Ntwarden Windows Analysis Toolkit

by reason-machines2384a003145aNo license83 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 3 months ago

NtWarden is a Windows Analysis and Research Toolkit providing GUI-based inspection of processes, kernel internals, services, network, ETW, and more via ImGui + DirectX 11 with optional kernel driver support.

Instructions onlySecurity
AI-generated overview

Guides building and using NtWarden, a Windows inspection toolkit for processes, kernel internals, services and network.

What it does
This skill documents NtWarden, a Windows analysis and research toolkit with an ImGui and DirectX 11 GUI, a WinSys static library, a KWinSys kernel driver, and a WinSysServer remote TCP server. It explains build requirements, driver installation, remote inspection setup, and C++ usage patterns for enumerating processes, services, network connections, kernel modules, callbacks and SSDT entries. It also covers per-process security analysis such as unbacked memory, hollowing, direct syscalls and inline hooks, plus troubleshooting steps.
When to use it
Use it when inspecting Windows processes, services, network state, ETW sessions, registry or kernel internals with NtWarden. It also fits setting up the KWinSys kernel driver, connecting to a remote WinSysServer target, or detecting hooks and hidden processes.
Requirements
Visual Studio 2022, Windows SDK 10.0.26100.0 or later, and the Windows Driver Kit for the kernel driver. Administrator rights are needed for full functionality, test signing for the driver, and Capstone for user hook disassembly. Remote inspection uses TCP port 50002 by default with no authentication. The skill is instructions only and ships no scripts.

NtWarden Windows Analysis and Research Toolkit

Skill by ara.so — Daily 2026 Skills collection.

NtWarden is a Windows system inspection tool built on ImGui + DirectX 11. It covers processes, services, network, kernel internals, ETW, registry, object manager, and more — locally or remotely via WinSysServer. A kernel driver (KWinSys) enables deep kernel-mode analysis including SSDT hooks, kernel callbacks, EPT hook detection, and driver integrity checks.


Architecture

ComponentRole
NtWardenGUI app (ImGui + DirectX 11)
WinSysStatic lib — process, service, network enumeration
KWinSysKernel driver — callbacks, SSDT, kernel modules, pool, etc.
WinSysServerHeadless TCP server for remote inspection

Build Requirements

  • Visual Studio 2022
  • Windows SDK 10.0.26100.0+
  • WDK (Windows Driver Kit) — required only for KWinSys kernel driver

Building

powershell
# Open solution in Visual Studio 2022# Select Release | x64# Build All
# Output lands in:x64/Release/NtWarden.exex64/Release/WinSysServer.exex64/Release/KWinSys/KWinSys.sys

Solution structure:

NtWarden.sln├── NtWarden/          # GUI application├── WinSys/            # Core static library├── KWinSys/           # Kernel driver (.sys)└── WinSysServer/      # Remote TCP server

Running NtWarden

Always run as Administrator for full functionality.

powershell
# Run elevatedStart-Process NtWarden.exe -Verb RunAs

User-mode features (processes, services, network, ETW, registry, object manager) work without the driver.


Kernel Driver Setup (KWinSys)

⚠️ Use only in a test VM. Enable test signing before installing.

powershell
# Enable test signing (requires reboot)bcdedit /set testsigning on
# On VMs, may also need:bcdedit /set nointegritychecks on
# Reboot, then run NtWarden as Administrator.# Switching to the Kernel Mode tab auto-installs and starts KWinSys.

Manual driver management:

powershell
# Install manuallysc create KWinSys type= kernel binPath= "C:\path\to\KWinSys.sys"sc start KWinSys
# Stop and removesc stop KWinSyssc delete KWinSys

The NtWarden GUI also exposes driver management under the Driver menu.


Remote Inspection (WinSysServer)

Deploy to a target machine (typically a VM) and connect from NtWarden.

