Skip to product information
1 of 1

Windows Kernel Exploitation Handbook

Windows Kernel Exploitation Handbook

Regular price €99 EUR
Regular price EUR Sale price €99 EUR
Sale Sold out

This handbook is a practical introduction to Windows kernel internals, reverse engineering, and modern Windows kernel exploitation concepts.

It has been written by Juan Sacco, author of the Windows Kernel Exploitation training and expert in Kernel Internals, for security researchers, exploit developers, reverse engineers, and students who want a structured reference while learning Windows kernel exploitation.

Unlike our video trainings, this handbook focuses on explaining the concepts, terminology, and architecture behind modern Windows kernel exploitation. It can be used as a companion while studying, building a lab environment, or following the Exploit Pack training material.

Throughout the handbook, you will explore topics such as:

  • Windows kernel architecture
  • PE format and Windows internals
  • Kernel drivers and driver objects
  • Device Objects, IRPs and IOCTLs
  • Physical and virtual memory
  • Address translation
  • WinDbg basics
  • Driver reversing with Ghidra
  • Modern Windows exploit mitigations
  • SMEP, SMAP, kASLR, PatchGuard, VBS, HVCI, kCFG and kCET
  • Kernel exploitation fundamentals
  • Vulnerability classes commonly found in Windows drivers

The handbook includes diagrams, explanations, practical examples, and references intended to make complex kernel concepts easier to understand.

This is a written reference designed to complement practical training. It does not include the complete laboratory exercises, downloadable tools, debugging sessions, or hands-on exploit development projects available in our Windows Kernel Exploitation trainings.

  • Format: Digital PDF handbook including high-resolution diagrams and illustrations
View full details