The course

Windows, floor by floor

Eleven levels, grouped into the same bands as the diagram below — User Mode, the Executive, the kernel, virtualization, and the HAL/hardware floor — ordered top to bottom exactly like the real Windows architecture. Each level builds on the one below it.

Read first

System architecture

The map of every layer below — start here before Level 0.

Win32ApplicationPOSIXApplicationOS/2ApplicationWork-stationServiceServerserviceSecurityIntegral subsystemsWin32POSIXOS/2Environmental subsystemsUser ModeExecutive ServicesI/OManagerSecurityReferenceMonitorIPCManagerVirtualmemoryManager(VMM)ProcessManagerPnPManagerPowerManagerWindowsManagerGDIObject ManagerExecutiveKernel Mode DriversMicro KernelHardware abstraction Layer (HAL)Kernel ModeHardware

The course, same bands as above

  1. User Mode

    L0Applications, the loader & the Win32 environmentInteractiveWhat runs when you double-click something: PE images, the DLL loader, WOW64, and the Win32 environment (CSRSS, Win32k, windows and desktops) apps live inside.CreateProcess → LoadLibrary
  2. L1System support processes & servicesThe privileged processes that aren't apps and aren't the kernel: Winlogon, the Service Control Manager, and the svchost hosts that run most of Windows.services.exe → svchost.exe
  3. L2Security & authenticationInteractiveTokens, ACLs, UAC and the Security Reference Monitor that checks every access above — plus LSASS, Kerberos/NTLM and the crypto plumbing behind logon. The diagram's "Security" box in the Integral subsystems.AccessCheck(token, sd, …)
  4. Kernel Mode — the Executive

    L3IPC & component boundariesHow the processes above talk to each other and to the kernel: named pipes, RPC/COM, and the ALPC primitive underneath them — the Executive's IPC Manager.RpcBindingFromStringBinding()
  5. L4The Executive: objects, processes & memoryInteractiveThe core kernel-mode managers every subsystem above is built on: the Object Manager, the Process/Thread Manager, and the Memory Manager.ZwCreateProcess() → EPROCESS
  6. L5I/O, storage & the cache managerHow the Executive turns a read() into a device stack request: the I/O Manager, PnP/power, drivers, volumes, file systems, and the cache manager.IRP → IoCallDriver()
  7. L6NetworkingThe stack above the I/O Manager: Winsock/AFD, TCP/IP, filtering (WFP), and the NDIS drivers that reach the actual adapter.socket() → AFD → tcpip.sys
  8. L7Configuration & the registryThe Configuration Manager: how hives, keys and values become the database every layer above reads its settings from.HKLM\SYSTEM\CurrentControlSet
  9. Kernel Mode — the kernel

    L8The kernel: scheduling, interrupts & synchronizationInteractiveBeneath the Executive: IRQL, ISRs, DPCs, and the scheduler that decides which thread actually runs next.IRQL: PASSIVE → DISPATCH → …
  10. Virtualization

    L9Virtualization & the hypervisorHow Hyper-V virtualizes the hardware beneath the kernel itself, and how VBS/HVCI uses that same boundary for isolation.root partition ↔ child partition
  11. Boot, HAL & hardware

    L10Boot, HAL & hardwareInteractiveThe floor of the stack: firmware, secure boot, the boot manager, the HAL, and the session-manager handoff that brings everything above to life.UEFI → winload.efi → ntoskrnl.exe

Cross-cutting: the diagnostics toolkit

The event log, ETW, and WMI aren't a layer of the OS — they're the instruments you use to observe every layer above. Read them alongside whichever level you're on.