$npx skillfedfor your agent

Windows Kernel Exploits

This skill guides penetration testers through identifying and exploiting Windows kernel vulnerabilities for privilege escalation. It covers automated vulnerability assessment using tools like WES-NG and Watson, then walks through exploitation of named CVEs including PrintNightmare, EternalBlue, and others, with emphasis on reliability and crash risk mitigation.

Windows Kernel Exploits helps testers identify and exploit kernel vulnerabilities for local privilege escalation to SYSTEM.

AI-generated summary based on this skill's SKILL.md

241 34 GPL-3.0updated by blacklanternsecurity

Decision gist · record as of 2026-04-01

Windows Kernel Exploits helps testers identify and exploit kernel vulnerabilities for local privilege escalation to SYSTEM. This skill guides penetration testers through identifying and exploiting Windows kernel vulnerabilities for privilege escalation. It covers automated vulnerability assessment using tools like WES-NG and Watson, then walks through exploitation of named CVEs including PrintNightmare, EternalBlue, and others, with emphasis on reliability and crash risk mitigation.

manual: git clone https://github.com/blacklanternsecurity/red-run → cp -r red-run ~/.claude/skills/windows-kernel-exploits

Use it when

  • Windows Kernel Exploits teaches kernel vulnerability exploitation techniques focused on privilege escalation.
  • Windows Kernel Exploits recommends automated vulnerability assessment tools including WES-NG and Watson.
Same gist for agents: .md · .json

Install

blacklanternsecurity/red-run/windows-kernel-exploits · repository language: Python

generated, unverified - the skill's exact subdirectory could not be determined; check the repository on GitHub

Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.

Frequently asked questions

AI-generated answers based on this skill's SKILL.md and metadata

What does Windows Kernel Exploits cover?

Windows Kernel Exploits guides penetration testers through identifying and exploiting Windows kernel vulnerabilities for privilege escalation. It covers automated vulnerability assessment using tools like WES-NG and Watson, then walks through exploitation of named CVEs including PrintNightmare and EternalBlue, with emphasis on reliability and crash risk mitigation.

What kernel vulnerability exploitation windows techniques are included?

Windows Kernel Exploits teaches kernel vulnerability exploitation techniques focused on privilege escalation. The skill emphasizes practical exploitation of known CVEs, reliability considerations, and crash risk mitigation strategies to help penetration testers successfully escalate privileges through kernel-level attacks.

Which tools does Windows Kernel Exploits recommend for assessment?

Windows Kernel Exploits recommends automated vulnerability assessment tools including WES-NG and Watson. These tools help identify applicable kernel vulnerabilities on target systems before exploitation attempts, streamlining the reconnaissance phase of kernel-level privilege escalation engagements.

How does Windows Kernel Exploits address exploitation reliability?

Windows Kernel Exploits emphasizes reliability and crash risk mitigation throughout its exploitation guidance. The skill provides techniques to reduce system instability when exploiting kernel vulnerabilities, helping penetration testers maintain target system stability during privilege escalation attempts.

What specific CVEs does Windows Kernel Exploits cover?

Windows Kernel Exploits walks through exploitation of named CVEs including PrintNightmare and EternalBlue. These represent key kernel vulnerabilities commonly encountered in penetration testing engagements, with detailed exploitation guidance and proof-of-concept approaches.

Is Windows Kernel Exploits suitable for penetration testing?

Windows Kernel Exploits is designed specifically for penetration testers conducting authorized security assessments. It provides kernel attack vectors, privilege escalation techniques, and exploitation frameworks needed for comprehensive kernel-level testing within authorized engagements.

Let your AI agent find skills like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.

wish › “Learn about Windows kernel vulnerabilities and exploitation techniques”

Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →

Related skills

Windows Token Impersonation
by blacklanternsecurity · blacklanternsecurity/red-run

Windows Token Impersonation helps penetration testers escalate privileges on Windows systems by leveraging dangerous token privileges like SeImpersonate and SeDebug. The skill guides you through obtaining a service account shell, checking for exploitable privileges, and using tools like JuicyPotato, PrintSpoofer, and GodPotato to reach SYSTEM.

GPL-3.0updated Apr 2026
★ 241repo stars
Windows Discovery
by blacklanternsecurity · blacklanternsecurity/red-run

Windows Discovery maps privilege escalation vectors on compromised Windows hosts through systematic enumeration of system configuration, user context, services, and misconfigurations. It gathers baseline OS details, token privileges, and group memberships to identify immediate escalation paths, then reports findings to the orchestrator without crossing into exploitation.

GPL-3.0updated Apr 2026
★ 241repo stars
windows-privilege-escalation
by yaklang · yaklang/hack-skills

This playbook teaches you how to move from low-privilege shell access to SYSTEM or admin on Windows through systematic enumeration and exploitation. It covers token manipulation, Potato family exploits, weak service configurations, DLL hijacking, UAC bypass techniques, scheduled task abuse, and registry autorun abuse—each with specific commands and tool recommendations for different OS versions.

MITupdated Jun 2026
★ 1,480repo stars
windows-boundaries
by hypnguyen1209 · hypnguyen1209/offensive-claude

Windows Boundaries equips you with techniques and tools to cross Windows security boundaries—from kernel/user mode transitions via win32k/dxgkrnl exploits and BYOVD drivers, to UAC elevation, AppContainer/LPAC sandbox escapes, PPL circumvention, and RPC/ALPC-based token impersonation. Includes enumeration scripts, proof-of-concept exploits, and OPSEC guidance for each attack vector.

MITupdated Jul 2026
★ 326repo stars
privesc-windows
by hypnguyen1209 · hypnguyen1209/offensive-claude

privesc-windows guides you through multiple privilege-escalation paths on Windows hosts, from token-impersonation attacks (GodPotato, SigmaPotato, PrintNotifyPotato) and UAC bypass techniques to service/DLL hijacking and kernel exploits. It covers enumeration, exploitation, and credential harvesting with tactical OPSEC guidance and detection evasion for each method.

MITupdated Jul 2026
★ 326repo stars
Av Edr Evasion
by blacklanternsecurity · blacklanternsecurity/red-run

This skill teaches authorized penetration testers how to evade antivirus and EDR systems blocking payload execution. It covers custom DLL and EXE compilation using mingw and Go, AMSI bypass for PowerShell, shellcode alternatives, and ETW patching—all grounded in documented techniques and stopping before C2 setup or persistence.

GPL-3.0updated Apr 2026
★ 241repo stars

More skills Windows Credential Harvesting (GPL-3.0) · windows-mitigations-bypass (MIT) · Pivoting Tunneling (GPL-3.0) · kernel-security (MIT) · recon-port-scan (Apache-2.0) · edr-evasion (MIT)

Tags
privilege-escalationvulnerability-researchkernel-mode-attacksexploit-developmentwindows-securitypenetration-testingcve-exploitationsecurity-tools