NtWarden Windows Analysis and Research Toolkit
Skill by ara.so — Daily 2026 Skills collection.
NtWarden is a Windows system inspection tool built on ImGui + DirectX 11. It covers processes, services, network, kernel internals, ETW, registry, object manager, and more — locally or remotely via WinSysServer. A kernel driver (KWinSys) enables deep kernel-mode analysis including SSDT hooks, kernel callbacks, EPT hook detection, and driver integrity checks.
Architecture
Build Requirements
- Visual Studio 2022
- Windows SDK 10.0.26100.0+
- WDK (Windows Driver Kit) — required only for KWinSys kernel driver
Building
Solution structure:
Running NtWarden
Always run as Administrator for full functionality.
User-mode features (processes, services, network, ETW, registry, object manager) work without the driver.
Kernel Driver Setup (KWinSys)
⚠️ Use only in a test VM. Enable test signing before installing.
Manual driver management:
The NtWarden GUI also exposes driver management under the Driver menu.
Remote Inspection (WinSysServer)
Deploy to a target machine (typically a VM) and connect from NtWarden.
Files to copy to target
Starting the server (on target, elevated)
Connecting from NtWarden (on host)
- Launch NtWarden
- Go to Remote menu
- Enter target IP and port (default:
50002) - Click Connect
Protocol notes
- Custom binary protocol over TCP
- 12-byte header:
MessageType,DataSize,Status - No authentication — use only in isolated lab/VM environments
- User-mode data (processes, services, network) works without KWinSys on target
- Kernel tabs require KWinSys loaded on the remote target
WinSys Static Library — Key Usage Patterns
WinSys is the core library consumed by both NtWarden and WinSysServer. Example integration patterns in C++:
Process Enumeration
Service Enumeration
Network Connections
Communicating with KWinSys Driver (IOCTL)
Per-Process Security Analysis (Analyze Process)
Accessible via right-click > Analyze Process in the GUI, or programmatically:
Key Features by Tab
User Mode (no driver)
Kernel Mode (requires KWinSys)
Common Patterns
Check if driver is loaded before using kernel features
Detect hidden processes (cross-reference EPROCESS list vs user-mode list)
Troubleshooting
NtWarden won't show kernel tabs
- Ensure KWinSys.sys is in the same directory as NtWarden.exe (or
x64/Release/KWinSys/) - Run NtWarden as Administrator
- Confirm test signing is enabled:
bcdedit /enum | findstr testsigning - Check Logger tab for driver load errors
Driver fails to install
WinSysServer connection refused
Capstone not found (user hooks tab shows no data)
- User hook detection with disassembly requires Capstone
- Build WinSys with Capstone linked, or the hook scanner will report bytes without disassembly
Performance overlay not visible
- Launch NtWarden, go to Performance tab
- Enable overlay mode — it renders over other windows using DirectX 11 transparency
Build errors — missing WDK
- KWinSys requires the Windows Driver Kit
- If you only need user-mode features, exclude KWinSys project from build in Visual Studio (right-click project > Unload Project)
Tested Windows Versions
- Windows 11 23H2 (Build 22631.6199)
- Windows 10 22H2 (Build 19045.2006)
- Windows 10 1703 (Build 15063.13)
References
- zodiacon — Primary inspiration
- WinArk — Kernel-mode feature reference
- LolDrivers — Vulnerable driver database used in Modules tab


