0xcyberpj/windows-exploitation
GitHub: 0xcyberpj/windows-exploitation
一个系统化整理 Windows 内核漏洞利用与安全研究学习资源的分类合集,涵盖演讲视频、论文和漏洞分析文章。
Stars: 14 | Forks: 7
## 高级 Windows 漏洞开发资源
一些主要与 Windows Internals 以及任何与 Windows 内核相关的资源、链接、书籍和论文。主要是我很喜欢看的演讲和视频。
## 非常重要的资源
- [terminus 项目](http://terminus.rewolf.pl/terminus/)
- [React OS Win32k](https://reactos.org/wiki/Techwiki:Win32k)
- [Geoff Chappell - 内核模式 Windows](https://www.geoffchappell.com/studies/windows/km/index.htm)
- [HEVD 漏洞驱动程序](https://github.com/hacksysteam/HackSysExtremeVulnerableDriver)
- [FLARE 内核 Shellcode 加载器](https://github.com/fireeye/flare-kscldr)
- [Vergilius - 未公开的内核结构](https://www.vergiliusproject.com/)
- [Windows X86-64 系统调用表](https://j00ru.vexillium.org/syscalls/nt/64/)
- [漏洞驱动程序汇总帖](https://www.unknowncheats.me/forum/anti-cheat-bypass/334557-vulnerable-driver-megathread.html)
## 必看 / 必读(如果你只能选几个)- 最爱列表
- [ ⭐ 内核模式威胁与实际防御](https://www.youtube.com/watch?v=BBJgKuXzfwc)
- [ ⭐ Morten Schenk - 将 Windows 10 内核漏洞利用提升到新高度](https://youtu.be/33Jr1wkaCmQ)
- [ ⭐ 内核对象滥用的生命与终结](https://youtu.be/_u7d9kLdi0c)
- [ ⭐ Windows 10 缓解机制改进](https://youtu.be/gCu2GQd0GSE)
## Windows Rootkit
**演讲 / 视频录像**
- [11 部分系列播放列表 - Rootkit:它们是什么,以及如何发现它们](https://www.youtube.com/watch?v=ewNo_poX7bA&list=PLF58FB7BCB20ED11A)
- [Hooking Nirvana](https://www.youtube.com/watch?v=pHyWyH804xE)
- [Alex Ionescu - 推进 UEFI Bootkit 的发展](https://www.youtube.com/watch?v=dpG97TBR3Ys)
- [BlueHat v18 || 内核 Rootkit 恶意软件的回归(在 Windows 10 上)](https://youtu.be/qVIxFfXpyNc)
- [Numchecker:一种用于内核 Rootkit 检测的系统方法](https://www.youtube.com/watch?v=TgMsMwsfoQ0)
- [DEF CON 26 - Ring 0 Ring 2 Rootkit 绕过防御](https://www.youtube.com/watch?v=7AEMxaZhdLU)
- [Black Hat Windows 2001 - 内核模式 Rootkit](https://www.youtube.com/watch?v=99Znv6tgYS0)
- [Black Hat Windows 2004 - DKOM(直接内核对象操作)](https://www.youtube.com/watch?v=1Ie20b5IGgY)
- [RTFM SigSegv1 - 从损坏的内存转储到 Rootkit 检测](https://www.youtube.com/watch?v=hlhM_q3ZHfQ)
**文章 / 论文**
- [使用动态分析剖析 Turla Rootkit 恶意软件](https://www.lastline.com/labsblog/dissecting-turla-rootkit-malware-using-dynamic-analysis/)
- [深入了解驱动程序签名强制执行](https://j00ru.vexillium.org/2010/06/insight-into-the-driver-signature-enforcement/)
- [DERUSB 的 WINDOWS 驱动程序签名绕过](http://www.sekoia.fr/blog/windows-driver-signing-bypass-by-derusbi/)
- [一个基础的 Windows DKOM Rootkit](https://blog.landhb.dev/posts/v9eRa/a-basic-windows-dkom-rootkit-pt-1/)
- [操纵 ActiveProcessLinks 在用户态隐藏进程](https://ired.team/miscellaneous-reversing-forensics/windows-kernel/manipulating-activeprocesslinks-to-unlink-processes-in-userland)
## Windows 内核缓解机制
**演讲 / 视频录像**
- [BlueHat v18 || 通过攻击性安全研究强化 Hyper-V](https://www.youtube.com/watch?v=8RCH0vFxWT4)
- [全面绕过控制流保护 - 这是 CFG 而不是 kCFG](https://www.blackhat.com/docs/us-15/materials/us-15-Zhang-Bypass-Control-Flow-Guard-Comprehensively-wp.pdf)
- [BlueHat v18 || 缓解机制绕过:过去、现在与未来](https://www.youtube.com/watch?v=WsoFmN3oDw8)
- [Windows Offender 逆向工程 Windows Defender 的防病毒模拟器](https://www.youtube.com/watch?v=LvW68czaEGs)
- [Windows 10 缓解机制改进(非常棒的演讲)](https://www.youtube.com/watch?v=gCu2GQd0GSE)
- [Windows 10 对 TPM、HVCI 和 SecureBoot 要求概述](https://www.youtube.com/watch?v=v149T7p4XLA)
