Windows desktop 0.3.31 · Windows, macOS and Linux core CLI 0.3.14

Install automatic post-change file monitoring.

On Windows, ZSEC Antivirus automatically watches Desktop, Documents and Downloads with native file events, scans changed files locally, verifies signed data-only rules and can move exact configured matches into authenticated encrypted quarantine. The graphical protection centre requires no folder selection for this default coverage.

Install boundary: these unsigned Community packages detect after filesystem changes rather than at the kernel access boundary. The Windows graphical 0.3.31 package comes from immutable revision 8b3d8f4da941dac1f0ca0945f58ab9155ec28390; the separate core 0.3.14 assets remain at revision 57557ae4dd03765a59b05a3a0e0006edc13b7bd4. ZSEC is not publisher-signed, independently efficacy-tested or qualified as a primary antivirus. Verify exact SHA-256 values and keep Microsoft Defender or another supported primary provider, plus native platform controls, active.

A full local dashboard with a verifiable Community package.

The Community 0.3.31 client exposes overview, scans, an evidence-led scope/elapsed-time scan rail, crash-resilient bounded automatic monitoring, native tray controls, transactional startup repair, encrypted quarantine, hourly Defender definition-health maintenance, separate daily signed advisory checks, reports, evidence-backed Windows Security health, up to 20 sanitized local Defender Protection History records, three fixed Defender actions, read-only Defender Network Protection posture, security/YubiKey status, replacement blockers, settings and bounded review-only PE, Authenticode, script-chain and ZIP safety evidence in one interface. Protection History omits affected paths, process names and usernames; inaccessible history remains unavailable rather than clean. Concurrent health readers no longer terminate monitoring, transient Windows path-resolution races are retried, lifecycle path-boundary tests pass on Windows, Ubuntu and macOS, and persistent scope gaps remain a visible amber coverage review. Review observations never authorise quarantine, and ZSEC does not silently change Defender preferences.

Implemented in the prepared package

  • Modern dark protection centre with persistent navigation, responsive evidence cards, animated operation status and reduced-motion support.
  • Indeterminate scan evidence rail shows real scope and elapsed time without inventing a completion percentage; final severity comes only from the validated report.
  • Bounded local Defender Protection History includes detection/remediation status while omitting file paths, processes and usernames.
  • Concurrent bounded event ingestion during baseline, coalescing repeated activity without silently losing coverage.
  • Five-control authenticated recovery self-test: encrypted copy, restore, no-overwrite, tamper rejection and device-key recovery.
  • Path-free bounded exact-rule worker with independent broker SHA-256 verification and fail-closed protocol outcomes.
  • Automatic companion installation with executable, process, startup registration and fresh-heartbeat verification.
  • Windows PowerShell 5.1 clean-install paths tested with omitted roots; explicit empty roots fail closed.
  • The package contains no provider-removal or Defender-preference automation.

Primary-provider replacement readiness

  • No publisher Authenticode signature or trusted timestamp.
  • The exact-rule worker is same-user process separation, not an AppContainer hostile-parser sandbox.
  • No protected service, kernel pre-access mediation or Windows Security provider registration.
  • No independently validated efficacy or false-positive benchmark and no provider removal path.

Windows desktop release notes and provenance

Microsoft Store boundary: the earlier separately packaged unsigned 0.3.30 Store candidate recorded an overall WACK pass but remains unsubmitted. Version 0.3.31 Store materials are draft-only; this direct-download page does not claim a 0.3.31 Store package, Partner Center acceptance, Store signing, clean-VM Store installation or public Store availability.

Install the graphical client: extract the verified ZIP into a new folder, review DESKTOP.md, open Windows PowerShell in that folder and run .\Install-ZsecAntivirusDesktop.ps1 -PlanOnly. Review the plan, then run .\Install-ZsecAntivirusDesktop.ps1 -Open. The installer preserves the existing Windows protection provider and activates the per-user companion transactionally.

Archive: 33,854,891 bytes · SHA-256: 3177951175510a0d992080f99dfa9d43f70d14ee4255492e1d7a8114c629752c

Checksum sidecar: 115 bytes · SHA-256: d7fa3c39278b03853eb98050300ce2fa1977bfb6d60115c2c3b4f7111fb67e9f. The package and both ZSEC executables remain unsigned.

Update boundary: Microsoft supplies Defender’s real malware definitions. ZSEC checks active Defender health hourly and requests a definition refresh only when Defender reports stale or missing material. The separately signed ZSEC catalog is advisory-only and creates no malware rule. Application updates remain notification-only until publisher signing is available. ZSEC does not register as the primary provider.

Protection boundary: Microsoft Defender supplies supported Windows real-time and on-access enforcement when live evidence confirms it active. ZSEC adds a native observer, fast automatic metadata inventory, content hashing for new and changed files, periodic full-content reconciliation, deterministic exact rules, encrypted quarantine and recovery evidence. Application or advisory metadata cannot disable, remove, select or reconfigure the active provider.

Verification evidence: ZIP integrity testing passed. All 1,107 manifest-declared payload files were present with no extra payload entry, and every declared size and SHA-256 matched. Installed-runtime acceptance independently matched the GUI and engine hashes and version, verified companion process, integrity, heartbeat and startup registration, and confirmed Microsoft Defender remained active and unchanged. No independent malware-efficacy result or reproducible second-build claim is made.

