Windows Kernel Exploitation β€” Juan Sacco

Join us at hack.lu 2026 β€” Info & Registration

Duration: 90 min

Type: Workshop

Speakers: Juan Sacco

Abstract

Windows Kernel Exploitation Workshop: is a hard-core practical, training focused on advanced Windows kernel exploitation techniques, including post-exploitation techniques, data-only payloads (gadgets), table hijacking of SSDT, Shadow, GDT and IDT, free space memory allocattion and VBS enclaves.

This workshop is meant for enthusiasts, malware developers/analysts, reverse engineers and exploit developers alike.

Description

This is a hard-core hands-on workshop for hackers that already have expert experience in Windows exploits and want to move into advanced kernel exploitation, this training is not for the faint of heart.

Bring a laptop with a fresh Windows 11 VM and WinDBG installed if you want to follow along the excercises.

The training focuses on Windows 11 (fully patched) exploitation scenarios, including IRP Table hijacking, SSDT and Shadow SSDT, IDT and GDT table research, MSR-based techniques, data-only attacks, ZwMapViewOfSection-based exploits (physical memory), suspended-thread execution concepts, and Data-Only Gadget techniques.

Throughout this workshop, you will learn how to:

  • Analyze advanced Windows kernel exploitation primitives.
  • Analyze kernel objects, handle tables, access tokens, process structures, thread structures, and object metadata.
  • Turn kernel read/write access into practical exploit chains.
  • Understand the difference between code-execution payloads and data-only payloads.
  • Windows kernel dispatch paths, including SSDT, Shadow SSDT, MSR-based dispatch, and IRP-related structures.
  • Analyze table hijacking techniques involving IDT, MSR, SSDT, Shadow SSDT, GDT, and driver-specific dispatch structures.
  • Understand why older persistent hooking techniques are fragile on modern Windows and how transient techniques differ. (PatchGuard)
  • Develop exploitation strategies that consider PatchGuard, HVCI, VBS, kCFG, kCET, SMEP, SMAP, and NX in the execution flow.
  • What is Data Only Gadget Technique
  • VBS and HVCI abuse via VBS Enclaves
  • What is Free Writable Memory (Physical access via primitive) and how can be abused

View on pretalx