Detours: Runtime API Interception on Windows
Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
At a glance
- What is it?
- A Microsoft library for intercepting and instrumenting Windows API calls at runtime. Runs on Windows NT through Windows 11, used for debugging, dynamic analysis, and tracing application behavior without source code changes.
- Who is it for?
- Detours is for Windows developers, security researchers, and system administrators who need runtime visibility into API calls. Use it to debug application behavior, analyze untrusted code, trace system interactions, or audit compliance with policies.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 37 days ago.
- What is it written in?
- Mainly C++, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.
Editorial analysis
Runtime interception replacing static analysis
Detours is a Microsoft library that intercepts function calls inside running processes on Windows. Instead of modifying source code or recompiling, you write a small plugin (called a detour) that intercepts calls to a target function, observes the call and arguments, optionally modifies the behavior, and passes control to the original function or a replacement. This happens at runtime without touching the original executable.
Common use cases include observing which files an application opens, which network calls it makes, which registry keys it reads, and which functions it calls in third-party DLLs. The README states that Detours has been used by independent software vendors and Microsoft product teams for debugging, security analysis, and telemetry collection.
Detours is a runtime tool, not a static analysis tool. It works on compiled binaries in memory, so you can analyze applications where you do not have source code. This makes it useful for examining untrusted applications, understanding legacy systems, and verifying that a closed-source library behaves as documented.
How Detours intercepts function calls
Detours works by modifying the entry point of target functions in memory. It replaces the first few bytes of a function with a jump instruction that redirects control to your detour code. Your detour code can inspect the arguments, call the original function, inspect the return value, and then return to the caller. This is called function hooking or API hooking.
The process requires that you specify which DLL and which function you want to intercept. Detours handles the machinery of finding the function in memory, creating a trampoline that preserves the original function's behavior, and inserting the jump instruction. A trampoline is a piece of code that executes the original function's preamble and then jumps to the rest of the function, allowing the original behavior to continue.
Detours can intercept functions in system DLLs (like kernel32.dll, ntdll.dll, ws2_32.dll) and in third-party libraries. It supports both 32-bit and 64-bit processes. The level of control you have depends on the function: some functions are simple to intercept, while others have complex calling conventions or are optimized in ways that complicate hooking.
Supported platforms and incompatibilities
Detours works on Windows NT, Windows XP, Windows Server 2003, Windows 7, Windows 8, Windows 10, and Windows 11. It runs on both x86 and x64 architectures. The current version in the repository is 4.0.1, released on 2018-04-16.
Detours cannot be used by Windows Store apps. The Windows Store environment sandboxes applications and does not expose the low-level APIs that Detours requires to inject hooks into running processes. If you are developing a store app, or if you need to analyze a store app, Detours is not an option.
For traditional Windows desktop applications, services, command-line tools, and server processes, Detours works. You have full access to the process memory and can instrument any DLL that is loaded.
Building and sample programs
Detours is distributed in source code form, not as pre-built binaries. The repository includes a Makefile and vc/ subdirectory with Visual Studio project files for building the core library. Building requires a Windows environment with a C++ compiler such as Visual Studio. The root Makefile orchestrates building the core library, source files in src/, samples, and tests with `make all`; `make clean` and `make realclean` are also available. The system.mak file defines build variables and platform settings.
The samples directory contains more than a dozen example programs demonstrating common techniques. The README points to samples/README.TXT for detailed build and run instructions. Examples include comeasy (intercepting COM objects), dtest (testing and tracing DLL initialization), dumpe (dumping executable structure), dumpi (dumping imports), einst (installing detours into a live process), excep (exception handling in detours), findfunc (locating functions in DLLs), member (intercepting class methods), opengl (hooking OpenGL calls), payload (injecting code into processes), region (analyzing memory regions), setdll (injecting a DLL), simple and simple_safe (basic hooking patterns), slept (tracing Sleep calls), and syelog (event logging).
Each sample demonstrates a specific pattern: how to write a detour handler function, how to attach to a running process, how to deal with calling conventions, how to preserve stack alignment, and how to avoid common mistakes like incorrect function signatures or incomplete trampolines. The samples are intended as reference implementations showing both correct and safe approaches (simple_safe) alongside basic patterns (simple).
Documentation and community resources
Technical documentation is maintained on the Detours Wiki on GitHub. The wiki covers topics like architecture, calling conventions, ARM support, and advanced techniques. The project uses standard GitHub workflows: issues for bug reports and questions, pull requests for contributions, and releases announced via a low-traffic mailing list (detours-announce).
Contributions to Detours require agreeing to a Contributor License Agreement (CLA), which assigns rights to Microsoft. This is standard for Microsoft open source projects but can be a barrier for some contributors.
Maintenance status and long-term support
The last push to the repository was on 2026-08-24. The most recent release, v4.0.1, was published on 2018-04-16, more than eight years ago. The gap between the release date and recent pushes suggests the project is in maintenance mode: the core code is stable and mature, changes are infrequent and mainly address bugs or minor updates. The repository includes a Makefile for compilation and a tests/ directory with test suites, indicating the codebase includes comprehensive testing infrastructure.
Detours was developed by Microsoft Research and has been in use internally and by external users for many years. The codebase is well-tested and unlikely to change significantly. The Windows NT family of operating systems is a stable platform; the core mechanisms Detours relies on (function hooking, DLL injection, memory modification) have not changed substantially across Windows versions from NT through Windows 11. If you rely on Detours, maintenance mode is reassuring: you get stability at the cost of few new features. The community uses GitHub issues for bug reports and pull requests for contributions. The detours-announce mailing list provides a low-traffic channel for announcements about new versions.
The license is MIT, which allows commercial and private use without cost. There are no licensing costs or restrictions on distributing software that uses Detours. The project includes a SECURITY.md file documenting security considerations for using the library.
Editorial conclusion
Detours is for Windows developers, security researchers, and system administrators who need runtime visibility into API calls. Use it to debug application behavior, analyze untrusted code, trace system interactions, or audit compliance with policies. Skip it if you need to support Windows Store apps (which are incompatible) or if you target non-Windows platforms. Verify first that the binaries you plan to instrument have no anti-tampering protection, that you have permission to modify the running process, and that intercepting calls to the DLLs you target does not violate their licensing terms.
Frequently asked questions
What is Detours?
Detours is a Microsoft library for intercepting and monitoring Windows API calls at runtime. It modifies functions in memory to inject hooks, allowing you to observe, modify, or log calls without changing source code.
How do I use Detours?
Build the Detours library from source using the included Makefile. Write a detour handler function in C++, specify which DLL and function you want to hook, and link against the Detours library. Sample programs in the repository demonstrate the pattern.
What Windows versions does Detours support?
Detours supports Windows NT, Windows XP, Windows Server 2003, Windows 7, Windows 8, Windows 10, and Windows 11 on both x86 and x64. It cannot be used by Windows Store apps.
Is Detours still maintained?
The latest release was v4.0.1 in 2018. The repository receives occasional updates, most recently in 2026-08. The project is in maintenance mode, meaning the core is stable with infrequent changes.
Can I use Detours to analyze closed-source software?
Yes. Detours works on compiled binaries without source code. You can hook system DLLs and third-party libraries to observe what calls the application makes and what those functions return.
What is the difference between Detours and static analysis?
Detours intercepts function calls while a program runs and can see the actual values passed and returned. Static analysis tools examine source code or compiled binaries without running them and cannot capture runtime behavior.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/microsoft-detours)