| route-pattern | /:user_id/:repository |
| route-controller | files |
| route-action | disambiguate |
| fetch-nonce | v2:1238885f-797c-7290-a0c5-4a6063ee3e06 |
| current-catalog-service-hash | f3abb0cc802f3d7b95fc8762b94bdcb13bf39634c40c357301c4aa1d67a256fb |
| request-id | C1B8:2CFBA0:1AE6C95:227DCE3:6991B534 |
| html-safe-nonce | da469478451e730d154cf9bd68632dd7e4d7304b4882cbf45f8607975ce7e752 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDMUI4OjJDRkJBMDoxQUU2Qzk1OjIyN0RDRTM6Njk5MUI1MzQiLCJ2aXNpdG9yX2lkIjoiMjA2OTQ5ODIxOTE4MDcwMDk4MCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 93c646951dab9c853f5ed3b26f1f8c6845d600c306edb7dbfbf7c8c7b26cc6c9 |
| hovercard-subject-tag | repository:1064900686 |
| github-keyboard-shortcuts | repository,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | // |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/adanto/winlow |
| twitter:image | https://opengraph.githubassets.com/e95f888fc5b12540d7765ed317de086d633d26ff52c92ee729388e79a5b48ab2/adanto/winlow |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/e95f888fc5b12540d7765ed317de086d633d26ff52c92ee729388e79a5b48ab2/adanto/winlow |
| og:image:alt | Concise, hands-on Windows internals, exploitation notes and detection playbooks. - adanto/winlow |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 42c603b9d642c4a9065a51770f75e5e27132fef0e858607f5c9cb7e422831a7b |
| turbo-cache-control | no-preview |
| go-import | github.com/adanto/winlow git https://github.com/adanto/winlow.git |
| octolytics-dimension-user_id | 9393785 |
| octolytics-dimension-user_login | adanto |
| octolytics-dimension-repository_id | 1064900686 |
| octolytics-dimension-repository_nwo | adanto/winlow |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1064900686 |
| octolytics-dimension-repository_network_root_nwo | adanto/winlow |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 848bc6032dcc93a9a7301dcc3f379a72ba13b96e |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
| Skip to content | https://patch-diff.githubusercontent.com/adanto/winlow#start-of-content |
|
| https://patch-diff.githubusercontent.com/ |
|
Sign in
| https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fadanto%2Fwinlow |
| GitHub CopilotWrite better code with AI | https://github.com/features/copilot |
| GitHub SparkBuild and deploy intelligent apps | https://github.com/features/spark |
| GitHub ModelsManage and compare prompts | https://github.com/features/models |
| MCP RegistryNewIntegrate external tools | https://github.com/mcp |
| ActionsAutomate any workflow | https://github.com/features/actions |
| CodespacesInstant dev environments | https://github.com/features/codespaces |
| IssuesPlan and track work | https://github.com/features/issues |
| Code ReviewManage code changes | https://github.com/features/code-review |
| GitHub Advanced SecurityFind and fix vulnerabilities | https://github.com/security/advanced-security |
| Code securitySecure your code as you build | https://github.com/security/advanced-security/code-security |
| Secret protectionStop leaks before they start | https://github.com/security/advanced-security/secret-protection |
| Why GitHub | https://github.com/why-github |
| Documentation | https://docs.github.com |
| Blog | https://github.blog |
| Changelog | https://github.blog/changelog |
| Marketplace | https://github.com/marketplace |
| View all features | https://github.com/features |
| Enterprises | https://github.com/enterprise |
| Small and medium teams | https://github.com/team |
| Startups | https://github.com/enterprise/startups |
| Nonprofits | https://github.com/solutions/industry/nonprofits |
| App Modernization | https://github.com/solutions/use-case/app-modernization |
| DevSecOps | https://github.com/solutions/use-case/devsecops |
| DevOps | https://github.com/solutions/use-case/devops |
| CI/CD | https://github.com/solutions/use-case/ci-cd |
| View all use cases | https://github.com/solutions/use-case |
| Healthcare | https://github.com/solutions/industry/healthcare |
| Financial services | https://github.com/solutions/industry/financial-services |
| Manufacturing | https://github.com/solutions/industry/manufacturing |
| Government | https://github.com/solutions/industry/government |
