Windows · macOS · Linux · version 0.3.0

Automatic file monitoring you can verify.

ZSEC Antivirus 0.3 can watch selected folders using native operating-system file events, scan changed files locally, verify signed data-only rules and place configured matches into authenticated encrypted quarantine when you explicitly enable it.

Install boundary: these unsigned website evaluation packages are built from draft pull request #5 and detect after filesystem changes rather than at the kernel access boundary. The newer Windows graphical client is source/local-evidence only at immutable revision 394d97b; its public native download remains gated by publisher signing and release qualification. Verify exact SHA-256 values and keep Malwarebytes, Microsoft Defender or native platform controls active.

A full local dashboard, with public distribution still gated.

The installed Community 0.3 client exposes overview, scans, automatic monitoring, encrypted quarantine, signed feeds, reports, evidence-backed health, security/YubiKey status, replacement blockers and settings in one interface.

Implemented and locally accepted

  • Modern dark protection centre with persistent navigation, rounded evidence cards, animated operation status and reduced-motion support.
  • Separate packaged scanner engine with strict JSON contracts and no command shell.
  • Manifest hash verification, versioned per-user install, Desktop and Start-menu shortcuts.
  • Existing Malwarebytes and Windows Security state preserved during install and test.

Public native release remains gated

  • No publisher Authenticode signature or trusted timestamp.
  • No protected service, kernel pre-access mediation or Windows Security provider registration.
  • No independently validated efficacy or false-positive benchmark.
  • No automatic removal of an existing antivirus provider.

Inspect the immutable Windows GUI source and the hash-verifying desktop installer scripts.

Download the exact build for this computer.

Every archive has a separate SHA-256 file and immutable source revision 2e46d12c345e853282af97214b35b3c3badaea86. A mismatch means stop and delete the download.

Windows x86-64

Self-contained ZIP for Windows 10 or 11. Extract it before starting the executable.

Download Windows ZIP

Checksum · 3929c3c496f21b202d46c636008b6b08571729eb3724437e377c46d58f70e6b1

macOS native

Self-contained tar archive built and smoke-tested on the declared macOS architecture.

Download macOS archive

Checksum · 9b8a5be5930daae9b1cdb603c423c1912bfbe7438b1fd79f71112f3669253cd4

Linux x86-64

Self-contained tar archive for a supported x86-64 Linux test environment.

Download Linux archive

Checksum · e25b61ec37db60faca94bb979fd5c20ce35b19364bb86a341e368dfce3ad0757

Portable Python package

Advanced users on Windows, macOS or Linux can install the universal Python 3.11+ wheel with pipx install zsec_shield-0.3.0-py3-none-any.whl. Download wheel · Python checksums

Verify, extract, inspect, then run.

Use a test folder first. Each archive includes its platform companion, status command, uninstall path, manifests and licences.

Verify SHA-256

Windows: Get-FileHash .\zsec-shield-*.zip -Algorithm SHA256. macOS: shasum -a 256 zsec-shield-*.tar.gz. Linux: sha256sum zsec-shield-*.tar.gz.

Extract the archive

Keep the extracted folder together. The executable, libraries, manifest, licences and threat-model documents form one reviewed bundle.

Review the install plan

Run the included installer in plan mode. Confirm the protected Downloads path, state path, CLI/runtime hashes and per-user supervisor before it writes anything.

Install and verify health

Start the per-user companion, then use the included status script to verify its supervisor, executable hashes and fresh 30-second heartbeat.

Install once for automatic user-session protection.

The per-user supervisor starts at login, pins the CLI/runtime by SHA-256 and writes bounded health evidence. The native observer starts before its baseline scan.

Windows automatic companion

.\Install-ZsecAntivirusCompanion.ps1 -CliPath .\zsec-shield.exe -EnableQuarantine -StartNow

macOS or Linux automatic companion

sh ./install.sh --cli "$PWD/zsec-shield" then sh ./status.sh. Use the matching platform archive only.

Windows quarantine is enabled only by the explicit installer switch shown above. macOS/Linux packages start in detection-only mode; all three include a state-preserving uninstall path.

Useful companion protection, not replacement antivirus.

ZSEC Antivirus 0.3 performs local exact-rule scanning after filesystem activity and can encrypt configured matches for recovery. It does not mediate file access, inspect process memory or behaviour, filter network traffic, register with Windows Security, run as a protected service, or provide independently certified detection efficacy.

That boundary is enforced in code: replacement-readiness returns a non-success decision with keep_existing_protection, and there is no override.

AvailableNative event watch + deterministic local scan
OptionalAuthenticated encrypted quarantine
Not shippedKernel pre-access blocking + primary-provider registration

Keep existing antivirus and OS controls active.

Add ZSEC Browser Shields.

ZSEC Browser Shields Community 0.4 contains 38 packaged network blockers, two link-cleaning rules, local per-site controls and optional High-Risk Browsing. It is an unsigned, manually installed Manifest V3 extension—not a standalone browser or spyware detector.