windows-internals

Installation
SKILL.md

Windows Internals — detection-relevant knowledge

This skill encodes how Windows actually works at the level needed to write detections that survive tool changes and evasion. It answers: "Why is this behaviour suspicious?" rather than "What tool name should I look for?"


1. Process creation chain

When a process is created on Windows, the following sequence occurs:

CreateProcess(W) API call
  → Kernel validates executable image
  → Access token assigned (inherited from parent or explicitly specified)
  → Primary thread created
  → DLLs loaded (ntdll.dll → kernel32.dll → application imports)
  → Process initialisation (TLS callbacks, DllMain for loaded DLLs)
  → Entry point executed
Installs
3
First Seen
Sep 16, 2026