Ntwarden Windows Analysis Toolkit

作者 reason-machines2384a003145a无许可证83 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3个月前更新

NtWarden is a Windows Analysis and Research Toolkit providing GUI-based inspection of processes, kernel internals, services, network, ETW, and more via ImGui + DirectX 11 with optional kernel driver support.

仅含说明Security
AI 生成的概览

指导构建和使用 NtWarden,这是一款用于进程、内核内部、服务和网络检查的 Windows 分析工具包。

功能
该技能介绍 NtWarden,一个 Windows 分析与研究工具包,包含 ImGui 与 DirectX 11 图形界面、WinSys 静态库、KWinSys 内核驱动以及 WinSysServer 远程 TCP 服务器。内容涵盖构建要求、驱动安装、远程检查配置,以及枚举进程、服务、网络连接、内核模块、回调和 SSDT 表项的 C++ 用法示例。还涉及单进程安全分析,如无后备内存、镂空、直接系统调用和内联钩子,并提供故障排查步骤。
适用场景
适用于使用 NtWarden 检查 Windows 进程、服务、网络状态、ETW 会话、注册表或内核内部信息。也适合配置 KWinSys 内核驱动、连接远程 WinSysServer 目标,或检测钩子与隐藏进程。
运行要求
需要 Visual Studio 2022、Windows SDK 10.0.26100.0 或更高版本,内核驱动还需 Windows 驱动工具包(WDK)。完整功能需要管理员权限,驱动需要测试签名,用户钩子反汇编需要 Capstone。远程检查默认使用 TCP 端口 50002,且无身份验证。该技能仅为说明文档,不附带脚本。

NtWarden Windows Analysis and Research Toolkit

Skill by ara.so — Daily 2026 Skills collection.

NtWarden is a Windows system inspection tool built on ImGui + DirectX 11. It covers processes, services, network, kernel internals, ETW, registry, object manager, and more — locally or remotely via WinSysServer. A kernel driver (KWinSys) enables deep kernel-mode analysis including SSDT hooks, kernel callbacks, EPT hook detection, and driver integrity checks.


Architecture

ComponentRole
NtWardenGUI app (ImGui + DirectX 11)
WinSysStatic lib — process, service, network enumeration
KWinSysKernel driver — callbacks, SSDT, kernel modules, pool, etc.
WinSysServerHeadless TCP server for remote inspection

Build Requirements

  • Visual Studio 2022
  • Windows SDK 10.0.26100.0+
  • WDK (Windows Driver Kit) — required only for KWinSys kernel driver

Building

powershell
# Open solution in Visual Studio 2022# Select Release | x64# Build All
# Output lands in:x64/Release/NtWarden.exex64/Release/WinSysServer.exex64/Release/KWinSys/KWinSys.sys

Solution structure:

NtWarden.sln├── NtWarden/          # GUI application├── WinSys/            # Core static library├── KWinSys/           # Kernel driver (.sys)└── WinSysServer/      # Remote TCP server

Running NtWarden

Always run as Administrator for full functionality.

powershell
# Run elevatedStart-Process NtWarden.exe -Verb RunAs

User-mode features (processes, services, network, ETW, registry, object manager) work without the driver.


Kernel Driver Setup (KWinSys)

⚠️ Use only in a test VM. Enable test signing before installing.

powershell
# Enable test signing (requires reboot)bcdedit /set testsigning on
# On VMs, may also need:bcdedit /set nointegritychecks on
# Reboot, then run NtWarden as Administrator.# Switching to the Kernel Mode tab auto-installs and starts KWinSys.

Manual driver management:

powershell
# Install manuallysc create KWinSys type= kernel binPath= "C:\path\to\KWinSys.sys"sc start KWinSys
# Stop and removesc stop KWinSyssc delete KWinSys

The NtWarden GUI also exposes driver management under the Driver menu.


Remote Inspection (WinSysServer)

Deploy to a target machine (typically a VM) and connect from NtWarden.

