Windows Kernel Programming
Windows Kernel Programming
About the Book
The book describes software kernel drivers programming for Windows. These drivers don't deal with hardware, but rather with the system itself: processes, threads, modules, registry and more. Kernel code can be used for monitoring important events, preventing some from occurring if needed. Various filters can be written that can intercept calls that a driver may be interested in.
- Who Should Read This Book
- What You Should Know to Use This Book
- Sample Code
Chapter 1: Windows Internals Overview
- Page States
- System Memory
- Thread Stacks
- System Services (a.k.a. System Calls)
- General System Architecture
Handles and Objects
- Object Names
- Accessing Existing Objects
Chapter 2: Getting Started with Kernel Development
- Installing the Tools
- Creating a Driver Project
- The DriverEntry and Unload Routines
- Deploying the Driver
- Simple Tracing
Chapter 3: Kernel Programming Basics
General Kernel Programming Guidelines
- Unhandled Exceptions
- Function Return Values
- C++ Usage
- Testing and Debugging
- Debug vs. Release Builds
- The Kernel API
- Functions and Error Codes
- Dynamic Memory Allocation
- The Driver Object
- Device Objects
- General Kernel Programming Guidelines
Chapter 4: Driver from Start to Finish
- Passing Information to the Driver
- Client / Driver Communication Protocol
- Creating the Device Object
- Client Code
- The Create and Close Dispatch Routines
- Installing and Testing
Chapter 5: Debugging
- Debugging Tools for Windows
Introduction to WinDbg
- Tutorial: User mode debugging basics
- Local Kernel Debugging
- Local kernel Debugging Tutorial
Full Kernel Debugging
- Configuring the Target
- Configuring the Host
- Kernel Driver Debugging Tutorial
Chapter 6: Kernel Mechanisms
Interrupt Request Level
- Raising and Lowering IRQL
- Thread Priorities vs. IRQLs
Deferred Procedure Calls
- Using DPC with a Timer
Asynchronous Procedure Calls
- Critical Regions and Guarded Regions
Structured Exception Handling
Using C++ RAII Instead of
- Crash Dump Information
- Analyzing a Dump File
- System Hang
- Interlocked Operations
- Dispatcher Objects
- Fast Mutex
- Executive Resource
High IRQL Synchronization
- The Spin Lock
- Work Items
- Interrupt Request Level
Chapter 7: The I/O Request Packet
- Introduction to IRPs
- IRP Flow
IRP and I/O Stack Location
- Viewing IRP Information
- Completing a Request
Accessing User Buffers
- Buffered I/O
- Direct I/O
User Buffers for
Putting it All Together: The Zero Driver
- Using a Precompiled Header
- The Read Dispatch Routine
- The Write Dispatch Routine
- Test Application
Chapter 8: Process and Thread Notifications
- Process Notifications
Implementing Process Notifications
- Handling Process Exit Notifications
- Handling Process Create Notifications
Providing Data to User Mode
- The User Mode Client
- Thread Notifications
- Image Load Notifications
Chapter 9: Object and Registry Notifications
- Pre-Operation Callback
- Post-Operation Callback
The Process Protector Driver
- Object Notification Registration
- Managing Protected Processes
- The Pre-Callback
- The Client Application
- Handling Pre-Notifications
- Handling Post-Operations
- Performance Considerations
Implementing Registry Notifications
- Handling Registry Callback
- Modified Client Code
- Object Notifications
Chapter 10: Introduction to File System Mini-Filters
- Loading and Unloading
- Operations Callback Registration
- The Altitude
- INF Files
- Installing the Driver
Processing I/O Operations
- Pre Operation Callbacks
- Post Operation Callbacks
The Delete Protector Driver
- Handling Pre-Create
- Handling Pre-Set Information
- Some Refactoring
- Generalizing the Driver
- Testing the Modified Driver
- File Name Parts
The Alternate Delete Protector Driver
- Handling Pre-Create and Pre-Set Information
- Testing the Driver
- Managing Contexts
- Initiating I/O Requests
The File Backup Driver
- The Post Create Callback
- The Pre-Write Callback
- The Post-Cleanup Callback
- Testing the Driver
- Restoring Backups
User Mode Communication
- Creating the Communication Port
- User Mode Connection
- Sending and Receiving Messages
- Enhanced File Backup Driver
- The User Mode Client
Chapter 11: Miscellaneous Topics
- Driver Signing
- Example Driver Verifier Sessions
- Using the Native API
- Filter Driver Implementation
- Attaching Filters
- Attaching Filters at Arbitrary Time
- Filter Cleanup
- More on Hardware-Based Filter Drivers
- Adding a Device to Filter
- Removing a Filter Device
- Initialization and Unload
- Handling Requests
- Testing the Driver
- Results of Requests
- Driver Hooking
- Kernel Libraries
The Leanpub 45-day 100% Happiness Guarantee
Within 45 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.
See full terms
Free Updates. DRM Free.
If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).
Most Leanpub books are available in PDF (for computers), EPUB (for phones and tablets) and MOBI (for Kindle). The formats that a book includes are shown at the top right corner of this page.
Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.
C++ Best PracticesJason Turner
Level up your C++, get the tools working for you, eliminate common problems, and move on to more exciting things!