- [剖析 Windows 10 安全的守护者 - Chuanda Ding](https://www.youtube.com/watch?v=a0AB76YNMlQ)
- [Windows 10 基于虚拟化的安全攻击面分析](https://www.youtube.com/watch?v=_646Gmr_uo0)
- [深入探讨 Hyper-V 架构与漏洞](https://www.youtube.com/watch?v=2bK_rC81_Eo)
- [最后一次 kaslr 泄露](https://www.youtube.com/watch?v=PTnuwchEci0)
- [BlueHat v18 || 针对内核 TOCTOU 漏洞的缓解措施](https://www.youtube.com/watch?v=YGkhK55jitE)
- [REcon 2013 - 我有 99 个问题,但内核指针不是其中之一 ](https://www.youtube.com/watch?v=5HbmpPBKVFg)
- [SMEP:它是什么,以及如何在 Windows 上击败它](https://j00ru.vexillium.org/2011/06/smep-what-is-it-and-how-to-beat-it-on-windows/)
- [BlueHat IL 2020 - David Weston - 保障 Windows 安全](https://www.youtube.com/watch?v=NlfZG2wTPZU)
- [提升 Windows 安全性 — David Weston](https://www.youtube.com/watch?v=FJnGA4XRaq4)
- [OffensiveCon18 - CFI 攻击与防御的演变](https://www.youtube.com/watch?v=oOqpl-2rMTw)
**文章 / 论文**
**通用缓解机制论文**
- [使用 0day 漏洞缓解机制强化 Windows 10](https://www.microsoft.com/security/blog/2017/01/13/hardening-windows-10-with-zero-day-exploit-mitigations/)
- [将 Windows 10 内核漏洞利用提升到新高度](https://www.blackhat.com/docs/us-17/wednesday/us-17-Schenk-Taking-Windows-10-Kernel-Exploitation-To-The-Next-Level%E2%80%93Leveraging-Write-What-Where-Vulnerabilities-In-Creators-Update-wp.pdf)
**kASLR**
- [Windows 8.1 中的 KASLR 绕过缓解机制](https://www.crowdstrike.com/blog/kaslr-bypass-mitigations-windows-81/)
- [开发一种新的 Windows 10 KASLR 绕过 - 仅用一条 WinDBG 命令](https://www.offensive-security.com/vulndev/development-of-a-new-windows-10-kaslr-bypass-in-one-windbg-command/)
**SMEP**
- [在 64 位 Windows 8 上使用面向返回的编程绕过 Intel SMEP](http://blog.ptsecurity.com/2012/09/bypassing-intel-smep-on-windows-8-x64.html)
- [面向返回的编程教程](https://rstforums.com/forum/topic/106553-rop-for-smep-bypass/)
- [栈缓冲区溢出(SMEP 绕过)](https://www.abatchy.com/2018/01/kernel-exploitation-4)
- [Windows 10 x64 与绕过 SMEP](https://connormcgarr.github.io/x64-Kernel-Shellcode-Revisited-and-SMEP-Bypass/)
- [SMEP:它是什么,以及如何在 Windows 上击败它](https://j00ru.vexillium.org/2011/06/smep-what-is-it-and-how-to-beat-it-on-windows/)
**CET**
- [用于执行控制流完整性的处理器指令集架构安全分析](https://dl.acm.org/doi/pdf/10.1145/3337167.3337175)
- [Intel 控制流强制执行技术深入解析](https://software.intel.com/content/www/us/en/develop/articles/technical-look-control-flow-enforcement-technology.html)
- [控制流强制执行技术规范](https://software.intel.com/sites/default/files/managed/4d/2a/control-flow-enforcement-technology-preview.pdf)
- [Intel CET 响应号召防范常见恶意软件威胁](https://newsroom.intel.com/editorials/intel-cet-answers-call-protect-common-malware-threats/)
- [R.I.P ROP:Windows 20H1 中的 CET 内部机制](https://windows-internals.com/cet-on-windows/)
## Windows 内核 Shellcode
**文章 / 论文**
- [加载内核 Shellcode](https://www.fireeye.com/blog/threat-research/2018/04/loading-kernel-shellcode.html)
- [Windows 内核 Shellcode - 概览](https://www.matteomalvica.com/blog/2019/07/06/windows-kernel-shellcode/)
- [Windows 10 上的 Windows 内核 Shellcode – 第 1 部分](https://improsec.com/tech-blog/windows-kernel-shellcode-on-windows-10-part-1)
- [Windows 10 上的 Windows 内核 Shellcode – 第 2 部分](https://improsec.com/tech-blog/windows-kernel-shellcode-on-windows-10-part-2)
- [Windows 10 上的 Windows 内核 Shellcode – 第 3 部分](https://improsec.com/tech-blog/windows-kernel-shellcode-on-windows-10-part-3)
