← Back to list

Review for Mastering Windows Internal — gtworek

Want to master the inner workings of the Windows operating system?  Dive deep into Windows Internals with this insightful and hands-on…

Diyar Saadi | Malfav · 2025-08-05 12:16 · 0 claps · 2.0 min read
#windows #internal #malwar #training
Open on Medium ↗
Wiki topics: GEN · Genomics & Sequencing

Review for Mastering Windows Internal — gtworek

Want to master the inner workings of the Windows operating system? Dive deep into Windows Internals with this insightful and hands-on course by Grzegorz Tworek, ex-Microsoft MVP and one of the most respected experts in Windows security and internals.

This course isn’t just theory it’s packed with practical, real-world knowledge, examples, and tool demonstrations. Whether you’re a red teamer, blue teamer, or just a curious learner, you’ll walk away with an advanced understanding of how Windows really works under the hood.

🧠 What You’ll Learn:

1. Talking to the Windows Kernel

We begin with a powerful concept BYOVD (Bring Your Own Vulnerable Driver). Instead of forcing your way into the kernel, leverage existing code that already has the necessary permissions. Learn how to:

  • Halt protected processes
  • Read inaccessible memory
  • Crash the system with a single bug You’ll explore syscalls, IOCTLs, and FCTLs, with plenty of hands-on C programming but don’t worry, much of the code is provided and explained in detail.

2. EXEs, DLLs, and Other Binaries

Running an .exe is easy but what actually happens behind the scenes?

  • Learn how Windows locates, loads, and interacts with binaries
  • Understand PE files, search order hijacking, and the PEB (Process Environment Block)
  • Get familiar with LOLBins legitimate binaries abused for malicious purposes

3. Authentication and Authorization

Security starts with two critical questions: Who are you? and What are you allowed to do? This module explores:

  • Windows local authentication mechanisms
  • Access tokens, privileges, and impersonation
  • How Windows makes decisions about user rights and permissions

(We’re focusing on local security no Active Directory here, so we can go deeper into core mechanics.)

4. Persistence Techniques

Attackers want to stay in. Defenders want to keep them out. Either way, you need to understand persistence.

  • Learn how attackers manipulate Windows to run custom code on reboot or login
  • Get a categorized, systematic breakdown of persistence techniques
  • Build your knowledge whether you’re red-teaming or defending

5. Windows Registry

This isn’t about changing your desktop wallpaper. This is deep registry forensics and internals, including:

  • How registry data is stored and used by Windows
  • Why some keys don’t “really” exist
  • What happens when a registry path goes beyond 512 levels deep
  • Weird and nerdy registry behaviors that only advanced users understand

6. The Toolkit

What good is theory without tools? Grzegorz will walk you through:

  • Lesser-known open-source gems
  • Proper use of Sysinternals tools (not just running them understanding them)
  • Affordable commercial software that can level up your workflow You’ll not only learn what tools to use, but how and why to use them.

By the end of this course, you’ll have both the deep technical understanding and the hands-on experience to continue exploring Windows Internals confidently on your own.


메타데이터
post_id
e40ca5fef4e0
slug
review-for-mastering-windows-internal-gtworek-e40ca5fef4e0
url
https://medium.com/@malfavwin32/review-for-mastering-windows-internal-gtworek-e40ca5fef4e0
canonical_url
https://medium.com/@malfavwin32/review-for-mastering-windows-internal-gtworek-e40ca5fef4e0
author_url
https://medium.com/@malfavwin32
status
ok
fetched_at
2026-07-18 13:02:20