startup registration, and confirmed Microsoft Defender remained active and unchanged. No independent malware-efficacy result or reproducible second-build claim is made.
Inspect the immutable Windows GUI source, the exact worker boundary and the hash-verifying installer scripts. The Windows desktop assets are separate from the v0.3.14 core CLI set below.