- [Kernel 惊魂记 - 重温 64 位 Windows 10 上的 Token 窃取 Payload 与绕过 SMEP](https://connormcgarr.github.io/x64-Kernel-Shellcode-Revisited-and-SMEP-Bypass/)
- [内核中用于权限提升的 Token 滥用](https://ired.team/miscellaneous-reversing-forensics/windows-kernel/how-kernel-exploits-abuse-tokens-for-privilege-escalation)
- [Shellcode 开发简介](https://owasp.org/www-pdf-archive/Introduction_to_shellcode_development.pdf)
- [Windows Shellcode 开发简介 – 第 1 部分](https://securitycafe.ro/2015/10/30/introduction-to-windows-shellcode-development-part1/)
- [DoublePulsar 初始 SMB 后门 Ring 0 Shellcode 分析](https://zerosum0x0.blogspot.com/2017/04/doublepulsar-initial-smb-backdoor-ring.html)
- [探索注入线程](https://ired.team/miscellaneous-reversing-forensics/get-injectedthread#injecting-shellcode)
## Windows 内核漏洞利用
**演讲 / 视频录像**
- [HITB2016AMS - 内核漏洞挖掘与缓解机制](https://www.youtube.com/watch?v=nvI6w8aW-4Q)
- [Ilja van Sprundel:Windows 驱动程序攻击面](https://www.youtube.com/watch?v=qk-OI8Z-1To)
- [REcon 2015 - 这次 Font 在 4 字节内猎杀你](https://www.youtube.com/watch?v=uvy5BF1Nlio)
- [利用 Windows 10 PagedPool 差一溢出(WCTF 2018)](https://j00ru.vexillium.org/2018/07/exploiting-a-windows-10-pagedpool-off-by-one/)
- [Windows 内核漏洞利用技术 - Adrien Garin - LSE Week 2016](https://www.youtube.com/watch?v=f8hTwFpRphU)
- [Hackingz Ze Komputerz - 利用 CAPCOM.SYS - 第 1 部分](https://www.youtube.com/watch?v=pJZjWXxUEl4)
- [Hackingz Ze Komputerz - 利用 CAPCOM.SYS - 第 2 部分](https://www.youtube.com/watch?v=UGWqq5kTiso)
- [3 Way06 实用 Windows 内核漏洞利用](https://www.youtube.com/watch?v=hUCmV7uT29I)
- [KMDF 驱动程序的逆向工程与 Bug 挖掘](https://www.youtube.com/watch?v=puNkbSTQtXY)
- [二进制漏洞缓解与绕过历史 - 不仅仅是内核 ](https://vimeo.com/379935124)
- [Morten Schenk - 将 Windows 10 内核漏洞利用提升到新高度](https://www.youtube.com/watch?v=Gu_5kkErQ6Y)
- [REcon 2015 - 逆向工程 Windows AFD.sys](https://www.youtube.com/watch?v=2sPNUpfTJ5A)
- [Windows 内核图形驱动程序攻击面](https://www.youtube.com/watch?v=uzPTyXQ1Oys)
- [理解 Windows 内核字体缩放引擎中的 TOCTTOU](https://www.youtube.com/watch?v=61K3kqTRbzU)
- [Black Hat USA 2013 - 粉碎 Windows 内核中的字体缩放引擎](https://www.youtube.com/watch?v=efgoislKd8Q)
**文章 / 论文**
- [内核漏洞利用样本挖掘与内容提取](https://d3gpjj9d20n0p3.cloudfront.net/fortiguard/research/Kernel%20Exploit%20Hunting%20and%20Mitigation-WP.pdf)
- [整个 GreyHatHacker 网站都有很棒的分析文章](https://www.greyhathacker.net/)
- [BlueKeep:从 DoS 到 RCE 的旅程(CVE-2019-0708)](https://www.malwaretech.com/2019/09/bluekeep-a-journey-from-dos-to-rce-cve-2019-0708.html)
- [利用 SMBGhost (CVE-2020-0796) 进行本地权限提升](https://blog.zecops.com/vulnerabilities/exploiting-smbghost-cve-2020-0796-for-a-local-privilege-escalation-writeup-and-poc/)
- [Windows 驱动程序真的是极其棘手](https://googleprojectzero.blogspot.com/2015/10/windows-drivers-are-truely-tricky.html)
- [剖析与 ESET 联合挖掘中发现的双重 0day 样本](https://www.microsoft.com/security/blog/2018/07/02/taking-apart-a-double-zero-day-sample-discovered-in-joint-hunt-with-eset/)
- [池中之鲨 :: Windows 内核池中的混合对象漏洞利用](https://srcincite.io/blog/2017/09/06/sharks-in-the-pool-mixed-object-exploitation-in-the-windows-kernel-pool.html)
- [现实世界中的内核池溢出漏洞利用:Windows 10](https://www.gatewatcher.com/en/news/blog/kernel-pool-overflow-exploitation-in-real-world-windows-10)
