The Windows Research Kernel / ntoskrnl Source Code

Posts 1–11 of 11 · Page 1 of 1
The Windows Research Kernel / ntoskrnl Source Code
The Windows Research Kernel AKA WRK

Is a part of the source code of the actual windows NT Kernel. WRK is designed for academic uses and research, by no means it can be used for commercial purposes.

Properties

This is actually part of the windows kernel, which means you can find the source code of many kernel-level NT API functions, Structures & Data that is not defined in the standard API headers.

Uses

Since you can find here the full source codes of many APIs and structures which aren't defined in the public headers WRK can be used to study the kernel so you can actually understand what is going on 'behind the scenes'. You can find potential exploits or make your kernel modules harder to reverse by using the actual source of a structure/API instead of importing it from ntoskrnl.exe.

To Be Noted

This is not nearly the full source code of the kernel, lots of files are missing or removed. Also, this code is still somewhat protected (although leaked). Commercial use of this code is highly prohibited. Use only for personal and research purposes.

Disclaimer: I am not affiliated with microsoft or any of it's trademarks. This source code belongs to it's respective owner(s). Windows, Windows Kernel, Software Development Kits & Other Windows' components are registered trademarks of Microsoft Corporation in the United States and/or other countries.

Virus scans:
https://virustotal.com/en/file/44055...is/1478727593/.
https://virusscan.jotti.org/en-GB/fi...job/rx0nfiihvr.

https://virustotal.com/en/file/19757...is/1478867626/.
https://virusscan.jotti.org/en-US/fi...job/gubjh0o3vi.

I've also added header file "ntos.h" which as bulk-imported functions & structures from ntoskrnl.exe that are not defined in the regulard ddk headers.
Just include ntos.h to your driver project, and remove ntifs, ntdef & ntddk. from includes.
ntoskrnl_mpgh.net.rar8.2 MB · 41 downloads Clean
ntos_mpgh.net.rar11 KB · 27 downloads Clean
Quote Originally Posted by nullptr_t View Post
The Windows Research Kernel AKA WRK

Is a part of the source code of the actual windows NT Kernel. WRK is designed for academic uses and research, by no means it can be used for commercial purposes.

Properties

This is actually part of the windows kernel, which means you can find the source code of many kernel-level NT API functions, Structures & Data that is not defined in the standard API headers.

Uses

Since you can find here the full source codes of many APIs and structures which aren't defined in the public headers WRK can be used to study the kernel so you can actually understand what is going on 'behind the scenes'. You can find potential exploits or make your kernel modules harder to reverse by using the actual source of a structure/API instead of importing it from ntoskrnl.exe.

To Be Noted

This is not nearly the full source code of the kernel, lots of files are missing or removed. Also, this code is still somewhat protected (although leaked). Commercial use of this code is highly prohibited. Use only for personal and research purposes.

Disclaimer: I am not affiliated with microsoft or any of it's trademarks. This source code belongs to it's respective owner(s). Windows, Windows Kernel, Software Development Kits & Other Windows' components are registered trademarks of Microsoft Corporation in the United States and/or other countries.

https://virusscan.jotti.org/en-GB/fi...job/rx0nfiihvr
https://virustotal.com/en/file/44055...is/1478727593/
friend you have skype?
Quote Originally Posted by DaniielSanchez View Post
friend you have skype?
Yes, but why do you need it?
I remember going through this many years ago. It used to be available on MSDN I believe and later took it down. It's a nice resource if you want to get into kernel mode development but Microsoft is trying to shift away from the old WDM into KMDF. It's still relevant though depending on how one wishes write to their device drivers.
Quote Originally Posted by nullptr_t View Post
The Windows Research Kernel AKA WRK

Is a part of the source code of the actual windows NT Kernel. WRK is designed for academic uses and research, by no means it can be used for commercial purposes.

Properties

This is actually part of the windows kernel, which means you can find the source code of many kernel-level NT API functions, Structures & Data that is not defined in the standard API headers.

Uses

Since you can find here the full source codes of many APIs and structures which aren't defined in the public headers WRK can be used to study the kernel so you can actually understand what is going on 'behind the scenes'. You can find potential exploits or make your kernel modules harder to reverse by using the actual source of a structure/API instead of importing it from ntoskrnl.exe.

To Be Noted

This is not nearly the full source code of the kernel, lots of files are missing or removed. Also, this code is still somewhat protected (although leaked). Commercial use of this code is highly prohibited. Use only for personal and research purposes.

Disclaimer: I am not affiliated with microsoft or any of it's trademarks. This source code belongs to it's respective owner(s). Windows, Windows Kernel, Software Development Kits & Other Windows' components are registered trademarks of Microsoft Corporation in the United States and/or other countries.

https://virusscan.jotti.org/en-GB/fi...job/rx0nfiihvr
https://virustotal.com/en/file/44055...is/1478727593/

I've also added header file "ntos.h" which as bulk-imported functions & structures from ntoskrnl.exe that are not defined in the regulard ddk headers.
Just include ntos.h to your driver project, and remove ntifs, ntdef & ntddk. from includes.
help on creating a hack, I have the code I dont know compilar I need you.
Quote Originally Posted by DaniielSanchez View Post
help on creating a hack, I have the code I dont know compilar I need you.
I don't personally help people out for free.

- - - Updated - - -

Quote Originally Posted by __readgsqword View Post
I remember going through this many years ago. It used to be available on MSDN I believe and later took it down. It's a nice resource if you want to get into kernel mode development but Microsoft is trying to shift away from the old WDM into KMDF. It's still relevant though depending on how one wishes write to their device drivers.
To my knowledge it was never available for download just anyone. At least you'd had to be a dreamspark member to have access this.
/New attachment approved. Post back results and as always, use at your own risk.
So basically ReactOS...
Quote Originally Posted by Hitokiri~ View Post
So basically ReactOS...
Basically, but just narrowed down to the ntoskrnl part...
Posts 1–11 of 11 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us