Skip to content

Releases: Ari-Joon/KAM-Security

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 23 Sep 09:39

KAM Security now stays with you from sign-in, asks Windows before it changes anything machine-wide, runs Defender's scans exactly the way Windows Security does, and tells you when a newer version is out.

What is new since v0.4.0

There from sign-in, by the clock. The first time KAM Security opens, it adds itself to your sign-in items and starts in the notification area with no window, so it costs nothing until you open it. It is on by default and says so on the Overview, beside the checkbox that turns it off. Closing the window leaves the icon, and the tray's Close the icon (protection keeps running) does what it says: the service carries on either way. Protection itself is switched off only by the switch inside the app.

Windows' own permission prompt for machine-wide changes. The service runs as LocalSystem and could make any change on the machine, so it now refuses to make one the person could not make themselves. Defender's protections, audit policy, firewall rules, the protection switch, and clearing a cache outside your own profile all need a caller Windows has elevated, read from the caller's own token before any handler runs. The window never runs elevated: it raises the ordinary Windows prompt, and an approved copy makes that one change and exits. Declining says nothing was changed.

Scans are Windows Security's scans. A quick or full scan started here is now the same scan as the button in Windows Security, so Defender deals with what it finds the way it is set up to, usually by quarantining it where Windows Security can restore it. v0.4.0 started them with Defender's report-only switch, which MpCmdRun's own help says is valid only for custom scans, and which could keep a finding out of the history KAM reads afterwards. A scan of a single path still reports without acting. Detections now carry Defender's name, severity and category for them, and every documented failure status is mapped, so "quarantine failed" can no longer read as "no longer present".

Defender's settings, read from where Defender keeps them. Potentially unwanted app blocking is read from PUAProtection, and audit mode now shows as "auditing only" instead of "not configured". Cloud-delivered protection is read from MAPSReporting; it had been read from the download-scanning switch, which is a different setting and now has a row of its own. A setting an organisation's policy controls says so and offers no button, because a change made here would be undone.

Update check. Once a day, or when you press Check now on the Overview, KAM asks GitHub for the newest release and shows its version, date and notes, with a button that opens the release page. It sends nothing about the machine and never downloads or installs anything: a program with a LocalSystem service should not install updates by itself until its releases are signed. A check that fails says it could not tell. It never says you are up to date when it does not know. The daily check can be switched off.

Also fixed

  • A failed read of Defender's history, before or after a scan, used to fall back to an empty list, so every past detection looked new or a failed read looked like a clean result. Both now say what could not be read.
  • WMI failures were discarded and read as "no rows". They are now errors, and each read gives up after thirty seconds instead of waiting forever.
  • Defender's console output was captured and never read, which could stall a long scan until its four-hour timeout.
  • The tray icon no longer freezes when the pointer rests on it.
  • Three control characters had crept into source files where escapes were meant, and one of them quietly stopped a test covering what it is named for.

Install

Unzip anywhere, keeping every file in one folder: the agent only serves clients installed alongside it, so separating them stops the shell working. Then right-click setup.ps1 and choose Run with PowerShell, or from a terminal:

powershell -ExecutionPolicy Bypass -File setup.ps1

It asks for administrator rights once, secures the folder, registers the service that makes the fast disk scan possible, and puts a shortcut on your desktop. The first time you open KAM Security it adds itself to your sign-in items, so its icon sits by the clock; untick Start KAM Security when I sign in on the Overview to stop that.

To remove all of it:

powershell -ExecutionPolicy Bypass -File setup.ps1 -Remove

The sign-in entry belongs to the app rather than the script, so untick that box first if you are removing KAM for good.

Upgrading from v0.4.0: run setup.ps1 -Remove from the old folder, then set up this release the same way. Quarantined items and the audit log are kept. Always replace both executables together.

These binaries are not signed

SmartScreen will warn on first run, and some antivirus products may flag them. That is expected for an unsigned tool that enumerates every file on disk and runs an elevated service. Verify the checksum against SHA256SUMS.txt, and build from source if you would rather not trust a download.

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 09:10

The machine can now be compared with itself, protection runs whether or not the window is open, and a round of adversarial review closed several ways an ordinary user could have borrowed the agent's LocalSystem rights.

What is new since v0.3.0

Changes: what is different since last time. Every other view reports what is true now. This one reports what is different — services, Run keys, Startup items, scheduled tasks and local administrators, compared against a baseline and charted over twelve weeks. There is no score, because a score needs an idea of what a correct machine looks like and this software does not have one. Things disappearing count at least as much as things appearing: an antivirus service or a backup task quietly removed gets reported, and Windows reports that nowhere else. It also notices when an entry's path stays the same but the file behind it is now signed by someone else, or by nobody. Changes this program made itself are labelled rather than hidden, so malware can't hide by using its name. A source that could not be read is named as unread, never reported as empty.

Protection is always on, with one switch. The agent restarts itself 5, 15 and 60 seconds after a crash, which it never managed before: the restart settings were silently failing to apply. Overview → Protection turns the watching off within seconds without stopping the service, because a security tool that can be silenced through its own window is one an attacker silences.

