prerequisites
2) Basic understanding of process Creation (there are if not billions at least millions of operations between double clicking and the appearance of the GUI only a minimal part happens in kernel )
- vmware or any virtual environment as target properly setup with serial or net debugging for kernel debugging
- host with windbg properly installed
- run windbg in host as administrator
--------for example if you have a pipe as serial connection it should look like this

windbg should start and wait for connection like this
Microsoft (R) Windows Debugger Version 10.0.17763.132 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Waiting for pipe \\.\pipe\vmwpipe
Waiting to reconnect...
start your virtual environment and select a debugging configuration screenshot is of serial config

the vm should start and produce an initial breakpoint in windbg
which needs to be acknowledged with g->enter or f5
after this leave a few minutes to completion of login to the vm
hit alt+delete or ctrl+break in windbg to break
and f5 or g->enter to relinquish control to vm several times
now you are ready to check your process creation
as i mentioned in the prerequisites you need to have a generic basic concept of process creation
you should be aware that a double click is handled by the shell (explorer.exe)
and it processes the Double Click and starts the process Creation by Calling CreateProcess()
CreateProcess Used To be a full fledged api in kernel32 earlier now it is a stub forwarding the call to kernelbase.dll which forwards it to ntdll and to its kernel counterpart ntexecutive (ntoskrnl,ntkrnlmp) .
do !process 0 0 explorer.exe tofetch the _EPROCESS of explorer.exe
do .process /p /P /r _EPROCESS fetched earlier
.reload /f explorer.exe
set a process specific breakpoint on the CreateProcess Import in explorer.exe as below and doubleclick calc.exe in your vm to get a break as below
0: kd> bp /p ffff9509`0b03b300 poi(Explorer!_imp_CreateProcessW)
0: kd> g
Breakpoint 4 hit
KERNEL32!CreateProcessWStub:
0033:00007ffb`21dfc020 4c8bdc mov r11,rsp
1: kd> k
# Child-SP RetAddr Call Site
00 00000000`1732e8f8 00007ffb`2103ec10 KERNEL32!CreateProcessWStub
01 00000000`1732e900 00007ffb`20fed0ee windows_storage!CInvokeCreateProcessVerb::CallCreateProcess+0x124
02 00000000`1732ebb0 00007ffb`20f8fde8 windows_storage!CInvokeCreateProcessVerb::_PrepareAndCallCreateProcess+0x1c2
03 00000000`1732ec30 00007ffb`20f8fbc7 windows_storage!CInvokeCreateProcessVerb::_TryCreateProcess+0x84
04 00000000`1732ec60 00007ffb`20f8f82d windows_storage!CInvokeCreateProcessVerb::Launch+0xfb
05 00000000`1732ed00 00007ffb`20feb31d windows_storage!CInvokeCreateProcessVerb::Execute+0x5d
06 00000000`1732ed40 00007ffb`20fe6014 windows_storage!CBindAndInvokeStaticVerb::InitAndCallExecute+0x169
07 00000000`1732edc0 00007ffb`20fe7eea windows_storage!CBindAndInvokeStaticVerb::TryCreateProcessDdeHandler+0x68
08 00000000`1732ee40 00007ffb`20fe459d windows_storage!CBindAndInvokeStaticVerb::Execute+0x1ba
09 00000000`1732f150 00007ffb`20fe4495 windows_storage!RegDataDrivenCommand::_TryInvokeAssociation+0xb5
0a 00000000`1732f1c0 00007ffb`22c7880f windows_storage!RegDataDrivenCommand::_Invoke+0x145
0b 00000000`1732f230 00007ffb`22c786ca SHELL32!CRegistryVerbsContextMenu::_Execute+0xcb
0c 00000000`1732f2a0 00007ffb`22c184e7 SHELL32!CRegistryVerbsContextMenu::InvokeCommand+0xaa
0d 00000000`1732f5a0 00007ffb`22c22549 SHELL32!HDXA_LetHandlerProcessCommandEx+0x117
0e 00000000`1732f6b0 00007ffb`22df9a29 SHELL32!CDefFolderMenu::InvokeCommand+0x139
0f 00000000`1732fa10 00007ffb`230b4409 SHELL32!SHInvokeCommandOnContextMenu2+0x1f5
10 00000000`1732fc50 00007ffb`2244c315 SHELL32!s_DoInvokeVerb+0xc9
11 00000000`1732fcc0 00007ffb`21df81f4 shcore!_WrapperThreadProc+0xf5
12 00000000`1732fda0 00007ffb`2461a251 KERNEL32!BaseThreadInitThunk+0x14
13 00000000`1732fdd0 00000000`00000000 ntdll!RtlUserThreadStart+0x21
you can see the arguments passed using something like this
1: kd> .printf "lpApplicationName = %mu\nlpCommandLine = %mu\nlpProcessAttributes %p\nlpThreadAttributes %p\nbInheritHandles = %x\ndwCreationFlags %x\nlpEnvironment=%p\nlpCurrentDirectory=%mu\nlpStartupInfo=%p\nlpProcessInformation=%p\n" , @rcx,@rdx,@r8,@r9,dwo(@rsp+28),dwo(@rsp+30),dwo(@rsp+38),dwo(@rsp+40),dwo(@rsp+48),dwo(@rsp+50)
lpApplicationName = C:\Windows\System32\calc.exe
lpCommandLine = "C:\Windows\System32\calc.exe"
lpProcessAttributes 0000000000000000
lpThreadAttributes 0000000000000000
bInheritHandles = 0
dwCreationFlags 4080414
lpEnvironment=0000000000000000
lpCurrentDirectory=C:\Windows\System32
lpStartupInfo=0000000012576758
lpProcessInformation=00000000125767f0
this is just the tip of iceberg
as you can see from the call stack the double click was captured and processed by shell32.dll and travelled a lot to reach this point now it has to travel in user mode a lot longer until it reaches the Syscall() in ntdll
the syscall ntdll!ZwCreateProcessEx is the place which transfers control from usermode to kernelmode nt!NtCreateProcessEx which will create the actual Handle create the_PEB ,_TEB Notify Registered Process Creation Callbacks about the new process and return back to explorer for preparation of Gui display