WIWindows Internals
LevelsExploreSearchGlossaryLabs
All levels

Level 2

Security & authentication

Tokens, ACLs, UAC and the Security Reference Monitor that checks every access above — plus LSASS, Kerberos/NTLM and the crypto plumbing behind logon. The diagram's "Security" box in the Integral subsystems.

  1. 1Security
  2. 2Access tokens
  3. 3Security descriptors & ACLs
  4. 4UAC, integrity levels, and the secure desktop
  5. 5Privileges (Se*)
  6. 6Access checks & the Security Reference Monitor
  7. 7AppContainers & capabilities
  8. 8LSASS, SAM, and local security policy
  9. 9Kerberos, NTLM, and authentication packages
  10. 10CNG, Schannel & crypto plumbing
  11. 11Protected Processes & PPL
  12. 12Exploit mitigations (CFG, ACG, ASLR, CIG)
  13. 13Application control: AppLocker & SRP
  14. 14Kernel Patch Protection (PatchGuard) & HyperGuard
L1 System support processes & servicesL3 IPC & component boundaries
  1. User Mode

    L0Applications, the loader & the Win32 environment
  2. L1System support processes & services
  3. L2Security & authentication
  4. Kernel Mode — the Executive

    L3IPC & component boundaries
  5. L4The Executive: objects, processes & memory
  6. L5I/O, storage & the cache manager
  7. L6Networking
  8. L7Configuration & the registry
  9. Kernel Mode — the kernel

    L8The kernel: scheduling, interrupts & synchronization
  10. Virtualization

    L9Virtualization & the hypervisor
  11. Boot, HAL & hardware

    L10Boot, HAL & hardware