Skip to content
SheldonCybersecurity researcher & developer
  • Profile
  • Work
  • Blogs
  • Pentest Book
  • Contact

Research topics

All articlesreverse engineering 8security research 7kernel exploitation 6windows internals 6privilege escalation 5malware analysis 3kernel pool 3data only attacks 3
All topics
reverse engineering 8security research 7kernel exploitation 6windows internals 6privilege escalation 5malware analysis 3kernel pool 3data only attacks 3race condition 2use after free 2byovd 2ioctl 2ot security 1ics 1air gap 1stuxnet 1triton 1wirelesshart 1cve 2025 62215 1double free 1object manager 1token 1clickfix 1infostealer 1acr stealer 1macos stealer 1windows 1blockchain 1c2 1cve 2026 21241 1afd sys 1pool spray 1kcfg 1cve 2024 30088 1toctou 1virtual memory 1ntoskrnl 1physical memory 1throttlestop 1cve 2025 7771 1race conditions 1syscall hooking 1patchguard 1virtualization based security 1kaslr 1smep 1smap 1code integrity 1cet 1secure boot 1kernel 1dynamic analysis 1ssdt 1rootkit 1
Back to profile

Research / Topic archive

physical memory.

Research, walkthroughs, and field notes on physical memory.

1 article

Allreverse engineeringkernel exploitationwindows internalsmalware analysisphysical memory

kernel exploitation

Exploiting CVE-2025-7771 in the ThrottleStop Driver: Kernel-Exploitation Series

A complete walkthrough of reverse engineering the ThrottleStop driver, understanding its physical memory read/write IOCTL handlers, and building a data-only privilege escalation exploit — from opening the device to spawning a SYSTEM shell.

Aug 12, 2026 · 14 min read

© 2026 Noman Nasir Minhas / Sheldon