Files to copy to target

FileSource PathPurpose
WinSysServer.exex64/Release/WinSysServer.exeAlways required
KWinSys.sysx64/Release/KWinSys/KWinSys.sysKernel features only

Starting the server (on target, elevated)

powershell
# Auto-install driver + start server on default port 50002WinSysServer.exe --install
# Custom portWinSysServer.exe --install --port 9000
# If driver already installed manually:WinSysServer.exeWinSysServer.exe --port 9000

Connecting from NtWarden (on host)

  1. Launch NtWarden
  2. Go to Remote menu
  3. Enter target IP and port (default: 50002)
  4. Click Connect

Protocol notes

  • Custom binary protocol over TCP
  • 12-byte header: MessageType, DataSize, Status
  • No authentication — use only in isolated lab/VM environments
  • User-mode data (processes, services, network) works without KWinSys on target
  • Kernel tabs require KWinSys loaded on the remote target

WinSys Static Library — Key Usage Patterns

WinSys is the core library consumed by both NtWarden and WinSysServer. Example integration patterns in C++:

Process Enumeration

cpp
#include "WinSys/ProcessManager.h"
// Enumerate all processes (user mode)auto& pm = WinSys::ProcessManager::Get();pm.Update();  // Refresh snapshot
for (auto& proc : pm.GetProcesses()) {    printf("PID: %5u  Name: %s\n",        proc->Id,        proc->GetImageName().c_str());}

Service Enumeration

cpp
#include "WinSys/ServiceManager.h"
WinSys::ServiceManager svcMgr;auto services = svcMgr.EnumServices();
for (auto& svc : services) {    printf("Service: %-40s  State: %u  StartType: %u\n",        svc.GetName().c_str(),        svc.Status.dwCurrentState,        svc.Config.dwStartType);}

Network Connections

cpp
#include "WinSys/NetworkManager.h"
WinSys::NetworkManager netMgr;auto conns = netMgr.GetTcpConnections();
for (auto& conn : conns) {    printf("PID: %u  Local: %s:%u  Remote: %s:%u  State: %u\n",        conn.ProcessId,        conn.LocalAddress.c_str(), conn.LocalPort,        conn.RemoteAddress.c_str(), conn.RemotePort,        conn.State);}

Communicating with KWinSys Driver (IOCTL)

cpp
#include "WinSys/KernelInterface.h"
// Open handle to driver deviceWinSys::KernelInterface ki;if (!ki.Open()) {    fprintf(stderr, "Failed to open KWinSys device. Is driver loaded?\n");    return;}
// Enumerate kernel modulesauto modules = ki.EnumKernelModules();for (auto& mod : modules) {    printf("Base: %p  Size: 0x%X  Path: %s\n",        mod.Base, mod.Size, mod.FullPath.c_str());}
// Read kernel callbacksauto callbacks = ki.EnumProcessCallbacks();for (auto& cb : callbacks) {    printf("Callback: %p  Module: %s  Suspicious: %d\n",        cb.Address,        cb.OwnerModule.c_str(),        cb.IsSuspicious ? 1 : 0);}

Per-Process Security Analysis (Analyze Process)

Accessible via right-click > Analyze Process in the GUI, or programmatically:

cpp
#include "WinSys/ProcessAnalyzer.h"
DWORD targetPid = 1234;WinSys::ProcessAnalyzer analyzer(targetPid);
auto result = analyzer.Analyze();
// Unbacked executable memory (shellcode indicator)for (auto& region : result.UnbackedRegions) {    printf("Unbacked RX region: base=%p size=0x%zX\n",        region.Base, region.Size);}
// Hollowing detectionif (result.HollowingDetected) {    printf("Hollowing: PEB ImageBase=%p vs PE Header ImageBase=%p\n",        result.PebImageBase, result.PeHeaderImageBase);}
// Direct syscalls outside ntdllfor (auto& sc : result.DirectSyscalls) {    printf("Direct syscall at: %p in module: %s\n",        sc.Address, sc.ModuleName.c_str());}
// Inline user hooksfor (auto& hook : result.UserHooks) {    printf("Hook in %s!%s at %p -> %p\n",        hook.Module.c_str(),        hook.Function.c_str(),        hook.Address,        hook.Target);}
// Token infoprintf("Elevated: %d  IntegrityLevel: %u\n",    result.Token.IsElevated,    result.Token.IntegrityLevel);

Key Features by Tab

User Mode (no driver)