OpenIntro StatisticsDavid Diez, Christopher Barr, Mine Cetinkaya-Rundel, and OpenIntro
A complete foundation for Statistics, also serving as a foundation for Data Science.
Leanpub revenue supports OpenIntro (US-based nonprofit) so we can provide free desk copies to teachers interested in using OpenIntro Statistics in the classroom and expand the project to support free textbooks in other subjects.
More resources: openintro.org.
Functional Design and ArchitectureAlexander Granin
Software Design in Functional Programming, Design Patterns and Practices, Methodologies and Application Architectures. How to build real software in Haskell with less efforts and low risks. The first complete source of knowledge.
R Programming for Data ScienceRoger D. Peng
This book brings the fundamentals of R programming to you, using the same material developed as part of the industry-leading Johns Hopkins Data Science Specialization. The skills taught in this book will lay the foundation for you to begin your journey learning data science. Printed copies of this book are available through Lulu.
C++20 is the next big C++ standard after C++11. As C++11 did it, C++20 changes the way we program modern C++. This change is, in particular, due to the big four of C++20: ranges, coroutines, concepts, and modules.
I am a Software Engineer and I am in ChargeAlexis Monville and Michael Doyle
I am a Software Engineer and I am in Charge is a real-world, practical book that helps you increase your impact and satisfaction at work no matter who you work with.
In the book, we will follow Sandrine, a fictional character who learns to think in a new way enabling her to take a different course of action.
Atomic KotlinBruce Eckel and Svetlana Isakova
For both beginning and experienced programmers! From the author of the multi-award-winning Thinking in C++ and Thinking in Java together with a member of the Kotlin language team comes a book that breaks the concepts into small, easy-to-digest "atoms," along with exercises supported by hints and solutions directly inside IntelliJ IDEA!
Invest In Digital Health - The Medical Futurist's GuideDr. Bertalan Mesko
Artificial Intelligence and Digital Health are booming. In this book, we explain why now it's a good time to invest in Digital Health and give recommendations on where to invest by looking at the top 24 technological trends we find the most promising.
The Hundred-Page Machine Learning BookAndriy Burkov
Everything you really need to know in Machine Learning in a hundred pages.
Mastering STM32Carmine Noviello
With more than 600 microcontrollers, STM32 is probably the most complete ARM Cortex-M platform on the market. This book aims to be the first guide around that introduces the reader to this exciting MCU portfolio from ST Microelectronics and its official CubeHAL.
Software Architecture for Developers: Volumes 1 & 2 - Technical leadership and communication
2 Books"Software Architecture for Developers" is a practical and pragmatic guide to modern, lightweight software architecture, specifically aimed at developers. You'll learn:The essence of software architecture.Why the software architecture role should include coding, coaching and collaboration.The things that you really need to think about before...
CCIE Service Provider Ultimate Study Bundle
2 BooksPiotr Jablonski, Lukasz Bromirski, and Nick Russo have joined forces to deliver the only CCIE Service Provider training resource you'll ever need. This bundle contains a detailed and challenging collection of workbook labs, plus an extensively detailed technical reference guide. All of us have earned the CCIE Service Provider certification...
The Future of Digital Health
6 BooksWe put together the most popular books from The Medical Futurist to provide a clear picture about the major trends shaping the future of medicine and healthcare. Digital health technologies, artificial intelligence, the future of 20 medical specialties, big pharma, data privacy and how technology giants such as Amazon or Google want to conquer...
Cisco CCNA 200-301 Complet
4 BooksCe lot comprend les quatre volumes du guide préparation à l'examen de certification Cisco CCNA 200-301.
CCDE Practical Studies (All labs)
3 BooksCCDE lab
"The C++ Standard Library" and "Concurrency with Modern C++"
2 BooksGet my books "The C++ Standard Library" and "Concurrency with Modern C++" in a bundle. The first book gives you the details you should know about the C++ standard library; the second one dives deeper into concurrency with modern C++. In sum, you get more than 600 pages full of modern C++ and about 250 source files presenting the standard library...
Modern Management Made Easy
3 BooksRead all three Modern Management Made Easy books. Learn to manage yourself, lead and serve others, and lead the organization.
Linux Administration Complet
4 BooksCe lot comprend les quatre volumes du Guide Linux Administration :Linux Administration, Volume 1, Administration fondamentale : Guide pratique de préparation aux examens de certification LPIC 1, Linux Essentials, RHCSA et LFCS. Administration fondamentale. Introduction à Linux. Le Shell. Traitement du texte. Arborescence de fichiers. Sécurité...
Programming with Ease
3 BooksAlle drei Bände der Serie Programming with Ease in einem Paket. Darin findest du alles, was ich dir zu den wichtigsten Phasen der Softwareentwicklung im Hinblick auf Clean Code Development für langfristig hohe Produktivität sagen kann.Im Band Slicing findest du die Anforderungsanalyse im Rahmen eines iterativ-inkrementellen Vorgehensmodells aus...
2 BooksUnveil the power of Ansible and Vagrant with this bundle at a special price. You'll have everything you need to get started with Vagrant - learn the basics and how to create your virtual development environments, using Ansible as provisioner! About Vagrant Cookbook Vagrant Cookbook is a complete guide to get started with Vagrant and create your...