<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://www.exploitpack.com/blogs/research/windows-kernel-exploits-using-zwmapviewofsection-and-zwunmapviewofsection</loc>
    <lastmod>2026-03-11T13:58:36+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_from_2025-09-15_11-23-14_2740a953-7a05-4a21-9f1b-bb2865fc945c.png?v=1773233916</image:loc>
      <image:title>Windows Kernel Exploits: ZwMapViewOfSection and ZwUnMapViewOfSection</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/windows-kernel-exploits-wrmsr-model-specific-registers</loc>
    <lastmod>2026-03-11T13:58:50+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_from_2025-09-11_18-28-52_087c5ba8-525c-4d17-8552-41d7153f1952.png?v=1773233930</image:loc>
      <image:title>Windows Kernel Exploits: WRMSR (Model Specific Registers)</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/ioctl-tool-for-hunting-windows-kernel-exploits</loc>
    <lastmod>2026-03-11T13:58:41+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_from_2025-09-25_18-47-41_bae0dab2-4ff6-47ad-967f-43085a99b730.png?v=1773233921</image:loc>
      <image:title>IOCTL++ tool for hunting Windows Kernel Exploits</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/subverting-the-windows-kernel-with-exploits-and-rootkits-bsides-frankfurt</loc>
    <lastmod>2025-09-26T19:33:38+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/bsides_8c93ba95-1df4-471f-b3f4-3f5950a04035.jpg?v=1758908018</image:loc>
      <image:title>Subverting the Windows Kernel with exploits and rootkits @BSides Frankfurt</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/windbg-plugin-for-windows-kernel-exploitation</loc>
    <lastmod>2026-03-11T13:58:24+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/1759771820191_67f811b5-7e6c-4298-a9f6-bfb2ef33c0c3.jpg?v=1773233904</image:loc>
      <image:title>WinDBG Plugin for Windows Kernel Exploitation.</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/driver-buddy-revolutions-for-ghidra</loc>
    <lastmod>2026-03-11T13:58:31+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/featured_e32127b8-efa1-4d7d-9075-b355d1f35f7d.png?v=1773233911</image:loc>
      <image:title>Driver Buddy Revolutions for Ghidra</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/driver-buddy-revolutions-for-ida</loc>
    <lastmod>2026-09-01T13:26:04+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/U2ULhwD_21040a60-9cad-4d65-a641-ca027ccd2376.jpg?v=1788261964</image:loc>
      <image:title>Driver Buddy Revolutions for IDA</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/0-day-msr-kernel-exploit-for-windows-11-25h2</loc>
    <lastmod>2026-03-11T13:58:01+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/1762202993547_3971d5a2-7ea2-48c5-9dc5-acfb133dc9df.png?v=1773233881</image:loc>
      <image:title>0-Day MSR Kernel Exploit for Windows 11 25H2</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/juan-sacco-founder-of-exploit-pack-at-nohat-conference-italy</loc>
    <lastmod>2026-09-01T13:30:15+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/NoHat_2025_FrancescoRoncoli__115_1aceec0b-dbe2-4b1e-b1e1-957bd21a3f32.jpg?v=1788262215</image:loc>
      <image:title>Juan Sacco, founder of Exploit Pack at No Hat conference (Italy)</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/unsigned-drivers-loading-on-windows-11-25h2-fully-patched-by-exploiting-kernel-r-w-primitives</loc>
    <lastmod>2026-03-11T13:57:47+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_From_2025-11-24_21-34-14_94ae0658-efe6-4b0e-b6b9-4f5f9b0eebad.png?v=1773233867</image:loc>
      <image:title>Unsigned drivers loading on Windows 11 25H2 (fully patched) by exploiting Kernel R/W primitives</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/video-juan-sacco-founder-of-exploit-pack-at-no-hat-conference-italy</loc>
    <lastmod>2026-09-01T13:29:42+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_2025-12-22_173719_2e1f134a-b9e2-41f9-b3c8-3888f22fc2ae.png?v=1788262182</image:loc>