| View all industries | https://github.com/solutions/industry |
| View all solutions | https://github.com/solutions |
| AI | https://github.com/resources/articles?topic=ai |
| Software Development | https://github.com/resources/articles?topic=software-development |
| DevOps | https://github.com/resources/articles?topic=devops |
| Security | https://github.com/resources/articles?topic=security |
| View all topics | https://github.com/resources/articles |
| Customer stories | https://github.com/customer-stories |
| Events & webinars | https://github.com/resources/events |
| Ebooks & reports | https://github.com/resources/whitepapers |
| Business insights | https://github.com/solutions/executive-insights |
| GitHub Skills | https://skills.github.com |
| Documentation | https://docs.github.com |
| Customer support | https://support.github.com |
| Community forum | https://github.com/orgs/community/discussions |
| Trust center | https://github.com/trust-center |
| Partners | https://github.com/partners |
| GitHub SponsorsFund open source developers | https://github.com/sponsors |
| Security Lab | https://securitylab.github.com |
| Maintainer Community | https://maintainers.github.com |
| Accelerator | https://github.com/accelerator |
| Archive Program | https://archiveprogram.github.com |
| Topics | https://github.com/topics |
| Trending | https://github.com/trending |
| Collections | https://github.com/collections |
| Enterprise platformAI-powered developer platform | https://github.com/enterprise |
| GitHub Advanced SecurityEnterprise-grade security features | https://github.com/security/advanced-security |
| Copilot for BusinessEnterprise-grade AI features | https://github.com/features/copilot/copilot-business |
| Premium SupportEnterprise-grade 24/7 support | https://github.com/premium-support |
| Pricing | https://github.com/pricing |
| Search syntax tips | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
| documentation | https://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax |
|
Sign in
| https://patch-diff.githubusercontent.com/login?return_to=https%3A%2F%2Fgithub.com%2Fadanto%2Fwinlow |
|
Sign up
| https://patch-diff.githubusercontent.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E&source=header-repo&source_repo=adanto%2Fwinlow |
| Reload | https://patch-diff.githubusercontent.com/adanto/winlow |
| Reload | https://patch-diff.githubusercontent.com/adanto/winlow |
| Reload | https://patch-diff.githubusercontent.com/adanto/winlow |
|
adanto
| https://patch-diff.githubusercontent.com/adanto |
| winlow | https://patch-diff.githubusercontent.com/adanto/winlow |
|
Notifications
| https://patch-diff.githubusercontent.com/login?return_to=%2Fadanto%2Fwinlow |
|
Fork
0
| https://patch-diff.githubusercontent.com/login?return_to=%2Fadanto%2Fwinlow |
|
Star
1
| https://patch-diff.githubusercontent.com/login?return_to=%2Fadanto%2Fwinlow |
|
MIT license
| https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/LICENSE.txt |
|
1
star
| https://patch-diff.githubusercontent.com/adanto/winlow/stargazers |
|
0
forks
| https://patch-diff.githubusercontent.com/adanto/winlow/forks |
|
Branches
| https://patch-diff.githubusercontent.com/adanto/winlow/branches |
|
Tags
| https://patch-diff.githubusercontent.com/adanto/winlow/tags |
|
Activity
| https://patch-diff.githubusercontent.com/adanto/winlow/activity |
|
Star
| https://patch-diff.githubusercontent.com/login?return_to=%2Fadanto%2Fwinlow |
|
Notifications
| https://patch-diff.githubusercontent.com/login?return_to=%2Fadanto%2Fwinlow |
|
Code
| https://patch-diff.githubusercontent.com/adanto/winlow |
|
Issues
0
| https://patch-diff.githubusercontent.com/adanto/winlow/issues |
|
Pull requests
0
| https://patch-diff.githubusercontent.com/adanto/winlow/pulls |
|
Actions
| https://patch-diff.githubusercontent.com/adanto/winlow/actions |
|
Projects
0
| https://patch-diff.githubusercontent.com/adanto/winlow/projects |
|
Security
0
| https://patch-diff.githubusercontent.com/adanto/winlow/security |
|
Insights
| https://patch-diff.githubusercontent.com/adanto/winlow/pulse |
|
Code
| https://patch-diff.githubusercontent.com/adanto/winlow |
|
Issues
| https://patch-diff.githubusercontent.com/adanto/winlow/issues |
|
Pull requests