Inspect the immutable Windows GUI source, the exact worker boundary and the hash-verifying installer scripts. The Windows desktop assets are separate from the v0.3.14 core CLI set below.

Download the exact build for this computer.

The ten core release assets come from immutable source revision 57557ae4dd03765a59b05a3a0e0006edc13b7bd4, were generated by the tagged workflow and carry Sigstore/SLSA attestations. The macOS and Linux packages are unsigned command-line companions, not graphical applications or primary antivirus providers. A mismatch means stop and delete the download.

Windows x86-64

Self-contained ZIP for Windows 10 or 11. Extract it before starting the executable.

Download Windows ZIP

13,437,103 bytes · Checksum · e822570ea5472b45643350d02d910688f185a2b4917efb48251b652444ffb591

macOS native

Self-contained tar archive built and smoke-tested on the declared macOS architecture.

Download macOS archive

12,805,932 bytes · Checksum · 81d28ff2f7077bf779e67363ba28dd107d66d3982d38d8463d197ff10faea950

Linux x86-64

Self-contained tar archive for a supported x86-64 Linux test environment.

Download Linux archive

24,240,917 bytes · Checksum · 2d947e8788039aef57bafa8bcd161e9dba891e5a36c6adacc9dc5d868f7f0517

Portable Python packages

Advanced users on Windows, macOS or Linux can install the 106,309-byte universal Python 3.11+ wheel with pipx install zsec_shield-0.3.14-py3-none-any.whl. Download wheel · 4eb3f1aba3734dcef323285177cc6719b0bf63bdd3f2e1152db586046d4be968

The 350,963-byte source distribution is zsec_shield-0.3.14.tar.gz · 16b7bee7c06117b0084e6ee076bb9f4b2319a1d8fbfbbdd4633003074501b03f. Verify both with the 194-byte Python checksum index, SHA-256 cda17bed0ce5f7cd9446e325579d9e402611c0cae697598645384154b2aba3cb.

Exact core checksum-file identities

The 507-byte native checksum index has SHA-256 279bdea77397c9f01da14133b70883b2c35db7d94d1a1824e5121b4b05e3f708. Individual sidecars: Windows, 104 bytes, 19115a5ee44e30fa41628f4dbd092eea9f21456c27197f0c2915a5f6751f97a0; macOS, 104 bytes, 8e26fdfe1ba82bfee37349cd2c6c1e9e3d495767e6900f1cb74dcbe2daf31247; Linux, 105 bytes, a778ec428561d9116cd0d1c60471a126af952b402030cacf27cacf7c27e38e94.

Verify, extract, inspect, then run.

Use a test folder first. Each archive includes its platform companion, status command, uninstall path, manifests and licences.

Verify SHA-256

Windows: Get-FileHash .\zsec-shield-*.zip -Algorithm SHA256. macOS: shasum -a 256 zsec-shield-*.tar.gz. Linux: sha256sum zsec-shield-*.tar.gz.

Extract the archive

Keep the extracted folder together. The executable, libraries, manifest, licences and threat-model documents form one reviewed bundle.

Review the install plan

Run the included installer in plan mode. Confirm the automatic Desktop, Documents and Downloads roots, state path, CLI/runtime hashes and per-user supervisor before it writes anything.

Install and verify health

Start the per-user companion, then use the included status script to verify its supervisor, executable hashes and fresh 30-second heartbeat.

Install once for automatic user-session protection.

The per-user supervisor starts at login, pins the CLI/runtime by SHA-256 and writes bounded health evidence. The native observer starts before the metadata inventory; an owned stopped companion is automatically restarted only after its launcher, runtime and configuration integrity are verified.

Windows automatic companion

.\Install-ZsecAntivirusCompanion.ps1 -CliPath .\zsec-shield.exe -EnableQuarantine -StartNow

macOS or Linux automatic companion

sh ./install.sh --cli "$PWD/zsec-shield" then sh ./status.sh. Use the matching platform archive only.

Windows quarantine is enabled only by the explicit installer switch shown above. macOS/Linux packages start in detection-only mode; all three include a state-preserving uninstall path.

Useful companion protection, not replacement antivirus.

ZSEC Antivirus Windows desktop 0.3.31 performs local exact-rule scanning after filesystem activity, supervises that monitor with bounded automatic restart, aggregates high-volume path-disappearance evidence, retries brief path-resolution races, verifies active Defender definition health, receives a separate signed advisory catalog, and can encrypt configured matches for recovery. It does not mediate file access, inspect process memory or behaviour, filter network traffic, register with Windows Security, run as a protected service, or provide independently certified detection efficacy.

That boundary is enforced in code: replacement-readiness returns a non-success decision with keep_existing_protection, and there is no override.

AvailableNative event watch + deterministic local scan
OptionalAuthenticated encrypted quarantine
Not shippedKernel pre-access blocking + primary-provider registration

Keep existing antivirus and OS controls active.

Add ZSEC Browser Shields.

ZSEC Browser Shields Community 0.5.2 contains 49,464 pinned EasyList network rules, 39 focused privacy rules, two link-cleaning rules, 19 selected EasyList-derived YouTube cosmetic selectors, local per-site controls and optional High-Risk Browsing. Acceptable Ads is not included. It is an unsigned, manually installed Manifest V3 extension—not a spyware detector.