windows-internals
Installation
SKILL.md
Windows Internals — detection-relevant knowledge
This skill encodes how Windows actually works at the level needed to write detections that survive tool changes and evasion. It answers: "Why is this behaviour suspicious?" rather than "What tool name should I look for?"
1. Process creation chain
When a process is created on Windows, the following sequence occurs:
CreateProcess(W) API call
→ Kernel validates executable image
→ Access token assigned (inherited from parent or explicitly specified)
→ Primary thread created
→ DLLs loaded (ntdll.dll → kernel32.dll → application imports)
→ Process initialisation (TLS callbacks, DllMain for loaded DLLs)
→ Entry point executed