# Hypervisor From Scratch: a Windows VT-x hypervisor built from a tutorial series

> SinaKarvandi/Hypervisor-From-Scratch is the companion source code for an eight-part tutorial on Intel VT-x hypervisors, written in C and built with the Windows Driver Kit. It is a teaching artifact, not a production hypervisor, and the README says so indirectly by warning that earlier parts are unmaintained.

**SinaKarvandi/Hypervisor-From-Scratch** — Source code of a multiple series of tutorials about the hypervisor. Available at: https://rayanfam.com/tutorials

- Repository: https://github.com/SinaKarvandi/Hypervisor-From-Scratch
- Website: https://rayanfam.com/tutorials
- Stars: 2,667 · Forks: 360
- Language: C
- License: MIT
- Published: 2026-09-28 · Updated: 2026-09-28 · Language: en
- Canonical page: https://hysenlabs.com/projects/sinakarvandi-hypervisor-from-scratch

## What Hypervisor From Scratch actually is

This repository is the source code that accompanies a tutorial series, not a standalone hypervisor product. The README describes it as "Source code of a multiple series of tutorials about the hypervisor" and points to rayanfam.com/tutorials for the written parts. The top level of the repository is organized by tutorial part, from "Part 1 - Basic Concepts & Configure Testing Environment" through "Part 8 - How To Do Magic With Hypervisor!", with each part in its own directory.

The audience is specific. Someone who wants to understand how Intel VT-x works at the level of VMCS fields, EPT tables and VM exits, and who is willing to read C driver code alongside prose. The topics list on the repository (ept, hidden-hook, hypervisor, tutorial, vmx, vt-x) matches that scope. If you want a hypervisor to run workloads, this is the wrong repository; the README itself redirects people who want analysis and reverse engineering tooling to HyperDbg.

## How the tutorial code is organized across the eight parts

Each numbered directory is a snapshot of the code at that stage of the series, and the progression is the architecture. Part 2, "Entering VMX Operation", covers the transition into VMX root operation. Part 3 sets up a first virtual machine. Part 4 is address translation with the Extended Page Table. Part 5 brings in the VMCS and running guest code. Part 6 handles virtualizing a system that is already running, which is the harder case because you are taking over a live machine rather than starting a guest from nothing. Part 7 uses EPT for page-level monitoring, and Part 8 is the catch-all "How To Do Magic With Hypervisor!" part.

That ordering matters for anyone reading the code. The later parts contain the more complete driver, and the README is explicit that changes are applied to newer parts while earlier parts stay as they were. So the directories are not eight parallel implementations of the same thing; they are a timeline, and the newest directory is the one closest to something you could extend.

## Installing the WDK and compiling the driver

The README gives a short build path and no more: install Visual Studio, then install the Windows Driver Kit, then compile. There are no package manager commands, no CMake invocation and no build script documented in the README, so the expectation is that you open the driver project for the part you are studying in Visual Studio with the WDK integration present.

The only environment facts the README states are about where the drivers have been exercised. According to the README, the drivers are tested on physical machines and on VMware Workstation nested virtualization, and from Part 8 onward support for Hyper-V is added, which means Part 8 and newer parts can be tested on a physical machine, under VMware Workstation nested virtualization, or under Hyper-V nested virtualization. Nothing else about the host configuration is documented in the README, so the per-part tutorial pages are where setup detail lives:

```bash
# The README documents no command-line build. The stated prerequisites are:
# 1. Install Visual Studio
# 2. Install Windows Driver Kit (WDK)
# 3. Compile the driver from the part directory you are studying
```

A first real use is to pick the latest part, build that driver, and load it on a machine that matches one of the three environments the README lists. If you start from Part 1 instead, expect to hit the instability the README warns about, because those earlier directories were not revised when the series was.

## The maintenance boundary the README draws itself

The most useful paragraph in the README is the note about drift. Hypervisors change as operating systems add features and as hardware mitigations land; the README names the Meltdown and Spectre updates as an example of changes that forced hypervisor work. Its instruction is blunt: if you want to use Hypervisor From Scratch in projects or research, use the driver from the latest parts, because the tutorial is updated in the newer parts while earlier parts keep untouched. It then says you might encounter errors and instability in the earlier parts.

That is a real limitation stated by the project, and it should shape how you read the repository. Part 1 through Part 7 are historical teaching material. They are still valuable for understanding how a concept was introduced, but they are not a supported code path. Treat any bug you find in an early part as expected rather than as something to file.

The last push to the repository was on 2026-05-13, so it is not abandoned, but the README's own framing tells you the maintenance is uneven across directories, and that is the thing to internalize before you plan work on top of it.

