Understanding the Windows Boot Process: UEFI, Boot Manager, and Winload
How a modern Windows machine goes from firmware to a running kernel, and where each stage's configuration actually lives.
Conceptual, architectural explainers - how a subsystem actually works underneath.
How a modern Windows machine goes from firmware to a running kernel, and where each stage's configuration actually lives.
How discretionary ACLs, mandatory integrity levels, and UAC's token-splitting combine to form Windows' layered access control model.
How Group Policy Objects, ADMX templates, and the client-side refresh cycle turn Active Directory structure into enforced machine configuration.
How NTFS's Master File Table, transaction journal, and lesser-known features like alternate data streams and the USN journal actually work.
How WinRM and PowerShell Remoting turn scattered single-machine administration into fleet-wide scripted management across hundreds of servers.
How the Windows kernel represents processes as containers of handles and a security token, and the tools to inspect both live.
How the registry's hive files, keys, and value types work under the hood, and the tools to inspect and edit them safely.
How the Service Control Manager starts, stops, and supervises background processes, and how to configure and debug a service directly.
How Task Scheduler's triggers, actions, and conditions work together, and how to build and inspect scheduled tasks from the command line.
How WSL2 differs fundamentally from WSL1's syscall translation, running an actual Linux kernel in a lightweight, tightly-integrated VM.