{"enrichment":{"faq":[{"a":"windows-kernel-security covers the foundational security architecture of the Windows kernel, including critical structures like EPROCESS and ETHREAD that manage process and thread state. The skill explores enforcement mechanisms such as PatchGuard (which detects kernel modifications), Driver Signature Enforcement (DSE) for validating driver authenticity, and Hypervisor-Enforced Code Integrity (HVCI) for runtime protection. Understanding these mechanisms is essential for security researchers studying kernel-level threats and defenses.","q":"What are Windows kernel internals security mechanisms?"},{"a":"windows-kernel-security examines PatchGuard bypass techniques as part of understanding kernel protection mechanisms. PatchGuard is Microsoft's runtime kernel patch protection that detects unauthorized modifications to critical kernel structures. Studying bypass approaches helps security researchers understand both the limitations of kernel defenses and the sophistication required for advanced kernel-mode attacks. This knowledge is critical for assessing kernel security posture and developing more robust protections.","q":"How does PatchGuard bypass relate to kernel security research?"},{"a":"windows-kernel-security teaches driver development fundamentals including callback registration and kernel communication patterns. The skill covers kernel callbacks for process, thread, and image events that allow drivers to intercept and respond to system activities. Understanding these mechanisms is essential for building security tools, anti-cheat systems, and kernel-mode monitoring solutions that interact with the Windows kernel through documented interfaces.","q":"What driver development and callback concepts does this cover?"},{"a":"windows-kernel-security addresses vulnerable driver exploitation, including Bring Your Own Vulnerable Driver (BYOVD) techniques where attackers load legitimate but flawed drivers to gain kernel access. The skill covers how these drivers can be weaponized for privilege escalation and kernel mode read/write primitives. Understanding this attack vector is vital for researchers studying modern privilege escalation chains and kernel-level threats.","q":"What is vulnerable driver exploitation and BYOVD?"},{"a":"windows-kernel-security explores hypervisor-based defense mechanisms including Extended Page Tables (EPT) and Virtualization-Based Security (VBS). These technologies enforce memory protection at the hypervisor level, making kernel tampering significantly harder. The skill covers how EPT-level hooks and hypervisor-enforced protections complement kernel-mode defenses, providing defense-in-depth against sophisticated kernel attacks and rootkits.","q":"How do hypervisor-based defenses like EPT protect kernel memory?"},{"a":"windows-kernel-security covers Windows kernel symbol walking using dbghelp and related tools for resolving kernel structures dynamically. The skill includes pool tag forensics for driver detection and kernel data protection techniques like secure pool allocation. These techniques are essential for security researchers developing detection tools, analyzing kernel memory forensically, and understanding how modern anti-cheat and security systems identify kernel tampering.","q":"What symbol resolution and forensic techniques are included?"}],"shadow_tags":["kernel-internals","driver-development","memory-protection","exploit-research","anti-cheat-evasion","hypervisor-security","boot-time-threats","privilege-escalation","forensic-analysis","virtualization-primitives"],"summary_rewrite":"Explore Windows kernel internals essential for security research, covering critical structures like EPROCESS and ETHREAD, callback systems, and enforcement mechanisms including PatchGuard, Driver Signature Enforcement, and Hypervisor-Enforced Code Integrity. Learn symbol resolution techniques, driver development patterns, and how anti-cheat systems detect kernel tampering."},"files":[{"bytes":39518,"path":".claude/skills/windows-kernel/SKILL.md","sha256":"9a606efe969ee95b807c9aa854cc4554f8db3c674803a52f8aa342f92257db53","url":"https://skillfed.io/files/gmh5225/awesome-game-security/windows-kernel/f47294cc/SKILL.md"}],"id":"gmh5225/awesome-game-security/windows-kernel","links":{"html":"https://skillfed.io/gmh5225/awesome-game-security/windows-kernel","md":"https://skillfed.io/gmh5225/awesome-game-security/windows-kernel.md","repo":"https://github.com/gmh5225/awesome-game-security"},"meta":{"agents_supported":["claude-code"],"first_seen":"2026-07-28","forks":458,"language":"Python","last_updated":"2026-07-28","license":"MIT","name":"windows-kernel-security","publisher":"gmh5225","stars":3261},"relations":{"similar":[{"id":"gmh5225/awesome-game-security/anti-cheat"},{"id":"mohitmishra786/low-level-dev-skills/hypervisor-internals"},{"id":"hypnguyen1209/offensive-claude/edr-evasion"},{"id":"gmh5225/awesome-game-security/game-hacking"},{"id":"gmh5225/awesome-game-security/dma-attack"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"BrownFineSecurity/iothackbot/chipsec"},{"id":"gmh5225/awesome-game-security/reverse-engineering"},{"id":"hypnguyen1209/offensive-claude/keylogger-arch"},{"id":"hypnguyen1209/offensive-claude/windows-boundaries"}]},"slug":{"owner":"gmh5225","repo":"awesome-game-security","skill":"windows-kernel"},"version":"f47294cc"}
