Windows Kernel Token Theft Analysis

Analyze and explain Windows kernel privilege escalation via token theft when arbitrary kernel R/W primitives are available. Use this skill when investigating kernel vulnerabilities, reviewing exploit code, understanding EPROCESS token manipulation, or developing defensive controls against token theft attacks. Trigger for any questions about Windows kernel exploitation, EPROCESS structures, token stealing techniques, or kernel vulnerability analysis.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/windows-hardening/windows-local-privilege-escalation/arbitrary-kernel-rw-token-theft commit 7321baa3af

Frequently asked questions

npx skillmds@latest add abelrguezr/windows-kernel-token-theft-analysis