kernel exploitation
Exploiting CVE-2025-62215: A Reference-Count Race in the Object Manager
A deep-dive into CVE-2025-62215 — an actively exploited race in ntoskrnl's Object Manager that double-frees the token's SID Values Block, reclaimed with a same-bucket spray and pivoted into a data-only token flip for SYSTEM.
· 30 min readmalware analysis
Inside the petshub[.]qa ClickFix: From a Fake CAPTCHA to an ACR Stealer Implant
Full teardown of the petshub[.]qa ClickFix campaign: a fake CAPTCHA that drops a blockchain-resolved macOS stealer and a four-stage Windows chain ending in an ACR Stealer implant flagged by 33/69 engines — Realtek masquerade, Heaven's Gate, and CVE-2024-38193 in tow.
· 27 min readkernel exploitation
Exploiting CVE-2026-21241: A Use-After-Free Race in AFD.sys
A deep-dive into CVE-2026-21241 — a use-after-free race in afd.sys's socket notification path, where a notification object is freed across a spinlock release, reclaimed with a named-pipe spray, and pivoted through kCFG-legal RtlSetBit calls into a KDP-evading SeDebugPrivilege flip and SYSTEM.
· 33 min readkernel exploitation
Exploiting CVE-2024-30088: A TOCTOU Race in the Windows Kernel
A deep-dive into CVE-2024-30088 — a TOCTOU race in ntoskrnl's AuthzBasepCopyoutInternalSecurityAttributes, exploited by flipping a user-memory pointer to redirect the kernel's own copy into kernel space, then pivoting the fixed-value write through an I/O Ring into SYSTEM.
· 24 min readkernel exploitation
The Kernel Attack Surface: How Windows Internals Enable Exploitation
A subsystem-by-subsystem map of the Windows kernel attack surface — how the syscall interface, I/O manager, memory manager, object manager, and kernel pool each create exploitable primitives, which techniques still work, and which ones died.
· 98 min readwindows internals
Windows Internals You Need To Know Before Kernel Exploitation
Every defense mechanism between a user-mode process and kernel code execution, explained from first principles — PatchGuard, VBS, HVCI, SMEP, SMAP, CET, KASLR, and the rest.
· 45 min readmalware analysis
Nanga: Process Telemetry from the Syscall Layer
A kernel-driver approach to malware dynamic analysis that captures process telemetry below user-mode evasion, at the syscall layer.
· 15 min read