- [现实世界中的内核池溢出漏洞利用 - Windows 7](https://www.gatewatcher.com/en/news/blog/kernel-pool-overflow-exploitation-in-real-world-windows-7)
- [Windows 7 上的内核池漏洞利用](https://www.exploit-db.com/docs/english/16032-kernel-pool-exploitation-on-windows-7.pdf)
- [简单的本地 Windows 内核漏洞利用](https://media.blackhat.com/bh-us-12/Briefings/Cerrudo/BH_US_12_Cerrudo_Windows_Kernel_WP.pdf)
- [利用 CVE-2014-4113](https://labs.f-secure.com/assets/BlogFiles/mwri-lab-exploiting-cve-2014-4113.pdf)
- [Pwn2Own 2014 - AFD.sys 悬垂指针漏洞](https://www.siberas.de/papers/Pwn2Own_2014_AFD.sys_privilege_escalation.pdf)
- [Symantec Endpoint Protection 0day](https://www.offensive-security.com/vulndev/symantec-endpoint-protection-0day/)
- [分析最新 Windows 10 v1607 Build 14393 中的 NULL SecurityDescriptor 内核漏洞利用缓解机制](https://labs.nettitude.com/blog/analysing-the-null-securitydescriptor-kernel-exploitation-mitigation-in-the-latest-windows-10-v1607-build-14393/)
- [nt!_SEP_TOKEN_PRIVILEGES - 单次写入权限提升保护](https://www.exploit-db.com/docs/english/41924-nt!_sep_token_privileges---single-write-eop-protect.pdf)
- [内核中用于权限提升的 Token 滥用](https://ired.team/miscellaneous-reversing-forensics/windows-kernel/how-kernel-exploits-abuse-tokens-for-privilege-escalation)
## Windows 内核 GDI 漏洞利用
**演讲 / 视频录像**
- [滥用 GDI 实现 Ring0 漏洞利用原语的演变](https://www.youtube.com/watch?v=ruuVkTuNUSc)
- [通过滥用 GDI 对象揭秘 Windows 内核漏洞利用](https://www.youtube.com/watch?v=2chDv_wTymc)
- [CommSec D1 - 内核对象滥用的生命与终结](https://www.youtube.com/watch?v=_u7d9kLdi0c)
- [通过类型隔离进行内核对象滥用](https://www.youtube.com/watch?v=kOV-Y9HcJWM)
**文章 / 论文**
- [使用 PALETTE 对象将 CVE-2017-14961 转变为完全的任意读/写](https://web.archive.org/web/20191220090640/http://theevilbit.blogspot.com/2017/11/turning-cve-2017-14961-ikarus-antivirus.html)
- [用于定向攻击的 0day 漏洞利用 (CVE-2018-8453)](https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/)
- [Operation WizardOpium 的 0day 漏洞利用](https://securelist.com/the-zero-day-exploits-of-operation-wizardopium/97086/)
- [在 Operation WizardOpium 中使用的 Windows 0day 漏洞利用 CVE-2019-1458](https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/)
- [滥用 GDI 对象引发 Ring0 原语革命](https://sensepost.com/blog/2017/abusing-gdi-objects-for-ring0-primitives-revolution/)
- [https://www.coresecurity.com/core-labs/articles/abusing-gdi-for-ring0-exploit-primitives](https://www.coresecurity.com/core-labs/articles/abusing-gdi-for-ring0-exploit-primitives)
- [位图传说:Windows 10 周年更新版后泄露 GDI 对象](https://labs.f-secure.com/archive/a-tale-of-bitmaps/)
- [CSW2017 彭秋 设防中 win32k dark_composition](https://www.slideshare.net/CanSecWest/csw2017-peng-qiushefangzhong-win32k-darkcompositionfinnalfinnalrmmark)
- [内核漏洞利用 -> GDI 位图滥用(Win7-10 32/64位)](https://www.fuzzysecurity.com/tutorials/expDev/21.html)
## Windows 内核 Win32k.sys 研究
**演讲 / 视频录像**
- [BlackHat 2011 - 通过用户态回调进行内核攻击](https://www.youtube.com/watch?v=EkGDSqpfzgg)
**文章 / 论文**
- [CVE-2020-1054 分析](https://0xeb-bp.github.io/blog/2020/06/15/cve-2020-1054-analysis.html)
- [当你因为补丁比对出一个在野使用的 0day 而极其兴奋,随后却发现它并非目标漏洞时](https://googleprojectzero.blogspot.com/2020/04/tfw-you-get-really-excited-you-patch.html)
- [一位统治系统:分析在野利用的 CVE-2016-7255 漏洞](https://blog.trendmicro.com/trendlabs-security-intelligence/one-bit-rule-system-analyzing-cve-2016-7255-exploit-wild/)
