| 8.30 | Coffee |
9.00 | Introducion & Welcome by Kimmo Rousku |
9.10 | Windows Kernel Architecture & Key Mechanisms |
| Tools Introduction (Kernel Debugger, Sysinternals) |
| Process Execution Context |
| Kernel Design |
| Multiprocessor Support |
| Kernel Components (Executive, Kernel, HAL) |
| Environment Subsystems |
| Sessions |
| System Threads |
| System Processes |
| Handles & Objects |
| Interrupts & Time Accounting |
12.15 | Lunch |
13.00 | Security Internals |
| Security Components |
| Object Protection |
| Authorization |
| User Account Control |
| Mandatory Integrity Levels |
14.30 | Coffee break |
14.45 | Security Internals (continued) |
| Process & Threads Internals |
| Process, thread and job data structures |
| Process startup and exit |
| Thread scheduling algorithms |
17.30 | Lottery: 2 lucky ones will win Rousku Ultimate Vista Machine |
| Buffet & cocktails |
19.30 | End of Buffet & cocktails |
| 8.30 | Coffee |
9.00 | Flashback from yesterday (Kimmo Rousku) |
| Memory Management Internals |
| Core mechanisms |
| Virtual Address Translation |
| Working Set Management |
10.30 | Coffee Break |
10.45 | Memory Management Internals |
| Physical Memory Management |
| Superfetch |
| File System Cache |
| Paging Files |
12.15 | Lunch |
13.00 | Startup & Shutdown Internals |
| Boot Process |
| Logon Process |
| Shutdown |
14.30 | Coffee break |
14.45 | Crash Dump Analysis |
| Why Windows crashes |
| What happens at the crash |
| Basic crash dump analysis |
| Harder dump analysis |
| System hangs |
16.45 | Lottery: 2 lucky ones will win Rousku Ultimate Vista Machine |
| Final thoughts |
17.00 | End of seminar |