> Windows Syscalls

Cross-version syscall map

Compare syscall IDs across Windows builds. This page is under construction in Phase 1 — the data model is wired and the table will populate as syscalls are added.

SyscallWin10 1507Win10 1607Win10 1703Win10 1709Win10 1803Win10 1809Win10 1903Win10 1909Win10 2004Win10 20H2Win10 21H1Win10 21H2Win10 22H2Win11 21H2Win11 22H2Win11 23H2Win11 24H2Server 2016Server 2019Server 2022Server 2025
NtAllocateVirtualMemory0x180x180x180x180x180x180x180x180x180x180x180x180x18
NtProtectVirtualMemory0x500x500x500x500x500x500x500x500x500x500x500x500x500x500x500x500x500x500x500x500x50
NtWriteVirtualMemory0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A0x3A
NtReadVirtualMemory0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F0x3F
NtOpenProcess0x260x260x260x260x260x260x260x260x260x260x260x260x260x260x260x260x260x260x260x260x26
NtCreateThreadEx0xB30xB60xB90xBA0xBB0xBC0xBD0xBD0xC10xC10xC10xC20xC20xC60xC70xC70xC90xB60xBC0xC50xC9
NtCreateSection0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A0x4A
NtMapViewOfSection0x280x280x280x280x280x280x280x280x280x280x280x280x280x280x280x280x280x280x280x280x28
NtQueueApcThread0x450x450x450x450x450x450x450x450x450x450x450x450x450x450x450x450x450x450x450x450x45
NtResumeThread0x520x520x520x520x520x520x520x520x520x520x520x520x520x520x520x520x520x520x520x520x52
NtOpenProcessToken0x1140x1190x11D0x11F0x1210x1220x1230x1230x1280x1280x1280x1290x1290x12F0x1310x1310x1330x1190x1220x12E0x133
NtOpenProcessTokenEx0x300x300x300x300x300x300x300x300x300x300x300x300x300x300x300x300x300x300x300x300x30
NtAdjustPrivilegesToken0x410x410x410x410x410x410x410x410x410x410x410x410x410x410x410x410x410x410x410x410x41
NtQueryInformationToken0x210x210x210x210x210x210x210x210x210x210x210x210x210x210x210x210x210x210x210x210x21
NtDuplicateToken0x420x420x420x420x420x420x420x420x420x420x420x420x420x420x420x420x420x420x420x420x42
NtImpersonateAnonymousToken0xED0xF00xF30xF40xF50xF60xF70xF70xFC0xFC0xFC0xFD0xFD0x1020x1030x1030x1050xF00xF60x1010x105
NtImpersonateThread0xEE0xF10xF40xF50xF60xF70xF80xF80xFD0xFD0xFD0xFE0xFE0x1030x1040x1040x1060xF10xF70x1020x106
NtSetInformationThread0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD0xD
NtCreateKey0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D0x1D
NtSetValueKey0x600x600x600x600x600x600x600x600x600x600x600x600x600x600x600x600x600x600x600x600x60
NtCreateFile0x550x550x550x550x550x550x550x550x550x550x550x550x550x550x550x550x550x550x550x550x55
NtWriteFile0x80x80x80x80x80x80x80x80x80x80x80x80x80x80x80x80x80x80x80x80x8
NtSetInformationFile0x270x270x270x270x270x270x270x270x270x270x270x270x270x270x270x270x270x270x270x270x27
NtSetSystemInformation0x18E0x1970x19D0x1A00x1A20x1A30x1A40x1A40x1AA0x1AA0x1AA0x1AC0x1AC0x1B50x1B90x1B90x1BC0x1970x1A30x1B20x1BC
More data coming soon