- [逆向工程 Win32k 类型隔离缓解机制](https://blog.quarkslab.com/reverse-engineering-the-win32k-type-isolation-mitigation.html)
- [0day 漏洞 CVE-2018-8589 的新利用方式](https://securelist.com/a-new-exploit-for-zero-day-vulnerability-cve-2018-8589/88845/)
- [检测与缓解针对 CVE-2017-0005 的权限提升漏洞利用](https://www.microsoft.com/security/blog/2017/03/27/detecting-and-mitigating-elevation-of-privilege-exploit-for-cve-2017-0005/)
- [探索 CVE-2015-1701 — 一次用于定向攻击的 Win32k 权限提升漏洞
](https://blog.trendmicro.com/trendlabs-security-intelligence/exploring-cve-2015-1701-a-win32k-elevation-of-privilege-vulnerability-used-in-targeted-attacks/)
- [利用 win32k!xxxEnableWndSBArrows 释放后重用漏洞https://www.nccgroup.trust/globalassets/our-research/uk/blog-post/2015-07-07_-_exploiting_cve_2015_0057.pdf)
- [win32k.sys 中的新 0day 漏洞 CVE-2019-0859](https://securelist.com/new-win32k-zero-day-cve-2019-0859/90435/)
- [在定向攻击中被利用的 Windows 0day CVE-2019-1132](https://www.welivesecurity.com/2019/07/10/windows-zero-day-cve-2019-1132-exploit/)
- [Windows 内核本地拒绝服务 #1:win32k!NtUserThunkedMenuItemInfo](https://j00ru.vexillium.org/2017/02/windows-kernel-local-denial-of-service-1/)
- [Windows 内核本地拒绝服务 #2:win32k!NtCompositionBeginFrame](https://j00ru.vexillium.org/2017/02/windows-kernel-local-denial-of-service-2/)
- [Windows 内核本地拒绝服务 #4:nt!NtAccessCheck 及其家族](https://j00ru.vexillium.org/2017/04/windows-kernel-local-denial-of-service-4/)
- [Windows 内核本地拒绝服务 #5:win32k!NtGdiGetDIBitsInternal](https://j00ru.vexillium.org/2017/04/windows-kernel-local-denial-of-service-5/)
- [Windows win32k.sys 菜单与一些“接近成功,但还差一点”的 Bug](https://j00ru.vexillium.org/2013/09/windows-win32k-sys-menus-and-some-close-but-no-cigar-bugs/)
- [Windows 内核 Internals - Win32K.sys](http://pasotech.altervista.org/windows_internals/Win32KSYS.pdf)
## Windows 内核逻辑漏洞
**演讲 / 视频录像**
- [如果你不会开车就别碰内核 - DEF CON 27 大会](https://www.youtube.com/watch?v=tzWq5iUiKKg)
**文章 / 论文**
- [一个漏洞驱动程序:差点吸取的教训](https://securelist.com/elevation-of-privileges-in-namco-driver/83707/)
- [CVE-2020-12138 - ATI Technologies Inc. 驱动程序 atillk64.sys 中的权限提升](https://h0mbre.github.io/atillk64_exploit/)
- [CVE-2019-18845 - Viper RGB 驱动程序本地权限提升](https://www.activecyber.us/activelabs/viper-rgb-driver-local-privilege-escalation-cve-2019-18845)
- [CVE-2020-8808 - CORSAIR iCUE 驱动程序本地权限提升](https://www.activecyber.us/activelabs/corsair-icue-driver-local-privilege-escalation-cve-2020-8808)
- [Razer rzpnk.sys 中的逻辑漏洞](https://www.fuzzysecurity.com/tutorials/expDev/23.html)
- [Dell SupportAssist 驱动程序 - 本地权限提升](http://dronesec.pw/blog/2018/05/17/dell-supportassist-local-privilege-escalation/)
- [MSI ntiolib.sys/winio.sys 本地权限提升](http://blog.rewolf.pl/blog/?p=1630)
- [CVE-2019-8372 - LG 内核驱动程序中的本地权限提升](http://www.jackson-t.ca/lg-driver-lpe.html)
- [使用 Carbon Black 的 Endpoint 驱动程序读取物理内存](https://billdemirkapi.me/Reading-Physical-Memory-using-Carbon-Black/)
- [ASUS UEFI 更新驱动程序物理内存读/写](https://codeinsecurity.wordpress.com/2016/06/12/asus-uefi-update-driver-physical-memory-readwrite/)
- [在 40 多个 Windows 驱动程序中发现权限提升漏洞](https://mspoweruser.com/privilege-escalation-vulnerabilities-found-in-over-40-windows-drivers/)