Scanner. Quick and full Defender scans start from here. Defender is told to report rather than remove, so what it finds stays put and is dealt with through the fenced, audited quarantine. Findings are read from Defender's own records, not from its console output, and a scan that was stopped never shows as a clean result. The on/off protections beside Attack Surface Reduction are now read and explained. Anything off can be switched on, audit mode first, and the result is read back from Defender instead of assumed. The rules are shown as a grid.

Firewall. Connections are grouped by program, with what each program says it is shown separately from who actually signed it. A map shows publishers by area and drills into their programs. Each program lists what is worth noticing instead of a risk score. A signed program listening on all interfaces is no longer drawn as "staying on this machine".

Cleanup. Removal goes to the Recycle Bin or to quarantine; the one-step permanent delete is gone. Where the Recycle Bin cannot work, the row says so instead of offering a button that fails. You can pick which duplicate copy to keep. Everything measured is drawn to scale in one map. Clearing a cache that costs something, such as Windows.old, now says what it costs and asks first.

Starts on a clean Windows install. kam-agent.exe needed the Visual C++ Redistributable, and on a machine without it the service simply would not start. The C runtime is now built into the binary, and a test fails if that dependency comes back. setup.ps1 registers the service, locks down the install folder and puts a shortcut on the desktop. -Remove undoes it.

Security fixes

Found by adversarial review and each fixed with a regression test. Every test was checked by disabling its guard and watching it fail.

  • Deleting through a junction. A user could replace a cache folder with a junction, and the next Clear would permanently delete whatever it pointed at, as LocalSystem. The folder is now opened once and held open for the whole walk, so the swap fails instead of racing.
  • Quarantine ids reached outside the store. An absolute path or .. in an id could delete directories anywhere, and restoring could write a file to any path as LocalSystem. Ids are now checked against the exact format the store issues.
  • powershell.exe resolved from the agent's folder. A planted copy beside the agent would have run as LocalSystem at the next click on the hardening panel. It is now named by absolute path.
  • A writable install folder. Unzipping into Downloads or the Desktop leaves the folder writable by any user, who could then drive the service or replace the agent. Installation now refuses such a folder, and setup.ps1 locks it down.
  • The audit log's directory was writable. A planted SQLite write-ahead log could rewrite the append-only audit log underneath the triggers that protect it. The agent now locks the directory before opening the database, at every start.
  • Named-pipe squatting. The protection against another process squatting the pipe name switched itself off after its first failure. A newline in a refused path could forge a line in the audit log. And one panic could disable auditing until reboot. All three are fixed.
  • Paths judged by their spelling. The removal checks looked at the path text instead of what it pointed to, so ::$INDEX_ALLOCATION, 8.3 short names and plain prefix matches all got past them. Paths are now resolved before they are judged.

Also fixed

  • The agent reported itself as the most suspicious program on the machine, and drew itself red on the firewall map. It is now identified as this program, still described as unsigned, and never exempted from anything.
  • The agent tripped its own canaries every two minutes when checking that its decoys were intact.
  • Two quarantined items could end up sharing one id, and a restore could then put a file back in the wrong place.

Registry canaries are switched off again

v0.3.0 introduced decoy PuTTY, WinSCP and Remote Desktop sessions. They reported themselves as planted and watched while reg.exe, Test-Path and .NET could not see them, and a decoy nothing can find is never read. They sit behind a flag until the cause is confirmed under the service account. File canaries are unaffected and verified working.

Install

Unzip anywhere, keeping every file in one folder — the agent only serves clients installed alongside it, so separating them stops the shell working. Then right-click setup.ps1 and choose Run with PowerShell, or from a terminal:

powershell -ExecutionPolicy Bypass -File setup.ps1

It asks for administrator rights once, registers the service that makes the fast disk scan possible, and puts a shortcut on your desktop. It adds nothing to the run keys and does not open the window at logon.

To remove all of it:

powershell -ExecutionPolicy Bypass -File setup.ps1 -Remove

Upgrading from an earlier version: replace both executables together. The protocol version has changed, and the window refuses to talk to an agent of a different version.

These binaries are not signed

SmartScreen will warn on first run, and some antivirus products may flag them. That is expected for an unsigned tool that enumerates every file on disk and runs an elevated service. Verify the checksum against SHA256SUMS.txt, and build from source if you would rather not trust a download.

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 21:26

Canaries now cover the registry as well as your documents.

What is new since v0.2.0

Decoy saved connections in the registry. Documents were only half of where a
thief looks. PuTTY keeps every saved session in the registry with its hostname
and username; WinSCP keeps its sessions there with a reversibly-encrypted
password beside them; the Remote Desktop client records the machines you have
connected to and the account you used. Infostealers enumerate all three, because
that is what maps out the rest of your estate. So there are decoy sessions there
now too, watched the same way, and a read comes back naming the process that did
it.

