Windows Kernel Exploitation
Windows Kernel Exploitation
Couldn't load pickup availability
Instructor: Juan Sacco is a security researcher and exploit developer specialized in reverse engineering, exploit development and Windows kernel exploitation. He is the founder of Exploit Pack. [LinkedIn] · [GitHub]
Windows Kernel Exploitation: is a practical, self-paced training focused on Windows kernel driver exploitation, reverse engineering, and exploit development.
The training focuses on modern Windows 11 environments and introduces the internals, debugging techniques, and exploitation concepts required to abuse of powerful kernel primitives such as physical memory access and MSR read/write.
You will work with WinDbg, Ghidra, Ret-Sync, custom analysis tools, vulnerable drivers, and real-world vendor driver samples.
Throughout the course, these are the actitivies and topics:
- Set up a Windows kernel and debugging environment.
- Build, load, and debug a minimal Windows kernel driver.
- Analyze Windows driver internals, including driver objects, device objects, symbolic links, IRPs, dispatch routines, and IOCTL handlers.
- Reverse engineer 64-bit Windows kernel drivers using Ghidra.
- Use WinDbg to inspect live kernel state, loaded modules, symbols, IRPs, driver objects, and device objects.
- Recover IOCTLs from static and dynamic analysis.
- Analyze vulnerable drivers that expose physical memory primitives.
- Analyze vulnerable drivers that expose WRMSR and RDMSR primitives.
- Understand physical memory, virtual memory, address translation, and why these concepts matter for kernel exploitation.
- Understand modern Windows 11 kernel protections and mitigations.
- Understand how mitigations such as kASLR, NX, SMEP, SMAP, kCFG, kCET, PatchGuard, VBS, and HVCI affect exploitability.
- Identify protection, filtering, and obfuscation techniques used by vendors to hide or restrict driver interfaces.
Participants will receive access to tools and materials used throughout the course, including:
- IOCTL++
- Exploit templates
- Driver analysis scripts
- Ghidra plugins
- WinDbg helpers
- Driver Buddy Revolutions
- Ret-Sync workflow material
- Vulnerable driver samples
- Lab notes and supporting documentation
Schedule and Delivery
Format: Pre-recorded, self-paced training
Structure: 4 modules with video lessons, hands-on exercises, downloadable tools, and supporting materials
Exercises: Practical labs included throughout the course
Access: Learn at your own pace and revisit the material as needed
You should be comfortable with basic systems programming concepts and have some familiarity with debugging or reverse engineering.
Prior kernel exploitation experience is helpful, but not required. The course introduces the required kernel concepts progressively through practical examples and labs.

You may also like..
-
Windows Kernel Exploitation
Regular price From €600 EURRegular priceEURSale price From €600 EUR -
Windows Kernel: Vulnerability Hunting Training
Regular price From €600 EURRegular priceEURSale price From €600 EUR -
Windows Kernel Exploitation Advanced
Regular price From €600 EURRegular priceEURSale price From €600 EUR