- [Blackat - 内核模式威胁与实际防御](https://i.blackhat.com/us-18/Thu-August-9/us-18-Desimone-Kernel-Mode-Threats-and-Practical-Defenses.pdf)
- [将漏洞驱动武器化以进行权限提升— 技嘉版!](https://medium.com/@fsx30/weaponizing-vulnerable-driver-for-privilege-escalation-gigabyte-edition-e73ee523598b)
## Windows 内核驱动程序开发
**演讲 / 视频录像**
- [Windows 内核编程 - 14 部分系列播放列表](https://youtu.be/XUlbYRFFYf0)
- [Windows 驱动程序开发 - 19 部分系列播放列表](https://youtu.be/T5VtaP-wtkk)
- [使用现代 C++ 开发内核驱动程序 - Pavel Yosifovich](https://www.youtube.com/watch?v=AsSMKL5vaXw)
**文章 / 论文**
- [Winsock 内核概述主题](https://docs.microsoft.com/en-us/windows-hardware/drivers/network/introduction-to-winsock-kernel)
- [驱动程序开发第 1 部分:驱动程序简介](https://www.codeproject.com/Articles/9504/Driver-Development-Part-1-Introduction-to-Drivers)
- [驱动程序开发第 2 部分:实现 IOCTL 简介](https://www.codeproject.com/Articles/9575/Driver-Development-Part-2-Introduction-to-Implemen)
- [驱动程序开发第 3 部分:驱动程序上下文简介](https://www.codeproject.com/Articles/9636/Driver-Development-Part-3-Introduction-to-driver-c)
- [驱动程序开发第 4 部分:设备堆栈简介](https://www.codeproject.com/Articles/9766/Driver-Development-Part-4-Introduction-to-device-s)
- [在驱动程序中创建 IOCTL 请求](https://docs.microsoft.com/en-us/windows-hardware/drivers/kernel/creating-ioctl-requests-in-drivers)
- [Windows 驱动程序第 2 部分:IOCTL](https://cylus.org/windows-drivers-part-2-ioctls-c678526f90ae)
- [使用 IOCTL 从你的用户态程序向内核驱动程序发送命令](https://ired.team/miscellaneous-reversing-forensics/windows-kernel/sending-commands-from-userland-to-your-kernel-driver-using-ioctl)
## Windows Internals
**演讲 / 视频录像**
- [Pluralsight - Windows Internals 1](https://www.pluralsight.com/courses/windows-internals)
- [Pluralsight - Windows Internals 2](https://www.pluralsight.com/courses/windows-internals2)
- [Pluralsight - Windows Internals 3](https://www.pluralsight.com/courses/windows-internals-3)
- [Pluralsight - Windows 10 Internals:系统与进程](https://www.pluralsight.com/courses/windows-10-internals-threads-memory-security)
- [Pluralsight - Windows 10 Internals - 线程、内存与安全](https://www.pluralsight.com/courses/windows-10-internals-system-processes)
- [Alex Ionescu Insection:极其惊人地(AWEsomely)利用共享内存对象](https://vimeo.com/133292423)
- [Windows Internals](https://www.youtube.com/watch?v=vz15OqiYYXo)
- [Windows 10 Segment Heap Internals](https://www.youtube.com/watch?v=hetZx78SQ_A)
- [Windows 内核漏洞研究与利用 - Gilad Bakas](https://www.youtube.com/watch?v=aRZ5Wi-NWXs)
- [NIC 五周年 - Windows 10 internals](https://youtu.be/ffYiIUOUAUs)
- [Black Hat USA 2012 - Windows 8 Heap Intervals](https://www.youtube.com/watch?v=XxlzK0CLFN0)
**文章 / 论文**
- [白皮书 - WINDOWS 10 SEGMENT HEAP INTERNALS](https://www.blackhat.com/docs/us-16/materials/us-16-Yason-Windows-10-Segment-Heap-Internals-wp.pdf)
- [探寻 SSDT](https://www.codeproject.com/Articles/1191465/The-Quest-for-the-SSDTs)
- [系统服务描述符表 - SSDT](https://ired.team/miscellaneous-reversing-forensics/windows-kernel/glimpse-into-ssdt-in-windows-x64-kernel)
- [中断描述符表 - IDT](https://ired.team/miscellaneous-reversing-forensics/windows-kernel/interrupt-descriptor-table-idt)
- [探索进程环境块](https://ired.team/miscellaneous-reversing-forensics/exploring-process-environment-block)
- [Windows 池管理器](https://www.osr.com/nt-insider/2014-issue1/windows-pool-manager/)