| https://patch-diff.githubusercontent.com/adanto/winlow/pulls |
|
Actions
| https://patch-diff.githubusercontent.com/adanto/winlow/actions |
|
Projects
| https://patch-diff.githubusercontent.com/adanto/winlow/projects |
|
Security
| https://patch-diff.githubusercontent.com/adanto/winlow/security |
|
Insights
| https://patch-diff.githubusercontent.com/adanto/winlow/pulse |
| Branches | https://patch-diff.githubusercontent.com/adanto/winlow/branches |
| Tags | https://patch-diff.githubusercontent.com/adanto/winlow/tags |
| https://patch-diff.githubusercontent.com/adanto/winlow/branches |
| https://patch-diff.githubusercontent.com/adanto/winlow/tags |
| 3 Commits | https://patch-diff.githubusercontent.com/adanto/winlow/commits/main/ |
| https://patch-diff.githubusercontent.com/adanto/winlow/commits/main/ |
| part1 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part1 |
| part1 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part1 |
| part2 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part2 |
| part2 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part2 |
| part3 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part3 |
| part3 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part3 |
| part4 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part4 |
| part4 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part4 |
| part5 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part5 |
| part5 | https://patch-diff.githubusercontent.com/adanto/winlow/tree/main/part5 |
| LICENSE.txt | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/LICENSE.txt |
| LICENSE.txt | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/LICENSE.txt |
| README.md | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/README.md |
| README.md | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/README.md |
| README | https://patch-diff.githubusercontent.com/adanto/winlow |
| MIT license | https://patch-diff.githubusercontent.com/adanto/winlow |
| https://patch-diff.githubusercontent.com/adanto/winlow#windows-internals--exploitation |
| https://patch-diff.githubusercontent.com/adanto/winlow#how-to-use-this-repository |
| https://patch-diff.githubusercontent.com/adanto/winlow#responsible-use--safety |
| https://patch-diff.githubusercontent.com/adanto/winlow#objectives |
| https://patch-diff.githubusercontent.com/adanto/winlow#index |
| https://patch-diff.githubusercontent.com/adanto/winlow#part-1--fundamentals |
| Introduction | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/01-introduction.md |
| Processes & Threads | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/02-processes-threads.md |
| Windows Loader & Image Activation | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/03-loader-image-activation.md |
| Memory & Virtual Address Space | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/04-memory-vas.md |
| Object Manager & Handles | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/05-object-manager-handles.md |
| Syscalls & the NTAPI Boundary | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/06-syscalls-ntapi.md |
| Scheduling, APCs & Callback Surfaces | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/07-apcs-callbacks.md |
| IPC (ALPC, RPC, COM, Pipes) | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part1/08-ipc.md |
| https://patch-diff.githubusercontent.com/adanto/winlow#part-2--exploitation-mitigations |
| DEP / NX / W^X | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part2/01-dep-nx-wx.md |
| ASLR / KASLR | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part2/02-aslr-kaslr.md |
| Compiler & Hardware CFI: CFG, CET (Shadow Stack/IBT) | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part2/03-cfg-cet.md |
| Trust & Integrity: Secure Boot, WDAC, Code Integrity, PatchGuard, VBS/HVCI, PPL | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part2/04-trust-integrity-stack.md |
| Compiler & EH Hardening (/GS, SafeSEH/SEHOP, EHCONT) | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part2/05-compiler-eh-hardening.md |
| https://patch-diff.githubusercontent.com/adanto/winlow#part-3--anti-reversing--evasion |
| Anti-Debugging | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part3/01-anti-debugging.md |