Files to copy to target

FileSource PathPurpose
WinSysServer.exex64/Release/WinSysServer.exeAlways required
KWinSys.sysx64/Release/KWinSys/KWinSys.sysKernel features only

Starting the server (on target, elevated)

powershell
# Auto-install driver + start server on default port 50002WinSysServer.exe --install
# Custom portWinSysServer.exe --install --port 9000
# If driver already installed manually:WinSysServer.exeWinSysServer.exe --port 9000

Connecting from NtWarden (on host)

  1. Launch NtWarden
  2. Go to Remote menu
  3. Enter target IP and port (default: 50002)
  4. Click Connect

Protocol notes

  • Custom binary protocol over TCP
  • 12-byte header: MessageType, DataSize, Status
  • No authentication — use only in isolated lab/VM environments
  • User-mode data (processes, services, network) works without KWinSys on target
  • Kernel tabs require KWinSys loaded on the remote target

WinSys Static Library — Key Usage Patterns

WinSys is the core library consumed by both NtWarden and WinSysServer. Example integration patterns in C++:

Process Enumeration

cpp
#include "WinSys/ProcessManager.h"
// Enumerate all processes (user mode)auto& pm = WinSys::ProcessManager::Get();pm.Update();  // Refresh snapshot
for (auto& proc : pm.GetProcesses()) {    printf("PID: %5u  Name: %s\n",        proc->Id,        proc->GetImageName().c_str());}

Service Enumeration

cpp
#include "WinSys/ServiceManager.h"
WinSys::ServiceManager svcMgr;auto services = svcMgr.EnumServices();
for (auto& svc : services) {    printf("Service: %-40s  State: %u  StartType: %u\n",        svc.GetName().c_str(),        svc.Status.dwCurrentState,        svc.Config.dwStartType);}

Network Connections

cpp
#include "WinSys/NetworkManager.h"
WinSys::NetworkManager netMgr;auto conns = netMgr.GetTcpConnections();
for (auto& conn : conns) {    printf("PID: %u  Local: %s:%u  Remote: %s:%u  State: %u\n",        conn.ProcessId,        conn.LocalAddress.c_str(), conn.LocalPort,        conn.RemoteAddress.c_str(), conn.RemotePort,        conn.State);}

Communicating with KWinSys Driver (IOCTL)

cpp
#include "WinSys/KernelInterface.h"
// Open handle to driver deviceWinSys::KernelInterface ki;if (!ki.Open()) {    fprintf(stderr, "Failed to open KWinSys device. Is driver loaded?\n");    return;}
// Enumerate kernel modulesauto modules = ki.EnumKernelModules();for (auto& mod : modules) {    printf("Base: %p  Size: 0x%X  Path: %s\n",        mod.Base, mod.Size, mod.FullPath.c_str());}
// Read kernel callbacksauto callbacks = ki.EnumProcessCallbacks();for (auto& cb : callbacks) {    printf("Callback: %p  Module: %s  Suspicious: %d\n",        cb.Address,        cb.OwnerModule.c_str(),        cb.IsSuspicious ? 1 : 0);}

Per-Process Security Analysis (Analyze Process)

Accessible via right-click > Analyze Process in the GUI, or programmatically:

cpp
#include "WinSys/ProcessAnalyzer.h"
DWORD targetPid = 1234;WinSys::ProcessAnalyzer analyzer(targetPid);
auto result = analyzer.Analyze();
// Unbacked executable memory (shellcode indicator)for (auto& region : result.UnbackedRegions) {    printf("Unbacked RX region: base=%p size=0x%zX\n",        region.Base, region.Size);}
// Hollowing detectionif (result.HollowingDetected) {    printf("Hollowing: PEB ImageBase=%p vs PE Header ImageBase=%p\n",        result.PebImageBase, result.PeHeaderImageBase);}
// Direct syscalls outside ntdllfor (auto& sc : result.DirectSyscalls) {    printf("Direct syscall at: %p in module: %s\n",        sc.Address, sc.ModuleName.c_str());}
// Inline user hooksfor (auto& hook : result.UserHooks) {    printf("Hook in %s!%s at %p -> %p\n",        hook.Module.c_str(),        hook.Function.c_str(),        hook.Address,        hook.Target);}
// Token infoprintf("Elevated: %d  IntegrityLevel: %u\n",    result.Token.IsElevated,    result.Token.IntegrityLevel);

Key Features by Tab

User Mode (no driver)