- [使用 C++ 解析 PE 文件头](https://ired.team/miscellaneous-reversing-forensics/pe-file-header-parser-in-c++)
- [深入剖析 Handle、Callback 与 ObjectType](https://rayanfam.com/topics/reversing-windows-internals-part1/)
## 高级 Windows 调试
**演讲 / 视频录像**
- [黑客直播 #28:Windows 内核调试第 I 部分](https://www.youtube.com/watch?v=s5gOW-N9AAo)
- [黑客直播 #29:Windows 内核调试第 II 部分](https://www.youtube.com/watch?v=4Xo_FAx6P0A)
- [黑客直播 #30:Windows 内核调试第 III 部分](https://www.youtube.com/watch?v=7zTtVYjjquA)
- [用于恶意软件分析的 WinDbg 基础](https://www.youtube.com/watch?v=QuFJpH3My7A)
- [Windows 调试与故障排除](https://www.youtube.com/watch?v=2rGS5fYGtJ4)
- [CNIT 126 10:使用 WinDbg 进行内核调试](https://www.youtube.com/watch?v=8sVZsxoCpSc)
- [Windows 内核调试第 I 部分](https://www.youtube.com/watch?v=s5gOW-N9AAo)
- [用于漏洞利用的微软补丁分析](https://www.youtube.com/watch?v=xMMQnok44IY)
- [Windows 内核调试基础](https://app.pluralsight.com/library/courses/windows-debugging-fundamentals)
**文章 / 论文**
- [调试教程第 1 部分:使用 CDB 和 NTSD 开始调试](https://www.codeproject.com/Articles/6469/Debug-Tutorial-Part-1-Beginning-Debugging-Using-CD)
- [调试教程第 2 部分:栈](https://www.codeproject.com/Articles/6470/Debug-Tutorial-Part-2-The-Stack)
- [调试教程第 3 部分:堆](https://www.codeproject.com/Articles/6489/Debug-Tutorial-Part-3-The-Heap)
- [调试教程第 4 部分:编写 WINDBG 扩展](https://www.codeproject.com/Articles/6522/Debug-Tutorial-Part-4-Writing-WINDBG-Extensions)
- [调试教程第 5 部分:句柄泄露](https://www.codeproject.com/Articles/6988/Debug-Tutorial-Part-5-Handle-Leaks)
- [调试教程第 6 部分:导航内核调试器](https://www.codeproject.com/Articles/7913/Debug-Tutorial-Part-6-Navigating-The-Kernel-Debugg)
- [调试教程第 7 部分:锁与同步对象](https://www.codeproject.com/Articles/7919/Debug-Tutorial-Part-7-Locks-and-Synchronization-Ob)
- [WinDbg 入门 - kernelmode](https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/getting-started-with-windbg--kernel-mode-)
- [Windows 调试器:第 1 部分:WinDbg 教程](https://www.codeproject.com/Articles/6084/Windows-Debuggers-Part-1-A-WinDbg-Tutorial#_Toc64133674)
## 0day - APT 高级恶意软件研究
**演讲 / 视频录像**
- [W32.Duqu:下一个 Stuxnet 的先驱](https://www.youtube.com/watch?v=SbkXffokmPE)
- [内核模式威胁与实际防御](https://www.youtube.com/watch?v=BBJgKuXzfwc)
- [向政府和进攻性安全公司出售 0day 漏洞](https://www.youtube.com/watch?v=ZDHHGZlEfsQ)
**文章 / 论文**
- [AcidBox:稀有恶意软件被 Turla 组织重新利用以攻击俄罗斯目标组织](https://unit42.paloaltonetworks.com/acidbox-rare-malware/)
- [Operation WizardOpium 的 0day 漏洞利用](https://securelist.com/the-zero-day-exploits-of-operation-wizardopium/97086/)
- [用于定向攻击的 0day 漏洞利用 (CVE-2018-8453)](https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/)
- [EternalBlue – 你需要知道的一切](https://research.checkpoint.com/2017/eternalblue-everything-know/)
- [深入剖析 Windows 内核权限提升漏洞:CVE-2016-7255](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/digging-windows-kernel-privilege-escalation-vulnerability-cve-2016-7255/)
## 电子游戏作弊(有时涉及内核模式内容)
**演讲 / 视频录像**
- [揭开反作弊系统的地下世界](https://www.youtube.com/watch?v=yJHyHU5UjTg)
**文章 / 论文**
- [drvmap - 使用 capcom 的驱动程序手动映射器](https://www.unknowncheats.me/forum/anti-cheat-bypass/252685-drvmap-driver-manual-mapper-using-capcom.html)
- [在你的 PC 上获取唯一标识符的所有方法](https://www.unknowncheats.me/forum/anti-cheat-bypass/333662-methods-retrieving-unique-identifiers-hwids-pc.html)