      <image:title>Exploit Pack at No Hat conference (Italy)</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/wdk-10-0-26100-0-gdt-for-ghidra-12</loc>
    <lastmod>2026-03-11T13:56:31+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_From_2025-12-23_13-55-34_036a0dc5-b2ac-4c78-b6d3-3253dd416292.png?v=1773233791</image:loc>
      <image:title>WDK 10.0.26100.0 GDT for Ghidra 12</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/data-only-attack-via-physical-r-w-and-pa-to-va-translation</loc>
    <lastmod>2026-03-11T13:55:53+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/image-20210831220831378_deb324ff-e468-4b2b-8850-f7f929d6e3f2.png?v=1773233753</image:loc>
      <image:title>Data Only attack via Physical R/W and [CR3 Walker PA to VA translation]</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/data-only-attack-using-superfetch-rdmsr-info-leak</loc>
    <lastmod>2026-03-11T13:56:02+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/1767357121948_7f1dc4d5-9244-408c-8d15-54439f32e3f6.jpg?v=1773233762</image:loc>
      <image:title>Data Only attack using [Superfetch] + RDMSR Info Leak</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/ntoskrnlwalker-interactive-kernel-rop-walker</loc>
    <lastmod>2026-03-11T13:56:10+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/1_a6b9af26-1e01-4a26-85f2-5fc2d768cd4c.jpg?v=1773233770</image:loc>
      <image:title>NTOSKrnlWalker - Interactive Kernel ROP walker</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/control-flow-in-windows-11-25h2-with-vbs-hvci</loc>
    <lastmod>2026-03-11T13:55:46+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/3_6b3ef2af-86a8-4e07-b353-c73972f92a8e.jpg?v=1773233746</image:loc>
      <image:title>Suspended threads in Windows 11 25h2 with VBS/HVCI</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/bypassing-kernel-code-execution-a-data-only-ssdt-hijack-under-hvci-but-how</loc>
    <lastmod>2026-03-11T13:51:15+01:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_From_2026-02-06_18-30-17_247e0d90-047c-469d-810c-234031f6b752.png?v=1773233475</image:loc>
      <image:title>Bypassing Kernel Code Execution: SSDT Hijack Under VBS/HVCI, but how?</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/exploit-pack-featured-in-hvck-magazine</loc>
    <lastmod>2026-09-01T13:27:48+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_2026-02-12_215354_48645e7f-2cc5-4b86-a40c-d1aa80e96a2d.png?v=1788262068</image:loc>
      <image:title>Exploit Pack featured in HVCK Magazine</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/the-watchdog-in-control-pack</loc>
    <lastmod>2026-09-01T13:24:49+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_From_2026-02-24_16-21-25_eaf0792d-e688-42d3-89e4-13c5798d452f.png?v=1788261889</image:loc>
      <image:title>&quot;The Watchdog&quot; in Control Pack</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/data-only-gadgets</loc>
    <lastmod>2026-04-28T11:13:32+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_From_2026-03-24_14-44-07_30548311-e043-425e-a0d3-31c984648350.png?v=1777367612</image:loc>
      <image:title>DOG - Data Only Gadgets</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/blue-hammer-analysis-ms-defender-lpe</loc>
    <lastmod>2026-05-21T16:38:24+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Screenshot_From_2026-04-07_12-20-06_5087c642-7754-43ef-bc00-8c2f6f776983.png?v=1779374304</image:loc>
      <image:title>BlueHammer Analysis (Defender LPE)</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/documentation/sidekick-feature</loc>
    <lastmod>2026-09-01T13:26:26+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/1_2bc72fb2-0af1-48f9-9c6a-b42ee865a536.jpg?v=1788261986</image:loc>
      <image:title>Sidekick Feature</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/shadow-ssdt-hijacking-to-achieve-kernel-code-execution-via-rw-primitives</loc>
