Ntwarden Windows Analysis Toolkit

reason-machines/trending-skills/skills/ntwarden-windows-analysis-toolkit

作者 reason-machines2384a003145a無授權條款83 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 個月前更新

NtWarden is a Windows Analysis and Research Toolkit providing GUI-based inspection of processes, kernel internals, services, network, ETW, and more via ImGui + DirectX 11 with optional kernel driver support.

僅含說明Security
AI 產生的概覽

說明如何建置與使用 NtWarden,這是一套用來檢查處理程序、核心內部、服務與網路的 Windows 分析工具組。

功能
此技能介紹 NtWarden,一套 Windows 分析與研究工具組,包含 ImGui 與 DirectX 11 圖形介面、WinSys 靜態程式庫、KWinSys 核心驅動程式,以及 WinSysServer 遠端 TCP 伺服器。內容涵蓋建置需求、驅動程式安裝、遠端檢查設定,以及列舉處理程序、服務、網路連線、核心模組、回呼與 SSDT 項目的 C++ 用法範例。也包含單一處理程序的安全分析,例如無後援記憶體、鏤空、直接系統呼叫與內聯掛鉤,並提供疑難排解步驟。
適用情境
適合在需要使用 NtWarden 檢查 Windows 處理程序、服務、網路狀態、ETW 工作階段、登錄檔或核心內部資訊時使用。也適合設定 KWinSys 核心驅動程式、連線遠端 WinSysServer 目標,或偵測掛鉤與隱藏處理程序。
執行需求
需要 Visual Studio 2022、Windows SDK 10.0.26100.0 或更新版本,核心驅動程式另需 Windows 驅動程式套件(WDK)。完整功能需要系統管理員權限,驅動程式需要測試簽署,使用者掛鉤反組譯需要 Capstone。遠端檢查預設使用 TCP 連接埠 50002,且沒有身分驗證。此技能僅為說明文件,不附帶指令碼。

NtWarden Windows Analysis and Research Toolkit

Skill by ara.so — Daily 2026 Skills collection.

NtWarden is a Windows system inspection tool built on ImGui + DirectX 11. It covers processes, services, network, kernel internals, ETW, registry, object manager, and more — locally or remotely via WinSysServer. A kernel driver (KWinSys) enables deep kernel-mode analysis including SSDT hooks, kernel callbacks, EPT hook detection, and driver integrity checks.


Architecture

ComponentRole
NtWardenGUI app (ImGui + DirectX 11)
WinSysStatic lib — process, service, network enumeration
KWinSysKernel driver — callbacks, SSDT, kernel modules, pool, etc.
WinSysServerHeadless TCP server for remote inspection

Build Requirements

  • Visual Studio 2022
  • Windows SDK 10.0.26100.0+
  • WDK (Windows Driver Kit) — required only for KWinSys kernel driver

Building

powershell
# Open solution in Visual Studio 2022# Select Release | x64# Build All
# Output lands in:x64/Release/NtWarden.exex64/Release/WinSysServer.exex64/Release/KWinSys/KWinSys.sys

Solution structure:

NtWarden.sln├── NtWarden/          # GUI application├── WinSys/            # Core static library├── KWinSys/           # Kernel driver (.sys)└── WinSysServer/      # Remote TCP server

Running NtWarden

Always run as Administrator for full functionality.

powershell
# Run elevatedStart-Process NtWarden.exe -Verb RunAs

User-mode features (processes, services, network, ETW, registry, object manager) work without the driver.


Kernel Driver Setup (KWinSys)

⚠️ Use only in a test VM. Enable test signing before installing.

powershell
# Enable test signing (requires reboot)bcdedit /set testsigning on
# On VMs, may also need:bcdedit /set nointegritychecks on
# Reboot, then run NtWarden as Administrator.# Switching to the Kernel Mode tab auto-installs and starts KWinSys.

Manual driver management:

powershell
# Install manuallysc create KWinSys type= kernel binPath= "C:\path\to\KWinSys.sys"sc start KWinSys
# Stop and removesc stop KWinSyssc delete KWinSys

The NtWarden GUI also exposes driver management under the Driver menu.


Remote Inspection (WinSysServer)

Deploy to a target machine (typically a VM) and connect from NtWarden.