Each decoy is a subkey alongside any real ones — never a value inside somebody's
own session — and is named KAM-Security-decoy-do-not-use, so anyone who finds
one in their own PuTTY list can tell at a glance that it is not theirs. A stealer
enumerates every session under those paths rather than opening one by name, so a
decoy does not need to deceive anybody to be found.

Switching canaries on now enables both audit subcategories. Registry auditing
is separate from file auditing in Windows, and having only half of it set
produced no registry events at all while looking perfectly healthy — the failure
mode a canary must never have, because it is indistinguishable from an all-clear.

Three fixes that came from running it rather than reading it

  • The registry canaries armed correctly and caught nothing. Windows names a
    registry object in the kernel's namespace with a hive prefix that depends on
    which account is asking, and the code built the expected name from the caller's
    SID — which the agent has and the shell does not. Trips now match on the tail
    of the path, which carries the decoy's own distinctive name.
  • A careless edit had put the planting call inside the read-only status check,
    which the window polls every few seconds. That would have created decoys on a
    machine whose owner never asked for any.
  • The tests genuinely contend on the registry: a scratch profile gives a test its
    own directory, but there is no scratch hive. The tests that touch it are now
    serialised.

Install

Unzip anywhere. Keep both executables in the same folder — the agent only
serves clients installed alongside it, so separating them stops the shell
working.

Run kam-shell.exe. For the fast disk scan, the behaviour watcher and the
canaries, install the agent as a service from an administrator terminal:

kam-agent.exe --install
sc start KamSecurityAgent

Canaries are off until you turn them on, and turning them on is two deliberate
steps: planting the decoys writes files and registry keys, and switching on
Windows' auditing changes a machine-wide setting. Both are reversible and both
are recorded in the audit log.

These binaries are not signed

SmartScreen will warn on first run, and some antivirus products may flag them.
That is expected for an unsigned tool that enumerates every file on disk and runs
an elevated service. Verify the checksum against SHA256SUMS.txt, and build from
source if you would rather not trust a download.

There is still no installer. That and the lack of signing are recorded as
deliberate decisions in PLAN.md rather than oversights.

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 20:27

Everything new in this release came out of one real infection: a credential
stealer that Microsoft Defender never flagged, which relaunched itself through
MSBuild from a hidden scheduled task and was still sitting there a day later. A
full offline Defender scan removed one dropped file; the launcher and the
persistence survived it. Each feature below closes a specific gap that let that
happen.

What is new since v0.1.0

Canary files. Decoy files that exist only to be stolen — a fake saved-password
database, a fake wallet, a fake recovery phrase. Nothing on the machine uses
them, so a read has no innocent explanation. Windows' own auditing records which
process read one, and which account it ran as. No driver, no third party,
nothing on the network. This closes the gap the watcher could not: the theft
itself, which in the original case was over in about three minutes.

A behaviour watcher. The agent now takes a cheap snapshot every two minutes
and records anything newly registered to start itself in the shape unwanted
software uses — a launcher running a script from a writable folder, a hidden
scheduled task, an unsigned script in AppData. It writes to the audit log and
the window, and never acts on its own.

Launcher-aware persistence. The scanner resolves what a launcher is told to
run and judges that. A stealer's script hiding behind cmd.exe /c is no longer
scored as "signed by Microsoft, lives in System32", which is exactly what let the
original task look like part of Windows.

A browser extension inventory. An extension that can read every page is in
practical terms a program holding your passwords and session cookies, and it has
no signature to check and starts nothing at boot — so the rest of the tool was
blind to it. It calls nothing malicious; it reports what each one may do.

A Defender hardening report. Windows ships nineteen Attack Surface Reduction
rules, free and switched off. Seven are worth recommending and three target this
exact attack. It reports which are on and what each would prevent, and
deliberately refuses to switch them on for you.

Two new YARA rules: browser credential theft, and a build tool used as a
loader.

Install

Unzip anywhere. Keep both executables in the same folder — the agent only
serves clients installed alongside it, so separating them stops the shell
working.

Run kam-shell.exe. For the fast disk scan and the behaviour watcher, install
the agent as a service from an administrator terminal:

kam-agent.exe --install
sc start KamSecurityAgent

These binaries are not signed

SmartScreen will warn on first run, and some antivirus products may flag them.
That is expected for an unsigned tool that enumerates every file on disk and runs
an elevated service. Verify the checksum against SHA256SUMS.txt, and build from
source if you would rather not trust a download.

There is still no installer, and the binaries are still unsigned. Both are
recorded as deliberate decisions in PLAN.md rather than oversights.

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 17:47

Install

Unzip anywhere. Keep both executables in the same folder — the
agent only serves clients installed alongside it, so separating them
stops the shell working.

Run kam-shell.exe. For the fast disk scan, install the agent as a
service from an administrator terminal:

kam-agent.exe --install
sc start KamSecurityAgent

These binaries are not signed

SmartScreen will warn on first run, and some antivirus products may
flag them. That is expected for an unsigned tool that enumerates
every file on disk and runs an elevated service. Verify the checksum
against SHA256SUMS.txt, and build from source if you would rather
not trust a download.