    <lastmod>2026-07-19T12:11:17+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/19_confirmwithdisassembly_fce29b5f-2bc8-48eb-b488-f74204fdce73.png?v=1784455877</image:loc>
      <image:title>Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write Primitives</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/winnotify-building-kernel-read-write-from-cr3-based-ioctls</loc>
    <lastmod>2026-06-10T14:19:21+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/1_9e26cc63-ac81-4b0b-809f-31c87ff4c6f4.png?v=1781093961</image:loc>
      <image:title>WinNotify: Building Kernel Read/Write from CR3-Based IOCTLs</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/modern-windows-kernel-exploitation-under-vbs-hvci-juan-sacco-presents-new-research-at-euskalhack-2026</loc>
    <lastmod>2026-09-01T13:31:32+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/54650016-e88b-4931-9bc8-7c5025bf9de2_ea57b8e2-7a82-4543-886f-92dc791bd110.jpg?v=1788262292</image:loc>
      <image:title>EuskalHack 2026 Conference - Subverting the Windows Kernel</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11</loc>
    <lastmod>2026-08-03T11:48:51+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/idt_0214f4de-d769-46ac-a634-31a2b3b5b453.png?v=1785750531</image:loc>
      <image:title>IDT Table Hijacking under VBS/HVCI/kCET in Windows 11</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/cve-2026-13043-panda-arbitrary-kernel-process-memory-read</loc>
    <lastmod>2026-10-05T15:31:32+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/badpanda_6eb64ed8-4f06-447f-aa9b-98f7ce1d205c.png?v=1791207092</image:loc>
      <image:title>CVE-2026-13043 Kernel Memory Access</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/kernel-driver-gates-and-handshakes</loc>
    <lastmod>2026-08-28T20:04:15+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/Unsaved_Image_1_5b6761c9-1a9c-40fb-8168-347e86dee08f.png?v=1787940255</image:loc>
      <image:title>Kernel Driver Gates and Handshakes</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/gdt-table-hijacking-and-fwa</loc>
    <lastmod>2026-08-10T14:01:39+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/gdt_46aecf30-1e2a-4872-91c2-969eaa2cc280.png?v=1786363299</image:loc>
      <image:title>Global Descriptor Table Hijacking in Windows 11</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/abusing-vbs-enclaves-vtl1-data-only-execution-process-sleep-and-edr-blind-spots</loc>
    <lastmod>2026-09-05T19:46:35+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/hollowprocess_23b0a02e-3bd2-48d3-a0a5-bc72a66aae03.png?v=1788630395</image:loc>
      <image:title>Abusing VBS Enclaves: Data-Only Execution and VTL1-Backed Process Hollowing</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/asustek-kernel-driver-asio3-sys-0-day-vulnerability</loc>
    <lastmod>2026-09-09T14:46:42+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/asio3-article-cover_3eb3b39e-a24b-44b9-9b4f-209e0d907089.png?v=1788958002</image:loc>
      <image:title>Asustek Kernel Driver Asio3.sys 0-day vulnerability</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/from-integer-overflow-to-arbitrary-kernel-va-read-write-cve-2026-62735-in-http-sys</loc>
    <lastmod>2026-09-14T23:24:28+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/bigger_10b63395-c708-4c0f-a618-608bb0ecc5de.png?v=1789421068</image:loc>
      <image:title>From Integer Overflow to Arbitrary Kernel VA Read/Write: CVE-2026-62735 in HTTP.sys</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://www.exploitpack.com/blogs/research/subverting-the-windows-kernel-juan-saccos-research-presented-at-brucon-2026</loc>
    <lastmod>2026-09-29T12:44:40+02:00</lastmod>
    <changefreq>weekly</changefreq>
    <image:image>
      <image:loc>https://cdn.shopify.com/s/files/1/0918/4162/6445/articles/BruCon1_06837ff1-92cf-4b83-bb12-8bb56add78d9.png?v=1790678680</image:loc>
      <image:title>Subverting the Windows Kernel: Juan Sacco&apos;s Research Presented at BruCON 2026</image:title>
    </image:image>
  </url>
</urlset>
