Windows Kernel Exploitation: Foundation and Advanced // Ashfaq Ansari

Virtual | March 9-15 | 32 Hours

Lectures on March 9, 10, 11, 12, 13, 14, 15.
Please check the detailed schedule for your time zone.


This comprehensive course combines the essentials of both the Foundation and Advanced Windows Kernel Exploitation courses. It is designed to guide participants through the intricacies of kernel exploitation, from uncovering and exploiting bugs in Windows kernel mode drivers to bypassing advanced exploit mitigations.

Participants will gain hands-on experience in a wide range of topics, including Windows and driver internals, various memory corruption types, exploit development techniques, mitigation bypass techniques, pool internals, and Feng-Shui. The course culminates in a Capture The Flag (CTF) challenge, allowing participants to apply their newly acquired skills.

During this course we will be using Windows 11 X64 for our lab exercise.

This combined course offers a holistic approach to Windows Kernel Exploitation, ensuring participants are well-equipped with the knowledge and skills required to excel in the realm of kernel exploitation.

Windows Kernel Exploitation: Foundation and Advanced // Ashfaq Ansari

Virtual | March 9-15 | 32 Hours



  • Information security professionals
  • Bug hunters and Red teamers
  • Windows exploit developers
  • Windows driver developers and testers
  • Ethical hackers and penetration testers looking to upgrade their skillset to the kernel level
  • Anyone with an interest in understanding Windows Kernel exploitation


"The Windows Kernel Exploitation is an excellent training choice for those who seek a high quality material on exploit development for the Windows kernel. The instructor does amazing job on explaining every topic in detailed manner and always engages with the students. The best part is the CTF which puts your newly acquired knowledge to test which I very much enjoyed."
"This is a great class - Ashfaq Ansari explains things very well and was thorough in providing examples and different ways of verifying things were working as expected through each example. I also appreciated that these sessions were recorded; it made everything more accessible and enjoyable. Thank you!"


Upon completion of this training, participants will be able to:

  • Understand Windows kernel debugging and internals
  • Grasp the basics of Windows and driver internals
  • Identify different memory corruption classes
  • Fuzz kernel mode drivers to find vulnerabilities
  • Dive deep into the exploit development process in kernel mode
  • Bypass advanced exploit mitigations like kASLR, SMEP, and KPTI/KVA Shadow
  • Understand pool internals and Feng-Shui
  • Develop Arbitrary Read/Write primitives



  • Windows Internals (Lecture)
    • Architecture
    • Executive and Kernel
    • Hardware Abstraction Layer (HAL)
    • Privilege Rings
  • Memory Management (Lecture and Hands-on)
    • Virtual Address Space
    • Memory Pool
  • Driver Internals (Lecture and Hands-on)
    • I/O Request Packet (IRP)
    • I/O Control Code (IOCTL)
    • Data Buffering


  • Fuzzing Windows Drivers (Lecture and Hands-on)
    • Attack Surface Analysis (Reversing driver using IDA)
      • Locating IOCTLs in Windows drivers
    • Memory Sanitizers
      • Special Pool
    • Fuzzing the discovered IOCTLs
    • Analyzing the crashes


  • Exploitation Basics (Lecture and Hands-on)
    • Stack Buffer Overflow (SMEP and KVA Shadow/KPTI disabled)
      • Understanding the vulnerability
      • Achieving code execution
    • Escalation of Privilege Payload
    • Kernel State Recovery


  • Advanced Exploit Mitigations
    • Kernel Address Space Layout Randomization (kASLR)
      • Understanding kASLR
      • Breaking kASLR using kernel pointer leaks
    • Supervisor Mode Execution Prevention (SMEP)
      • SMEP concepts
      • Breaking/bypassing SMEP
    • Kernel Page Table Isolation (KPTI/KVA Shadow)
      • KPTI concepts
      • Breaking/bypassing KPTI


  • Advanced Exploitation Techniques (Lecture and Hands-on)
    • Arbitrary Memory Overwrite
      • Understand the vulnerability
      • Achieving privilege escalation
    • Memory Disclosure
      • Understand the vulnerability
      • Leak function pointer
      • Calculate driver base address
    • Pool Overflow
      • Understand the vulnerability
      • Finding corruption target
      • Grooming target pool (Feng-Shui)
      • Achieving arbitrary read/write primitive (data-only attack)
      • Gaining local privilege escalation
      • Different places to corrupt


  • Capture The Flag (CTF)
    • Time to finish the CTF
    • Discuss any other vulnerability class if the students want and time permits


  • Assignment to write a blog post about the vulnerability exploited during CTF
  • Q/A and Feedback

Knowledge Prequisites

  • Basic operating system concepts
  • Familiarity with vulnerability classes
  • Basics of x86/x64 assembly and C/python
  • Basics of ROP
  • Patience

System Requirements

  • A laptop capable of running two virtual machines simultaneously (16 GB+ of RAM). Only x86-64 processors.
  • 40 GB free hard drive space
  • Vmware Workstation/Player installed
  • Everyone should have Administrator privilege on their laptop


Ashfaq Ansari a.k.a HackSysTeam is a vulnerability researcher and specializes in software exploitation. He is the develpper of HackSys Extreme Vulnerable Driver (HEVD) which has helped many upcoming professionals get started with Windows Kernel exploitation. He holds numerous CVEs under his belt and is the instructor of the popular "Windows Kernel Exploitation" course. His core interest lies in low-level software exploitation both in user and kernel mode, vulnerability research, reverse engineering, hybrid fuzzing, and program analysis.

Ringzer0’s Virtual Training Experience & FAQ
What can I expect from a virtual training delivered by Ringzer0, and answers to frequently asked questions.

Virtual Training Schedule

March 9 Sunday Live Lecture (4h)
March 10 Monday Live Lecture (4h)
March 11 Tuesday Live Lecture (4h)
March 12 Wednesday Live Lecture (4h)
March 13 Thursday Live Lecture (4h)
March 14 Friday Live Lecture (4h)
March 15 Saturday Live Lecture (4h)

4h Lecture Timings

8 am - 12 pm US Pacific Time
11 am - 3 pm US Eastern Time
4 pm - 8 pm UK GMT
5 pm - 9 pm Europe CET

Labs and Discord Channel

24 x 7 throughout the class, and beyond!

Cancellation Policy

BOOTSTRAP25: 60+ days before the event 75% of fees refunded; 45-60 days before event 50% refunded, less than 45 days 0% refunded. Course changes are allowed up to 14 days before event start (some restrictions will apply). Attendee changes can be accommodated up to 14 days prior to the event.

Note: In the event of a class cancellation, Ringzer0 will endeavor to offer transfer to another training at no additional charge.
Ringzer0 ★ BOOTSTRAP25
Welcome To BOOTSTRAP25 Thompson Conference Center, Austin TX // March 18-22 BOOK NOW Keep Austin reverse-engineering and learn with Ringzer0! Ringzer0 returns to the Thompson Conference Center, Austin, TX in March 2025 with BOOTSTRAP25, a celebration of South-West Cyber. Our one-day event follows a week of intense reverse engineering. Come for

All BOOTSTRAP25 + Bootloader Mixer Talks and Workshops

Our Sponsors
Great! Next, complete checkout for full access to Ringzer0
Welcome back! You've successfully signed in
You've successfully subscribed to Ringzer0
Success! Your account is fully activated, you now have access to all content
Success! Your billing info has been updated
Your billing was not updated