Windows Kernel Exploitation
Windows Kernel Exploitation Workshop: is a hard-core practical, training focused on advanced Windows kernel exploitation techniques, including post-exploitation techniques, data-only payloads (gadgets), table hijacking of SSDT, Shadow, GDT and IDT, free space memory allocattion and VBS enclaves.
This workshop is meant for enthusiasts, malware developers/analysts, reverse engineers and exploit developers alike.
This is a hard-core hands-on workshop for hackers that already have expert experience in Windows exploits and want to move into advanced kernel exploitation, this training is not for the faint of heart.
Bring a laptop with a fresh Windows 11 VM and WinDBG installed if you want to follow along the excercises.
The training focuses on Windows 11 (fully patched) exploitation scenarios, including IRP Table hijacking, SSDT and Shadow SSDT, IDT and GDT table research, MSR-based techniques, data-only attacks, ZwMapViewOfSection-based exploits (physical memory), suspended-thread execution concepts, and Data-Only Gadget techniques.
Throughout this workshop, you will learn how to:
- Analyze advanced Windows kernel exploitation primitives.
- Analyze kernel objects, handle tables, access tokens, process structures, thread structures, and object metadata.
- Turn kernel read/write access into practical exploit chains.
- Understand the difference between code-execution payloads and data-only payloads.
- Windows kernel dispatch paths, including SSDT, Shadow SSDT, MSR-based dispatch, and IRP-related structures.
- Analyze table hijacking techniques involving IDT, MSR, SSDT, Shadow SSDT, GDT, and driver-specific dispatch structures.
- Understand why older persistent hooking techniques are fragile on modern Windows and how transient techniques differ. (PatchGuard)
- Develop exploitation strategies that consider PatchGuard, HVCI, VBS, kCFG, kCET, SMEP, SMAP, and NX in the execution flow.
- What is Data Only Gadget Technique
- VBS and HVCI abuse via VBS Enclaves
- What is Free Writable Memory (Physical access via primitive) and how can be abused
Exploit Writer, Reverse Engineer, Pentester, Ethical Hacker, OSCP, OSCE, Linux Specialist (15+ years ), worked at Core Security, NOD32, Homeland Security (ArCERT), ING Nederland Red Team, KPN Red Team , RaboBank Red Team, Avast Red Team and others financial and security related organisations.
$whoami:
http://packetstormsecurity.com/search/?q=juan+sacco
https://www.exploit-db.com/?author=6701
Certifications:
- OSCP
- OSCE
- Advanced Corelan Exploit Development
- Advanced IDA Pro by HexRays
Conferences I participated worldwide as speaker:
NoHat - Windows Kernel Exploitation Training
BSides Frankfurt - Subverting the Windows kernel with rootkits and exploits
Black Hat Europe – Exploit Pack
HITB ( Hack in The Box ) - Exploit Writing 64 Bits
Black Hat – Exploit Pack tool
And more..
Publications and CVE’s:
NetPerf Hewllet Packard - Buffer Overflow ROP
Ivanti CVE2019-10885 – Privilege Escalation
Whatsapp 2.18.31 – Remote memory corruption
Kaspersky KSN – Remote RCE
BOCHS 2.6-5 Local Buffer Overflow
WhatsApp 2.17.52 Memory Corruption
Asterisk 13.17.2~dfsg-2 - CVE-2017-17090
MAWK 1.3.3-17 Buffer Overflow
PaloAlto Firewall PAN-57659/95895 - CVE-2016-2219
Microsoft Word MTA Handler Remote Code Execution
Facebook - Bug Bounty
Microsoft - Bug Bounty
Microsoft Windows Server 2008 R2 (x64) - SrvOs2FeaToNt' SMB - CVE-2017-0143
OSX – Xcode-select 2.1.1 Buffer Overflow
EChat Server 2.5 Buffer Overflow
Cisco ASA VPN Remote - CVE-2014-2120
xMatters AlarmPoint APClient 3.2.0 Heap Buffer Overflow
xMatters AlarmPoint Java Web Server API 3.2.1 SQLi
Easy Server 3.1 Buffer Overflow
Mercadolibre Persistent Web Vulnerability
BitchX 1.x IRC Client Buffer Overflow
Blender 2.0x Remote Code Execution
Microsoft Reporting tool Buffer Overflow
CDRipper 2.x Buffer Overflow
IRSSI Client 0.6x Remove Code Execution
VCDGEAR – Buffer overflow
MP3Info – Stack based buffer overflow
Perfectview CRM – Stored XSS and SQLi
Mobile IRON – XSS and SMTP Bypass
and more..