Files to copy to target

FileSource PathPurpose
WinSysServer.exex64/Release/WinSysServer.exeAlways required
KWinSys.sysx64/Release/KWinSys/KWinSys.sysKernel features only

Starting the server (on target, elevated)

powershell
# Auto-install driver + start server on default port 50002WinSysServer.exe --install
# Custom portWinSysServer.exe --install --port 9000
# If driver already installed manually:WinSysServer.exeWinSysServer.exe --port 9000

Connecting from NtWarden (on host)

  1. Launch NtWarden
  2. Go to Remote menu
  3. Enter target IP and port (default: 50002)
  4. Click Connect

Protocol notes

  • Custom binary protocol over TCP
  • 12-byte header: MessageType, DataSize, Status
  • No authentication — use only in isolated lab/VM environments
  • User-mode data (processes, services, network) works without KWinSys on target
  • Kernel tabs require KWinSys loaded on the remote target

WinSys Static Library — Key Usage Patterns

WinSys is the core library consumed by both NtWarden and WinSysServer. Example integration patterns in C++:

Process Enumeration

cpp
#include "WinSys/ProcessManager.h"
// Enumerate all processes (user mode)auto& pm = WinSys::ProcessManager::Get();pm.Update();  // Refresh snapshot
for (auto& proc : pm.GetProcesses()) {    printf("PID: %5u  Name: %s\n",        proc->Id,        proc->GetImageName().c_str());}

Service Enumeration

cpp
#include "WinSys/ServiceManager.h"
WinSys::ServiceManager svcMgr;auto services = svcMgr.EnumServices();
for (auto& svc : services) {    printf("Service: %-40s  State: %u  StartType: %u\n",        svc.GetName().c_str(),        svc.Status.dwCurrentState,        svc.Config.dwStartType);}

Network Connections

cpp
#include "WinSys/NetworkManager.h"
WinSys::NetworkManager netMgr;auto conns = netMgr.GetTcpConnections();
for (auto& conn : conns) {    printf("PID: %u  Local: %s:%u  Remote: %s:%u  State: %u\n",        conn.ProcessId,        conn.LocalAddress.c_str(), conn.LocalPort,        conn.RemoteAddress.c_str(), conn.RemotePort,        conn.State);}

Communicating with KWinSys Driver (IOCTL)

cpp
#include "WinSys/KernelInterface.h"
// Open handle to driver deviceWinSys::KernelInterface ki;if (!ki.Open()) {    fprintf(stderr, "Failed to open KWinSys device. Is driver loaded?\n");    return;}
// Enumerate kernel modulesauto modules = ki.EnumKernelModules();for (auto& mod : modules) {    printf("Base: %p  Size: 0x%X  Path: %s\n",        mod.Base, mod.Size, mod.FullPath.c_str());}
// Read kernel callbacksauto callbacks = ki.EnumProcessCallbacks();for (auto& cb : callbacks) {    printf("Callback: %p  Module: %s  Suspicious: %d\n",        cb.Address,        cb.OwnerModule.c_str(),        cb.IsSuspicious ? 1 : 0);}

Per-Process Security Analysis (Analyze Process)

Accessible via right-click > Analyze Process in the GUI, or programmatically:

cpp
#include "WinSys/ProcessAnalyzer.h"
DWORD targetPid = 1234;WinSys::ProcessAnalyzer analyzer(targetPid);
auto result = analyzer.Analyze();
// Unbacked executable memory (shellcode indicator)for (auto& region : result.UnbackedRegions) {    printf("Unbacked RX region: base=%p size=0x%zX\n",        region.Base, region.Size);}
// Hollowing detectionif (result.HollowingDetected) {    printf("Hollowing: PEB ImageBase=%p vs PE Header ImageBase=%p\n",        result.PebImageBase, result.PeHeaderImageBase);}
// Direct syscalls outside ntdllfor (auto& sc : result.DirectSyscalls) {    printf("Direct syscall at: %p in module: %s\n",        sc.Address, sc.ModuleName.c_str());}
// Inline user hooksfor (auto& hook : result.UserHooks) {    printf("Hook in %s!%s at %p -> %p\n",        hook.Module.c_str(),        hook.Function.c_str(),        hook.Address,        hook.Target);}
// Token infoprintf("Elevated: %d  IntegrityLevel: %u\n",    result.Token.IsElevated,    result.Token.IntegrityLevel);

Key Features by Tab

User Mode (no driver)

