KAM Security now stays with you from sign-in, asks Windows before it changes anything machine-wide, runs Defender's scans exactly the way Windows Security does, and tells you when a newer version is out.
What is new since v0.4.0
There from sign-in, by the clock. The first time KAM Security opens, it adds itself to your sign-in items and starts in the notification area with no window, so it costs nothing until you open it. It is on by default and says so on the Overview, beside the checkbox that turns it off. Closing the window leaves the icon, and the tray's Close the icon (protection keeps running) does what it says: the service carries on either way. Protection itself is switched off only by the switch inside the app.
Windows' own permission prompt for machine-wide changes. The service runs as LocalSystem and could make any change on the machine, so it now refuses to make one the person could not make themselves. Defender's protections, audit policy, firewall rules, the protection switch, and clearing a cache outside your own profile all need a caller Windows has elevated, read from the caller's own token before any handler runs. The window never runs elevated: it raises the ordinary Windows prompt, and an approved copy makes that one change and exits. Declining says nothing was changed.
Scans are Windows Security's scans. A quick or full scan started here is now the same scan as the button in Windows Security, so Defender deals with what it finds the way it is set up to, usually by quarantining it where Windows Security can restore it. v0.4.0 started them with Defender's report-only switch, which MpCmdRun's own help says is valid only for custom scans, and which could keep a finding out of the history KAM reads afterwards. A scan of a single path still reports without acting. Detections now carry Defender's name, severity and category for them, and every documented failure status is mapped, so "quarantine failed" can no longer read as "no longer present".
Defender's settings, read from where Defender keeps them. Potentially unwanted app blocking is read from PUAProtection, and audit mode now shows as "auditing only" instead of "not configured". Cloud-delivered protection is read from MAPSReporting; it had been read from the download-scanning switch, which is a different setting and now has a row of its own. A setting an organisation's policy controls says so and offers no button, because a change made here would be undone.
Update check. Once a day, or when you press Check now on the Overview, KAM asks GitHub for the newest release and shows its version, date and notes, with a button that opens the release page. It sends nothing about the machine and never downloads or installs anything: a program with a LocalSystem service should not install updates by itself until its releases are signed. A check that fails says it could not tell. It never says you are up to date when it does not know. The daily check can be switched off.
Also fixed
- A failed read of Defender's history, before or after a scan, used to fall back to an empty list, so every past detection looked new or a failed read looked like a clean result. Both now say what could not be read.
- WMI failures were discarded and read as "no rows". They are now errors, and each read gives up after thirty seconds instead of waiting forever.
- Defender's console output was captured and never read, which could stall a long scan until its four-hour timeout.
- The tray icon no longer freezes when the pointer rests on it.
- Three control characters had crept into source files where escapes were meant, and one of them quietly stopped a test covering what it is named for.
Install
Unzip anywhere, keeping every file in one folder: the agent only serves clients installed alongside it, so separating them stops the shell working. Then right-click setup.ps1 and choose Run with PowerShell, or from a terminal:
powershell -ExecutionPolicy Bypass -File setup.ps1
It asks for administrator rights once, secures the folder, registers the service that makes the fast disk scan possible, and puts a shortcut on your desktop. The first time you open KAM Security it adds itself to your sign-in items, so its icon sits by the clock; untick Start KAM Security when I sign in on the Overview to stop that.
To remove all of it:
powershell -ExecutionPolicy Bypass -File setup.ps1 -Remove
The sign-in entry belongs to the app rather than the script, so untick that box first if you are removing KAM for good.
Upgrading from v0.4.0: run setup.ps1 -Remove from the old folder, then set up this release the same way. Quarantined items and the audit log are kept. Always replace both executables together.
These binaries are not signed
SmartScreen will warn on first run, and some antivirus products may flag them. That is expected for an unsigned tool that enumerates every file on disk and runs an elevated service. Verify the checksum against SHA256SUMS.txt, and build from source if you would rather not trust a download.