- [驱动程序,即内核模式作弊](https://www.unknowncheats.me/forum/anti-cheat-bypass/271733-driver-aka-kernel-mode.html)
## Hyper-V 与虚拟机 / 沙箱逃逸
**演讲 / 视频录像**
- [Docker 容器环境中的漏洞利用](https://www.youtube.com/watch?v=77-jaeUKH7c)
- [SVGA 设备的现代客机到宿主机逃逸利用](https://www.youtube.com/watch?v=Y-G2WJ2cBKE)
- [REcon 2014 - 通过 3D 加速突破 VirtualBox](https://www.youtube.com/watch?v=i29bAx6W1uI)
- [36C3 - ESXi 的大逃亡](https://www.youtube.com/watch?v=XHDwsvywX50)
- [BlueHat v18 || 直出 VMware](https://www.youtube.com/watch?v=o36N5wi_ZFs)
- [通过攻击性安全研究强化 Hyper-V](https://www.youtube.com/watch?v=8RCH0vFxWT4)
- [驱动进入 Hyper-V 架构与漏洞](https://www.youtube.com/watch?v=p28eTnKo8sw)
- [HyperV 架构及其内存管理器](https://recon.cx/media-archive/2017/mtl/recon2017-mtl-10-andrea-allievi-The-HyperV-Architecture-and-its-Memory-Manager.mp4)
- [利用 Hyper-V IPC 实现 Ring 0 到 Ring -1 的漏洞利用](https://www.youtube.com/watch?v=_NaRZvrs8xY)
- [利用 Hyper-V IDE 模拟器逃逸虚拟机](https://www.youtube.com/watch?v=50xxJEODO3M)
- [深入探讨 Hyper-V 架构与漏洞](https://www.youtube.com/watch?v=2bK_rC81_Eo)
**文章 / 论文**
- [Hyper-V 内存内部机制。EXO 分区内存访问](https://hvinternals.blogspot.com/2020/06/hyper-v-memory-internals-exo-partition.html)
- [Hyper-V 探险 - 对 hypercall 进行模糊测试](https://labs.f-secure.com/blog/ventures-into-hyper-v-part-1-fuzzing-hypercalls)
- [对 Hyper-V 中的半虚拟化设备进行模糊测试](https://msrc-blog.microsoft.com/2019/01/28/fuzzing-para-virtualized-devices-in-hyper-v/)
- [Hyper-V 研究的第一步](https://msrc-blog.microsoft.com/2018/12/10/first-steps-in-hyper-v-research/)
- [Windows 沙箱攻击面分析](https://googleprojectzero.blogspot.com/2015/11/windows-sandbox-attack-surface-analysis.html)
## 模糊测试
**演讲 / 视频录像**
- [HITBGSEC 2016 - 模糊测试 Windows 内核](https://www.youtube.com/watch?v=X3YlDHTL5mA)
- [Windows 内核漏洞研究与利用](https://www.youtube.com/watch?v=aRZ5Wi-NWXs)
- [挡风玻璃上的 Bug:模糊测试 Windows 内核](https://www.youtube.com/watch?v=-BkjkimINC8)
- [面向中级学习者的 Windows 内核模糊测试 ](https://www.youtube.com/watch?v=wnNyPcerjJo)
- [面向初学者的 Windows 内核模糊测试 - Ben Nagy](https://www.youtube.com/watch?v=FY-33TUKlqY)
- [Disobey 2018 - 构建 Windows 内核模糊测试器 ](https://www.youtube.com/watch?v=mpXQvto4Vy4)
- [志在必得:Windows 内核模糊测试的艺术 ](https://www.youtube.com/watch?v=9FPuKfwucsw)
- [RECON 2019 - 向量化模拟:将一切结合起来](https://www.youtube.com/watch?v=x4LPhwbTs9E)
**文章 / 论文**
- [一年 Windows 内核字体模糊测试 #1:结果](https://googleprojectzero.blogspot.com/2016/06/a-year-of-windows-kernel-font-fuzzing-1_27.html)
- [一年 Windows 内核字体模糊测试 #2:技术](https://googleprojectzero.blogspot.com/2016/07/a-year-of-windows-kernel-font-fuzzing-2.html)
## Windows 浏览器漏洞利用
**演讲 / 视频录像**
- [挖掘 IE11 沙箱逃逸第 1 部分](https://www.youtube.com/watch?v=q9dnYno_Moc)
## 我最喜欢的书籍
- Windows Internals, Part 1 (Pavel Yosifovich 等)
- Windows 10 System Programming, Part 1 (Pavel Yosifovich)
- Windows 10 System Programming, Part 2 (Pavel Yosifovich)
- Windows Kernel Programming (Pavel Yosifovich)
- Rootkits: Subverting the Windows Kernel
- The Rootkit Arsenal
- Intel® 64 and IA-32 Architectures Software Developer Manuals
## 相关认证与课程
**课程**
- Advanced Windows Exploitation (AWE)
- Sans 660
- Sans 760
- Corelan "Bootcamp" 培训
- Corelan "Advanced" 培训
**认证**
- Offensive Security Exploitation Expert (OSEE)
- Giac GXPN
标签:0day挖掘, Web报告查看器, 内核安全, 恶意代码