Review for Mastering Windows Internal — gtworek
Want to master the inner workings of the Windows operating system? Dive deep into Windows Internals with this insightful and hands-on…
Review for Mastering Windows Internal — gtworek
Want to master the inner workings of the Windows operating system? Dive deep into Windows Internals with this insightful and hands-on course by Grzegorz Tworek, ex-Microsoft MVP and one of the most respected experts in Windows security and internals.
This course isn’t just theory it’s packed with practical, real-world knowledge, examples, and tool demonstrations. Whether you’re a red teamer, blue teamer, or just a curious learner, you’ll walk away with an advanced understanding of how Windows really works under the hood.
🧠 What You’ll Learn:
1. Talking to the Windows Kernel
We begin with a powerful concept BYOVD (Bring Your Own Vulnerable Driver). Instead of forcing your way into the kernel, leverage existing code that already has the necessary permissions. Learn how to:
- Halt protected processes
- Read inaccessible memory
- Crash the system with a single bug You’ll explore syscalls, IOCTLs, and FCTLs, with plenty of hands-on C programming but don’t worry, much of the code is provided and explained in detail.
2. EXEs, DLLs, and Other Binaries
Running an .exe is easy but what actually happens behind the scenes?
- Learn how Windows locates, loads, and interacts with binaries
- Understand PE files, search order hijacking, and the PEB (Process Environment Block)
- Get familiar with LOLBins legitimate binaries abused for malicious purposes
3. Authentication and Authorization
Security starts with two critical questions: Who are you? and What are you allowed to do? This module explores:
- Windows local authentication mechanisms
- Access tokens, privileges, and impersonation
- How Windows makes decisions about user rights and permissions
(We’re focusing on local security no Active Directory here, so we can go deeper into core mechanics.)
4. Persistence Techniques
Attackers want to stay in. Defenders want to keep them out. Either way, you need to understand persistence.
- Learn how attackers manipulate Windows to run custom code on reboot or login
- Get a categorized, systematic breakdown of persistence techniques
- Build your knowledge whether you’re red-teaming or defending
5. Windows Registry
This isn’t about changing your desktop wallpaper. This is deep registry forensics and internals, including:
- How registry data is stored and used by Windows
- Why some keys don’t “really” exist
- What happens when a registry path goes beyond 512 levels deep
- Weird and nerdy registry behaviors that only advanced users understand
6. The Toolkit
What good is theory without tools? Grzegorz will walk you through:
- Lesser-known open-source gems
- Proper use of Sysinternals tools (not just running them understanding them)
- Affordable commercial software that can level up your workflow You’ll not only learn what tools to use, but how and why to use them.
By the end of this course, you’ll have both the deep technical understanding and the hands-on experience to continue exploring Windows Internals confidently on your own.
메타데이터
- post_id
- e40ca5fef4e0
- slug
- review-for-mastering-windows-internal-gtworek-e40ca5fef4e0
- url
- https://medium.com/@malfavwin32/review-for-mastering-windows-internal-gtworek-e40ca5fef4e0
- canonical_url
- https://medium.com/@malfavwin32/review-for-mastering-windows-internal-gtworek-e40ca5fef4e0
- author_url
- https://medium.com/@malfavwin32
- status
- ok
- fetched_at
- 2026-07-18 13:02:20