The course
Windows, floor by floor
Eleven levels, grouped into the same bands as the diagram below — User Mode, the Executive, the kernel, virtualization, and the HAL/hardware floor — ordered top to bottom exactly like the real Windows architecture. Each level builds on the one below it.
Read first
System architecture
The map of every layer below — start here before Level 0.
The course, same bands as above
User Mode
L0Applications, the loader & the Win32 environmentInteractiveWhat runs when you double-click something: PE images, the DLL loader, WOW64, and the Win32 environment (CSRSS, Win32k, windows and desktops) apps live inside.CreateProcess → LoadLibrary- L1System support processes & servicesThe privileged processes that aren't apps and aren't the kernel: Winlogon, the Service Control Manager, and the svchost hosts that run most of Windows.services.exe → svchost.exe
- L2Security & authenticationInteractiveTokens, ACLs, UAC and the Security Reference Monitor that checks every access above — plus LSASS, Kerberos/NTLM and the crypto plumbing behind logon. The diagram's "Security" box in the Integral subsystems.AccessCheck(token, sd, …)
Kernel Mode — the Executive
L3IPC & component boundariesHow the processes above talk to each other and to the kernel: named pipes, RPC/COM, and the ALPC primitive underneath them — the Executive's IPC Manager.RpcBindingFromStringBinding()- L4The Executive: objects, processes & memoryInteractiveThe core kernel-mode managers every subsystem above is built on: the Object Manager, the Process/Thread Manager, and the Memory Manager.ZwCreateProcess() → EPROCESS
- L5I/O, storage & the cache managerHow the Executive turns a read() into a device stack request: the I/O Manager, PnP/power, drivers, volumes, file systems, and the cache manager.IRP → IoCallDriver()
- L6NetworkingThe stack above the I/O Manager: Winsock/AFD, TCP/IP, filtering (WFP), and the NDIS drivers that reach the actual adapter.socket() → AFD → tcpip.sys
- L7Configuration & the registryThe Configuration Manager: how hives, keys and values become the database every layer above reads its settings from.HKLM\SYSTEM\CurrentControlSet
Kernel Mode — the kernel
L8The kernel: scheduling, interrupts & synchronizationInteractiveBeneath the Executive: IRQL, ISRs, DPCs, and the scheduler that decides which thread actually runs next.IRQL: PASSIVE → DISPATCH → …Virtualization
L9Virtualization & the hypervisorHow Hyper-V virtualizes the hardware beneath the kernel itself, and how VBS/HVCI uses that same boundary for isolation.root partition ↔ child partitionBoot, HAL & hardware
L10Boot, HAL & hardwareInteractiveThe floor of the stack: firmware, secure boot, the boot manager, the HAL, and the session-manager handoff that brings everything above to life.UEFI → winload.efi → ntoskrnl.exe
Cross-cutting: the diagnostics toolkit
The event log, ETW, and WMI aren't a layer of the OS — they're the instruments you use to observe every layer above. Read them alongside whichever level you're on.