Beginner path

Start here if Windows internals is new to you

This path builds the mental model first, then moves from running processes to memory, diagnostics, and security. Each step is short enough to browse in one sitting, but concrete enough to be useful later in the EVTX lab.

Branch paths (security, networking, GUI)

Shorter guided sequences inside a single theme. Use Follow path, then Continue on each topic page.

Security deep dive

From identity (tokens) to object policy (DACL/SACL), through kernel access checks (SRM), ending with UAC and integrity boundaries.

Follow path

Networking stack tour

Follow a connection from Winsock and DNS through TCP/IP, filtering (WFP/BFE), down to NDIS and the NIC.

Follow path

GUI & session UI

Understand sessions, window stations, desktops, USER/GDI objects, and the CSRSS/Win32k plumbing behind the shell.

Follow path

Memory deep dive

VADs, pools, paging, working sets, and how the cache uses RAM.

Follow path

I/O & drivers

From I/O Manager and IRPs through driver stacks and PnP power.

Follow path

Virtualization & VBS

Hyper-V partitions, enlightened I/O, and virtualization-based security.

Follow path

Authentication path

From Winlogon through LSASS to Kerberos/NTLM and crypto plumbing.

Follow path

Loader & runtime

PE images, DLL loading, and WOW64 on 64-bit Windows.

Follow path

Storage path

Volumes, NTFS, cache, and reparse points.

Follow path

Then go deeper

After the beginner path, continue with one of these longer cross-theme sequences.