kernel exploitation
Exploiting CVE-2025-7771 in the ThrottleStop Driver: Kernel-Exploitation Series
A complete walkthrough of reverse engineering the ThrottleStop driver, understanding its physical memory read/write IOCTL handlers, and building a data-only privilege escalation exploit — from opening the device to spawning a SYSTEM shell.
· 14 min readkernel exploitation
The Kernel Attack Surface: How Windows Internals Enable Exploitation
A subsystem-by-subsystem map of the Windows kernel attack surface — how the syscall interface, I/O manager, memory manager, object manager, and kernel pool each create exploitable primitives, which techniques still work, and which ones died.
· 98 min read