{"enrichment":{"faq":[{"a":"Windows Boundaries provides techniques for exploiting kernel/user mode transitions, including win32k and dxgkrnl vulnerabilities, BYOVD (Bring Your Own Vulnerable Driver) kernel read/write exploits, and direct ring 0 access methods. The skill covers proof-of-concept exploits and enumeration approaches for identifying and leveraging these attack vectors.","q":"What Windows kernel privilege escalation techniques does Windows Boundaries cover?"},{"a":"Windows Boundaries includes UAC bypass methods and RPC/ALPC-based elevation techniques, including SeImpersonate token abuse, COM elevation bypass, and the potato family of exploits. It provides guidance on named pipe impersonation to SYSTEM and token elevation via RPC/ALPC channels.","q":"How can Windows Boundaries help with UAC bypass and token impersonation?"},{"a":"Windows Boundaries covers AppContainer and LPAC (Low Privilege AppContainer) escape vectors, including integrity level bypass methods and security boundary enumeration. The skill provides techniques to identify and exploit weaknesses in sandbox restrictions imposed by Chromium, Edge, and other sandboxed environments.","q":"What sandbox escape techniques are included for AppContainer and LPAC?"},{"a":"Windows Boundaries includes techniques for circumventing Protected Process Light (PPL) restrictions and dumping LSASS with kernel access. It covers kernel-level access methods and provides OPSEC guidance for performing these operations while minimizing detection.","q":"Can Windows Boundaries help bypass PPL and dump LSASS?"},{"a":"Windows Boundaries provides enumeration scripts and host boundary posture assessment tools to identify escape vectors and security gaps. These scripts help map Windows security boundaries and discover potential privilege escalation paths across kernel/user mode, sandbox, and integrity level transitions.","q":"How does Windows Boundaries support security boundary enumeration?"},{"a":"Windows Boundaries includes operational security guidance for each attack vector, covering EDR evasion at the kernel level, driver IOCTL fuzzing techniques, and methods to minimize forensic artifacts. The skill emphasizes safe exploitation practices and detection avoidance across all boundary-crossing techniques.","q":"What OPSEC guidance does Windows Boundaries provide?"}],"shadow_tags":["ring0-access","token-theft","sandbox-breakout","driver-exploitation","edr-bypass","integrity-escalation","ipc-abuse","process-protection","kernel-primitive","boundary-crossing"],"summary_rewrite":"Windows Boundaries equips you with techniques and tools to cross Windows security boundaries\u2014from kernel/user mode transitions via win32k/dxgkrnl exploits and BYOVD drivers, to UAC elevation, AppContainer/LPAC sandbox escapes, PPL circumvention, and RPC/ALPC-based token impersonation. Includes enumeration scripts, proof-of-concept exploits, and OPSEC guidance for each attack vector."},"files":[{"bytes":9092,"path":"skills/windows-boundaries/SKILL.md","sha256":"5f4a145e426b01d453ef1b556aa23874a09174d1660e1c67fc5decafd2aa00cf","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/windows-boundaries/e12cfdc7/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/windows-boundaries","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/windows-boundaries","md":"https://skillfed.io/hypnguyen1209/offensive-claude/windows-boundaries.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"windows-boundaries","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"hypnguyen1209/offensive-claude/privesc-windows"},{"id":"hypnguyen1209/offensive-claude/windows-mitigations"},{"id":"blacklanternsecurity/red-run/windows-kernel-exploits"},{"id":"hypnguyen1209/offensive-claude/threat-hunting"},{"id":"yaklang/hack-skills/windows-privilege-escalation"},{"id":"blacklanternsecurity/red-run/windows-token-impersonation"},{"id":"blacklanternsecurity/red-run/ad-persistence"},{"id":"hypnguyen1209/offensive-claude/edr-evasion"},{"id":"blacklanternsecurity/red-run/windows-discovery"},{"id":"hypnguyen1209/offensive-claude/incident-response"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"windows-boundaries"},"version":"e12cfdc7"}