TabCapability
ProcessesTree view, handles, threads, memory regions, modules
PerformanceCPU/RAM/GPU/network graphs, overlay mode
ServicesStatus, start type, binary path
Network > ConnectionsTCP/UDP with owning PID
Network > Root CertificatesSubject, issuer, thumbprint
Network > NDISAdapter driver, MAC, speed, media type
ETWActive trace sessions and registered providers
IPCRPC endpoints and named pipes
Object ManagerKernel object namespace browser
RegistryKey/value browser
LoggerKernel driver debug logs + GUI logs

Kernel Mode (requires KWinSys)

TabCapability
Process ObjectsEPROCESS enumeration, hidden process detection
ModulesKernel drivers + LolDrivers check
CallbacksProcess/thread/image/registry/object/power callbacks + integrity
SSDTEntries with owner and hook detection
Kernel PoolBig pool allocations and tag stats
Memory R/WRead/write kernel memory by address
TimersPer-CPU interrupt and DPC counters
FilterMinifilter drivers with altitude/instance
Descriptor TablesGDT/IDT entries
IRP DispatchIRP dispatch table for any driver
WFPWFP callout drivers and filters
DSE StatusDriver Signature Enforcement state
CI PolicyCode Integrity policy and enforcement level
Kernel IntegrityVerify kernel .text vs on-disk image
Hypervisor HooksEPT hook detection via timing analysis

Common Patterns

Check if driver is loaded before using kernel features

cpp
#include "WinSys/KernelInterface.h"
WinSys::KernelInterface ki;bool driverAvailable = ki.Open();
if (driverAvailable) {    // Use kernel-mode features    auto ssdt = ki.GetSSDTEntries();} else {    // Fall back to user-mode only    fprintf(stderr, "KWinSys not loaded — kernel features unavailable.\n");}

Detect hidden processes (cross-reference EPROCESS list vs user-mode list)

cpp
WinSys::KernelInterface ki;ki.Open();
auto kernelProcs = ki.EnumProcessObjects();  // Via EPROCESS walkauto& pm = WinSys::ProcessManager::Get();pm.Update();auto userProcs = pm.GetProcesses();
// Build set of user-visible PIDsstd::unordered_set<DWORD> visiblePids;for (auto& p : userProcs) visiblePids.insert(p->Id);
// Find PIDs in kernel list but not user listfor (auto& kp : kernelProcs) {    if (visiblePids.find(kp.ProcessId) == visiblePids.end()) {        printf("HIDDEN PROCESS: PID=%u Name=%s\n",            kp.ProcessId, kp.ImageName.c_str());    }}

Troubleshooting

NtWarden won't show kernel tabs

  • Ensure KWinSys.sys is in the same directory as NtWarden.exe (or x64/Release/KWinSys/)
  • Run NtWarden as Administrator
  • Confirm test signing is enabled: bcdedit /enum | findstr testsigning
  • Check Logger tab for driver load errors

Driver fails to install

powershell
# Verify test signing is onbcdedit /enum | Select-String "testsigning"
# Check for existing broken service entrysc query KWinSyssc delete KWinSys  # if stuck, delete and retry
# Some VMs also need:bcdedit /set nointegritychecks on# Then reboot

WinSysServer connection refused

powershell
# Verify server is running on targetnetstat -ano | findstr 50002
# Check Windows Firewall on targetnetsh advfirewall firewall add rule name="WinSysServer" `  dir=in action=allow protocol=TCP localport=50002

Capstone not found (user hooks tab shows no data)

  • User hook detection with disassembly requires Capstone
  • Build WinSys with Capstone linked, or the hook scanner will report bytes without disassembly

Performance overlay not visible

  • Launch NtWarden, go to Performance tab
  • Enable overlay mode — it renders over other windows using DirectX 11 transparency

Build errors — missing WDK

  • KWinSys requires the Windows Driver Kit
  • If you only need user-mode features, exclude KWinSys project from build in Visual Studio (right-click project > Unload Project)

Tested Windows Versions

  • Windows 11 23H2 (Build 22631.6199)
  • Windows 10 22H2 (Build 19045.2006)
  • Windows 10 1703 (Build 15063.13)

References

  • zodiacon — Primary inspiration
  • WinArk — Kernel-mode feature reference
  • LolDrivers — Vulnerable driver database used in Modules tab

来源与署名

来源:reason-machines/trending-skills位于skills/ntwarden-windows-analysis-toolkit提交2384a00

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架