| Anti-Disassembly | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part3/02-anti-disassembly.md |
| Sandbox & VM Evasion | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part3/03-sandbox-vm-evasion.md |
| Process Injection & Hooking | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part3/04-injection-hooking.md |
| AMSI & Script Host Internals | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part3/05-amsi-script-host.md |
| Telemetry Tampering & Unhooking (ETW, Direct Syscalls) | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part3/06-telemetry-tampering.md |
| Rootkits & Bootkits | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part3/07-rootkits-bootkits.md |
| https://patch-diff.githubusercontent.com/adanto/winlow#part-4--practical-exploitation |
| Buffer Overflows | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part4/01-buffer-overflows.md |
| Use-After-Free & Type Confusion | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part4/02-uaf-type-confusion.md |
| ROP & JOP | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part4/03-rop-jop.md |
| Shellcoding | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part4/04-shellcoding.md |
| Fuzzing & Exploit Development | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part4/05-fuzzing-exploit-dev.md |
| Kernel Exploitation Primer | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part4/06-kernel-exploitation-primer.md |
| https://patch-diff.githubusercontent.com/adanto/winlow#part-5--detection--countermeasures |
| Windows Eventing & ETW Playbook | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part5/01-etw-playbook.md |
| Telemetry & Hunting | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part5/02-telemetry-hunting.md |
| EDR & AV Evasion | https://patch-diff.githubusercontent.com/adanto/winlow/blob/main/part5/03-edr-av-evasion.md |
| https://patch-diff.githubusercontent.com/adanto/winlow#core-references |
| MITRE ATT&CK | https://attack.mitre.org/matrices/ |
| Microsoft Docs | https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createprocessa |
| Sysinternals (Microsoft) | https://learn.microsoft.com/en-us/sysinternals/downloads/process-explorer |
|
windows
| https://patch-diff.githubusercontent.com/topics/windows |
|
kernel
| https://patch-diff.githubusercontent.com/topics/kernel |
|
reverse-engineering
| https://patch-diff.githubusercontent.com/topics/reverse-engineering |
|
malware-analysis
| https://patch-diff.githubusercontent.com/topics/malware-analysis |
|
exploitation
| https://patch-diff.githubusercontent.com/topics/exploitation |
|
security-research
| https://patch-diff.githubusercontent.com/topics/security-research |
|
edr
| https://patch-diff.githubusercontent.com/topics/edr |
|
windows-internals
| https://patch-diff.githubusercontent.com/topics/windows-internals |
|
edr-evasion
| https://patch-diff.githubusercontent.com/topics/edr-evasion |
|
Readme
| https://patch-diff.githubusercontent.com/adanto/winlow#readme-ov-file |
|
MIT license
| https://patch-diff.githubusercontent.com/adanto/winlow#MIT-1-ov-file |
| Please reload this page | https://patch-diff.githubusercontent.com/adanto/winlow |
|
Activity | https://patch-diff.githubusercontent.com/adanto/winlow/activity |
|
1
star | https://patch-diff.githubusercontent.com/adanto/winlow/stargazers |
|
0
watching | https://patch-diff.githubusercontent.com/adanto/winlow/watchers |
|
0
forks | https://patch-diff.githubusercontent.com/adanto/winlow/forks |
|
Report repository
| https://patch-diff.githubusercontent.com/contact/report-content?content_url=https%3A%2F%2Fgithub.com%2Fadanto%2Fwinlow&report=adanto+%28user%29 |
| Releases | https://patch-diff.githubusercontent.com/adanto/winlow/releases |
| Packages
0 | https://patch-diff.githubusercontent.com/users/adanto/packages?repo_name=winlow |
|
| https://github.com |
| Terms | https://docs.github.com/site-policy/github-terms/github-terms-of-service |
| Privacy | https://docs.github.com/site-policy/privacy-policies/github-privacy-statement |
| Security | https://github.com/security |
| Status | https://www.githubstatus.com/ |
| Community | https://github.community/ |
| Docs | https://docs.github.com/ |
| Contact | https://support.github.com?tags=dotcom-footer |