Windows Kernel Security

Analyze Windows driver trust boundaries and kernel evidence for game-security research. Use for IOCTL authorization, callbacks and IRQL, driver provenance, DSE/PatchGuard, VBS/HVCI, build-specific internals, and crash or memory forensics; select repository resources for symbol comparison, ETW metadata, driver-unit coverage and offline dumps. Distinguish documented contracts, observed host state and inferred internals; report privilege prerequisites, mitigation scope, missing coverage and benign alternatives.

gmh5225 297fadc 2 files · 35.8 KB Updated

File contents

gmh5225/awesome-game-security/tree/main/.claude/skills/windows-kernel commit 297fadc083

Frequently asked questions

npx skillmds@latest add gmh5225/windows-kernel-security