TabCapability
ProcessesTree view, handles, threads, memory regions, modules
PerformanceCPU/RAM/GPU/network graphs, overlay mode
ServicesStatus, start type, binary path
Network > ConnectionsTCP/UDP with owning PID
Network > Root CertificatesSubject, issuer, thumbprint
Network > NDISAdapter driver, MAC, speed, media type
ETWActive trace sessions and registered providers
IPCRPC endpoints and named pipes
Object ManagerKernel object namespace browser
RegistryKey/value browser
LoggerKernel driver debug logs + GUI logs

Kernel Mode (requires KWinSys)

TabCapability
Process ObjectsEPROCESS enumeration, hidden process detection
ModulesKernel drivers + LolDrivers check
CallbacksProcess/thread/image/registry/object/power callbacks + integrity
SSDTEntries with owner and hook detection
Kernel PoolBig pool allocations and tag stats
Memory R/WRead/write kernel memory by address
TimersPer-CPU interrupt and DPC counters
FilterMinifilter drivers with altitude/instance
Descriptor TablesGDT/IDT entries
IRP DispatchIRP dispatch table for any driver
WFPWFP callout drivers and filters
DSE StatusDriver Signature Enforcement state
CI PolicyCode Integrity policy and enforcement level
Kernel IntegrityVerify kernel .text vs on-disk image
Hypervisor HooksEPT hook detection via timing analysis

Common Patterns

Check if driver is loaded before using kernel features

cpp
#include "WinSys/KernelInterface.h"
WinSys::KernelInterface ki;bool driverAvailable = ki.Open();
if (driverAvailable) {    // Use kernel-mode features    auto ssdt = ki.GetSSDTEntries();} else {    // Fall back to user-mode only    fprintf(stderr, "KWinSys not loaded — kernel features unavailable.\n");}

Detect hidden processes (cross-reference EPROCESS list vs user-mode list)

cpp
WinSys::KernelInterface ki;ki.Open();
auto kernelProcs = ki.EnumProcessObjects();  // Via EPROCESS walkauto& pm = WinSys::ProcessManager::Get();pm.Update();auto userProcs = pm.GetProcesses();
// Build set of user-visible PIDsstd::unordered_set<DWORD> visiblePids;for (auto& p : userProcs) visiblePids.insert(p->Id);
// Find PIDs in kernel list but not user listfor (auto& kp : kernelProcs) {    if (visiblePids.find(kp.ProcessId) == visiblePids.end()) {        printf("HIDDEN PROCESS: PID=%u Name=%s\n",            kp.ProcessId, kp.ImageName.c_str());    }}

Troubleshooting

NtWarden won't show kernel tabs

  • Ensure KWinSys.sys is in the same directory as NtWarden.exe (or x64/Release/KWinSys/)
  • Run NtWarden as Administrator
  • Confirm test signing is enabled: bcdedit /enum | findstr testsigning
  • Check Logger tab for driver load errors

Driver fails to install

powershell
# Verify test signing is onbcdedit /enum | Select-String "testsigning"
# Check for existing broken service entrysc query KWinSyssc delete KWinSys  # if stuck, delete and retry
# Some VMs also need:bcdedit /set nointegritychecks on# Then reboot

WinSysServer connection refused

powershell
# Verify server is running on targetnetstat -ano | findstr 50002
# Check Windows Firewall on targetnetsh advfirewall firewall add rule name="WinSysServer" `  dir=in action=allow protocol=TCP localport=50002

Capstone not found (user hooks tab shows no data)

  • User hook detection with disassembly requires Capstone
  • Build WinSys with Capstone linked, or the hook scanner will report bytes without disassembly

Performance overlay not visible

  • Launch NtWarden, go to Performance tab
  • Enable overlay mode — it renders over other windows using DirectX 11 transparency

Build errors — missing WDK

  • KWinSys requires the Windows Driver Kit
  • If you only need user-mode features, exclude KWinSys project from build in Visual Studio (right-click project > Unload Project)

Tested Windows Versions

  • Windows 11 23H2 (Build 22631.6199)
  • Windows 10 22H2 (Build 19045.2006)
  • Windows 10 1703 (Build 15063.13)

References

  • zodiacon — Primary inspiration
  • WinArk — Kernel-mode feature reference
  • LolDrivers — Vulnerable driver database used in Modules tab

來源與署名

來源:reason-machines/trending-skills位於skills/ntwarden-windows-analysis-toolkit提交2384a00

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架