Skip to product information
1 of 1

Windows Kernel Exploitation Advanced

Windows Kernel Exploitation Advanced

Regular price €600 EUR
Regular price EUR Sale price €600 EUR
Sale Sold out

Instructor: Juan Sacco is a security researcher and exploit developer specialized in reverse engineering, exploit development and Windows kernel exploitation. He is the founder of Exploit Pack. [LinkedIn] · [GitHub]

Windows Kernel Exploitation Advanced: is a hard-core practical, self-paced training focused on advanced Windows kernel exploitation, including post-exploitation techniques, data-only payloads, table hijacking of SSDT and Shadow, and exploitation strategies designed to bypass modern windows kernel protections.

This is a hard-core hands-on course for students who already have experience with Windows kernel drivers exploitation and want to move into advanced exploit development, this training is not for the faint of heart.

The training focuses on Windows 11 exploitation scenarios, including IRP Table hijacking, SSDT and Shadow SSDT research, MSR-based techniques, data-only attacks, ZwMapViewOfSection-based payloads, suspended-thread execution concepts, and Data-Only Gadget techniques.

Throughout the course, you will learn how to:

  • Analyze advanced Windows kernel exploitation primitives.
  • Turn kernel read/write access into practical exploit chains.
  • Understand the difference between code-execution payloads and data-only payloads.
  • Windows kernel dispatch paths, including SSDT, Shadow SSDT, MSR-based dispatch, and IRP-related structures.
  • Analyze table hijacking techniques involving IDT, MSR, SSDT, Shadow SSDT, GDT, and driver-specific dispatch structures.
  • Understand why older persistent hooking techniques are fragile on modern Windows and how transient techniques differ. (PatchGuard)
  • Develop exploitation strategies that consider PatchGuard, HVCI, VBS, kCFG, kCET, SMEP, SMAP, and NX in the execution flow.
  • Analyze kernel objects, handle tables, access tokens, process structures, thread structures, and object metadata.
  • Use WinDbg to inspect kernel structures, processes, handles, threads, tokens, page tables, and dispatch paths.
  • Use Ghidra and Ret-Sync to connect static analysis with live kernel execution.
  • Understand physical memory, virtual memory, address translation, CR3 walking, and page-table-aware exploitation.
  • MSR read/write primitives and MSR-related information leaks..
  • PA ZwMapViewOfSection-based payloads.
  • SSDT and Shadow SSDT exploit paths to achieve code execution
  • Advanced data-only attacks to abuse trusted kernel logic
  • Advanced Data-Only Gadget concepts to locate, classify, and chain useful kernel data targets at runtime.

Schedule and Delivery

Format: Pre-recorded, self-paced training
Structure: Advanced modules with video lessons, hands-on exercises, downloadable tools, and supporting materials
Exercises: Practical labs included throughout the course
Access: Learn at your own pace and revisit the material as needed

You should already be comfortable with the material covered in the Windows Kernel Exploitation training or have equivalent experience.

    View full details