{"enrichment":{"faq":[{"a":"kernel-exploitation teaches core exploitation techniques including use-after-free (UAF), out-of-bounds (OOB) access, and race conditions. You'll learn to build exploitation primitives, execute kernel ROP chains, and achieve privilege escalation through methods like commit_creds and modprobe_path overwrites. The skill emphasizes practical CTF scenarios with QEMU and GDB debugging.","q":"What linux kernel exploitation techniques does kernel-exploitation cover?"},{"a":"kernel-exploitation covers mitigation bypass techniques for SMEP, SMAP, KPTI, and KASLR. You'll learn information leak methods to defeat KASLR, ROP chain construction to bypass SMEP, and kernel-mode attack strategies. The skill provides hands-on approaches to circumvent modern kernel protections in exploitation scenarios.","q":"How does kernel-exploitation help bypass SMEP, SMAP, KPTI, and KASLR?"},{"a":"kernel-exploitation covers building kernel ROP chains and returning cleanly to userspace. You'll learn gadget identification, chain construction for privilege escalation, and ret2usr attack patterns. The skill includes practical examples of chaining syscalls and kernel functions to maintain execution flow while escalating privileges.","q":"What kernel ROP chain gadgets and return techniques are taught?"},{"a":"kernel-exploitation teaches privilege escalation through commit_creds and prepare_kernel_cred function calls. You'll learn to locate these functions, construct ROP chains invoking them, and transition back to userspace with elevated privileges. The skill covers both direct calls and indirect invocation through kernel gadgets.","q":"How can I use kernel-exploitation for privilege escalation via commit_creds?"},{"a":"kernel-exploitation uses QEMU for kernel environment setup and GDB for debugging kernel exploits. You'll learn to configure QEMU with kernel symbols, set breakpoints in kernel code, inspect memory during exploitation, and trace execution flow. These tools are essential for CTF scenarios and vulnerability analysis.","q":"What debugging tools and methods does kernel-exploitation use?"},{"a":"kernel-exploitation includes kernel heap exploitation techniques targeting the SLUB allocator. You'll learn heap layout manipulation, object spraying, and UAF primitives within kernel memory. The skill connects heap vulnerabilities to privilege escalation chains in realistic kernel exploitation workflows.","q":"Does kernel-exploitation cover heap exploitation and SLUB allocator?"}],"shadow_tags":["kernel-mode-attack","privilege-escalation-exploit","memory-safety-bypass","cpu-protection-mitigation","ctf-kernel-pwn","low-level-debugging","kernel-internals","exploit-development","system-security-research"],"summary_rewrite":"Learn to exploit kernel vulnerabilities like use-after-free, out-of-bounds access, and race conditions for privilege escalation. This skill covers environment setup with QEMU, building exploitation primitives, bypassing mitigations like KASLR and SMEP, and executing kernel ROP chains to achieve root access."},"files":[{"bytes":11595,"path":"skills/kernel-exploitation/SKILL.md","sha256":"9f5deef00930f584530634caa62ed87eaf183334bc19783356cefab5c68a0ecb","url":"https://skillfed.io/files/yaklang/hack-skills/kernel-exploitation/7549aac7/SKILL.md"}],"id":"yaklang/hack-skills/kernel-exploitation","links":{"html":"https://skillfed.io/yaklang/hack-skills/kernel-exploitation","md":"https://skillfed.io/yaklang/hack-skills/kernel-exploitation.md","repo":"https://github.com/yaklang/hack-skills"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":196,"language":"CSS","last_updated":"2026-06-16","license":"MIT","name":"kernel-exploitation","publisher":"yaklang","stars":1480},"relations":{"similar":[{"id":"ljagiello/ctf-skills/ctf-pwn"},{"id":"yaklang/hack-skills/arbitrary-write-to-rce"},{"id":"mohitmishra786/low-level-dev-skills/kernel-security"},{"id":"yaklang/hack-skills/stack-overflow-and-rop"},{"id":"mohitmishra786/low-level-dev-skills/branch-prediction-and-speculation"},{"id":"mohitmishra786/low-level-dev-skills/assembly-x86"},{"id":"hypnguyen1209/offensive-claude/exploit-development"},{"id":"hypnguyen1209/offensive-claude/shellcode-dev"},{"id":"mohitmishra786/low-level-dev-skills/os-dev-scratch"},{"id":"mohitmishra786/low-level-dev-skills/hypervisor-internals"}]},"slug":{"owner":"yaklang","repo":"hack-skills","skill":"kernel-exploitation"},"version":"7549aac7"}