## Where this is the wrong tool, and what to use instead

If your goal is to analyze, fuzz or reverse engineer software with a hypervisor, this repository is the wrong starting point and the README says so directly. It points to HyperDbg, described there as a hypervisor-based debugger designed specifically for analyzing, fuzzing and reversing applications. The difference in approach is the difference between a course and a tool: Hypervisor From Scratch gives you the primitives (VMX entry, EPT, VMCS setup) so you can see how the machine works, while HyperDbg is an assembled debugger you drive to get work done. Choosing the tutorial when you wanted the debugger means you spend your time on VM exits instead of on the target.

The README also links OpenSecurityTraining2's material (dbg3301) as the preferred tutorial for hypervisor-based reverse engineering, with a YouTube playlist as the alternative. That is another signal that the project positions itself as fundamentals, not as the practical end of the field.

A second case where it is the wrong tool: anything that needs a supported, versioned artifact. The repository retrieved no releases, and the README documents no installation package, no signing story and no update mechanism. You compile a driver from source and load it yourself.

## Licence and what MIT means for driver code you adapt

The README states that Hypervisor From Scratch is licensed under the MIT license, and the repository carries a LICENSE file at the top level. MIT is permissive: it allows reuse, modification and redistribution provided the copyright notice and permission notice are retained. For a tutorial repository this is generous, because it means you can lift a function or a structure definition into your own driver without a copyleft obligation.

Two practical points follow, neither of them legal advice. First, MIT covers the code in this repository; it does not cover Intel's software developer manuals, the WDK headers you compile against, or any third-party material the tutorial pages link to, and those carry their own terms. Second, a licence grant says nothing about whether the code is correct or safe. Loading a hypervisor changes how the machine behaves at the lowest level, and the README's warning about instability in earlier parts is a technical statement, not a licensing one. Keep the copyright notice in files you copy, and treat the code as a learning reference that you re-derive rather than as a vetted component.

## What to check before you commit to the series

Read the note in the README before you open any directory, then decide which part you actually need. If you are following the concepts in order, the early parts are fine as reading. If you intend to build and load a driver, go to the latest part and work backward only when a concept is unclear.

Check your environment against the three the README lists for Part 8 and newer: physical machine, VMware Workstation nested virtualization, or Hyper-V nested virtualization. If your setup is none of those, the README does not tell you what to expect.

Finally, look at the tutorial pages themselves. The README's build instructions stop at "install Visual Studio, install WDK, compile", so anything about project configuration, test signing or debugging setup has to come from the part you are reading. The repository is the code half of the material; the prose half is on rayanfam.com.

## Conclusion

Adopt this if you are learning Intel VT-x and want working driver code that pairs with written explanations, and start from Part 8 because the README states that earlier parts are left untouched and that the latest parts are the ones to use in real projects. Do not adopt it as the base for a shipped product: it is a tutorial, the README points production analysis users to HyperDbg, and the repository carries no release artifacts. Verify first that your machine or nested-virtualization setup matches what the README describes, and read the part-specific page before compiling, because the README gives only the WDK prerequisite and no per-part build flags.

## FAQ

### How can I build my own hypervisor with Hypervisor From Scratch?

The README says to install Visual Studio, then the Windows Driver Kit, and compile the driver from the part directory you are studying. It recommends starting from the latest parts, because earlier parts are left untouched and may show errors or instability.

### What is a hypervisor in simple terms, and how does Hypervisor From Scratch explain it?

The repository does not define the term in the README; it points to the tutorial pages, starting with Part 1, "Basic Concepts & Configure Testing Environment", for the conceptual explanation. The repository itself is the source code that accompanies that series.

### Can you give me an example of a hypervisor, and is Hypervisor From Scratch one?

Hypervisor From Scratch is the source code of a tutorial series about building a hypervisor, not a finished hypervisor you deploy. The README points readers who want a hypervisor for analysis and reverse engineering to HyperDbg instead.

### What are the top 5 hypervisors, and where does Hypervisor From Scratch fit?

The README does not rank hypervisors or list categories. It only states that Hypervisor From Scratch is the source code of a tutorial series, and it points to HyperDbg for hypervisor-based analysis and reverse engineering work.

## Sources

- [Issues](https://github.com/SinaKarvandi/Hypervisor-From-Scratch/issues)
- [License: MIT](https://github.com/SinaKarvandi/Hypervisor-From-Scratch/blob/master/LICENSE)
- [Project website](https://rayanfam.com/tutorials)
- [README](https://github.com/SinaKarvandi/Hypervisor-From-Scratch/blob/master/README.md)
- [SinaKarvandi/Hypervisor-From-Scratch on GitHub](https://github.com/SinaKarvandi/Hypervisor-From-Scratch)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/sinakarvandi-hypervisor-from-scratch