TabCapability
ProcessesTree view, handles, threads, memory regions, modules
PerformanceCPU/RAM/GPU/network graphs, overlay mode
ServicesStatus, start type, binary path
Network > ConnectionsTCP/UDP with owning PID
Network > Root CertificatesSubject, issuer, thumbprint
Network > NDISAdapter driver, MAC, speed, media type
ETWActive trace sessions and registered providers
IPCRPC endpoints and named pipes
Object ManagerKernel object namespace browser
RegistryKey/value browser
LoggerKernel driver debug logs + GUI logs

Kernel Mode (requires KWinSys)

TabCapability
Process ObjectsEPROCESS enumeration, hidden process detection
ModulesKernel drivers + LolDrivers check
CallbacksProcess/thread/image/registry/object/power callbacks + integrity
SSDTEntries with owner and hook detection
Kernel PoolBig pool allocations and tag stats
Memory R/WRead/write kernel memory by address
TimersPer-CPU interrupt and DPC counters
FilterMinifilter drivers with altitude/instance
Descriptor TablesGDT/IDT entries
IRP DispatchIRP dispatch table for any driver
WFPWFP callout drivers and filters
DSE StatusDriver Signature Enforcement state
CI PolicyCode Integrity policy and enforcement level
Kernel IntegrityVerify kernel .text vs on-disk image
Hypervisor HooksEPT hook detection via timing analysis

Common Patterns

Check if driver is loaded before using kernel features

cpp
#include "WinSys/KernelInterface.h"
WinSys::KernelInterface ki;bool driverAvailable = ki.Open();
if (driverAvailable) {    // Use kernel-mode features    auto ssdt = ki.GetSSDTEntries();} else {    // Fall back to user-mode only    fprintf(stderr, "KWinSys not loaded — kernel features unavailable.\n");}

Detect hidden processes (cross-reference EPROCESS list vs user-mode list)

cpp
WinSys::KernelInterface ki;ki.Open();
auto kernelProcs = ki.EnumProcessObjects();  // Via EPROCESS walkauto& pm = WinSys::ProcessManager::Get();pm.Update();auto userProcs = pm.GetProcesses();
// Build set of user-visible PIDsstd::unordered_set<DWORD> visiblePids;for (auto& p : userProcs) visiblePids.insert(p->Id);
// Find PIDs in kernel list but not user listfor (auto& kp : kernelProcs) {    if (visiblePids.find(kp.ProcessId) == visiblePids.end()) {        printf("HIDDEN PROCESS: PID=%u Name=%s\n",            kp.ProcessId, kp.ImageName.c_str());    }}

Troubleshooting

NtWarden won't show kernel tabs

  • Ensure KWinSys.sys is in the same directory as NtWarden.exe (or x64/Release/KWinSys/)
  • Run NtWarden as Administrator
  • Confirm test signing is enabled: bcdedit /enum | findstr testsigning
  • Check Logger tab for driver load errors

Driver fails to install

powershell
# Verify test signing is onbcdedit /enum | Select-String "testsigning"
# Check for existing broken service entrysc query KWinSyssc delete KWinSys  # if stuck, delete and retry
# Some VMs also need:bcdedit /set nointegritychecks on# Then reboot

WinSysServer connection refused

powershell
# Verify server is running on targetnetstat -ano | findstr 50002
# Check Windows Firewall on targetnetsh advfirewall firewall add rule name="WinSysServer" `  dir=in action=allow protocol=TCP localport=50002

Capstone not found (user hooks tab shows no data)

  • User hook detection with disassembly requires Capstone
  • Build WinSys with Capstone linked, or the hook scanner will report bytes without disassembly

Performance overlay not visible

  • Launch NtWarden, go to Performance tab
  • Enable overlay mode — it renders over other windows using DirectX 11 transparency

Build errors — missing WDK

  • KWinSys requires the Windows Driver Kit
  • If you only need user-mode features, exclude KWinSys project from build in Visual Studio (right-click project > Unload Project)

Tested Windows Versions

  • Windows 11 23H2 (Build 22631.6199)
  • Windows 10 22H2 (Build 19045.2006)
  • Windows 10 1703 (Build 15063.13)

References

  • zodiacon — Primary inspiration
  • WinArk — Kernel-mode feature reference
  • LolDrivers — Vulnerable driver database used in Modules tab

Source and attribution

Source:reason-machines/trending-skillsinskills/ntwarden-windows-analysis-toolkitat commit2384a00

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal