Advanced Windows Exploitation
Windows kernel exploitation, EDR evasion at the driver level, COM/DCOM abuse, ADCS attacks, and custom loader development for advanced Windows operations.
This course includes:
- 14 modules, 117 lessons
- 28 hands-on labs
- 14 quizzes
- Lifetime course access
- Certificate of completion
- One certification attempt included
- Certification is lifetime - never expires
- 14-day refund guarantee*
About This Course
What You'll Learn
Exploit Windows kernel vulnerabilities and driver bugs
Develop EDR evasion techniques at the kernel and driver level
Abuse COM/DCOM objects for lateral movement and persistence
Exploit Active Directory Certificate Services (ADCS)
Build custom reflective loaders and shellcode injection frameworks
Bypass Windows security mitigations: CFG, ACG, CIG, CET
Course Curriculum
This is a preview of the course content. Register to access all lessons.
Module 1 - Windows Internals for Exploitation
Process and Memory Architecture Lesson
The PE Format for Exploit Developers Lesson
Windows Kernel Object Model Lesson
The Windows API Layer Cake Lesson
Windows Security Architecture Lesson
Lab: Building Your Windows Exploitation Environment Hands-On
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 2 - Windows Heap Exploitation
Segment Heap Architecture Lesson
Low Fragmentation Heap Internals Lesson
User-Mode Heap Attacks Lesson
Kernel Pool Exploitation Lesson
Token and EPROCESS Manipulation Lesson
GDI Object Exploitation - Historical Context Lesson
Heap Feng Shui and Exploit Reliability Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 3 - Windows Kernel Exploitation
CLFS Exploitation Lesson
Win32k Exploitation Lesson
ntoskrnl.exe Core Kernel Attacks Lesson
IO_RING Exploitation Lesson
Registry and File System Attack Surfaces Lesson
RPC and ALPC Exploitation Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 4 - Kernel Mitigation Bypass
CFG, kCFG, and XFG Lesson
CET and Hardware Shadow Stack Lesson
ACG and Code Integrity Lesson
VBS, HVCI, and Data-Only Attacks Lesson
KASLR and Information Leaks Lesson
The Mitigation Matrix Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 5 - EDR Architecture and Evasion
How EDR Works - The Detection Stack Lesson
Direct and Indirect Syscalls Lesson
Ntdll Unhooking Techniques Lesson
Kernel Callback Removal Lesson
ETW Patching and Threat Intelligence Bypass Lesson
Hardware Breakpoint Hooking Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 6 - Security Boundary Bypass
AMSI Bypass Evolution Lesson
PPL and CI Bypass Lesson
Credential Guard and VBS-Protected Secrets Lesson
WDAC Bypass Lesson
PPID Spoofing and Process Attribute Manipulation Lesson
Windows Defender Evasion Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 7 - Process Injection and Code Execution
Classic Injection Techniques Lesson
Process Hollowing and Creation Variants Lesson
Hybrid Hollowing Techniques Lesson
Reflective DLL Injection Lesson
Module Stomping and DLL Hollowing Lesson
Beacon Object Files and In-Memory Execution Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 8 - Advanced Implant Engineering
Sleep Obfuscation Lesson
Call Stack Spoofing Lesson
Custom Shellcode Development Lesson
Rust-Based Implant Development Lesson
C2 Framework Integration Lesson
Anti-Analysis and Anti-Debug Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 9 - Windows Driver Exploitation
Windows Driver Architecture Lesson
Driver Attack Surface Analysis Lesson
Driver Vulnerability Research Lesson
BYOVD Attacks Lesson
Driver Exploit Development Lesson
Defenses and the Vulnerable Driver Blocklist Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 10 - Active Directory and Lateral Movement
ADCS Exploitation Lesson
Kerberos Ticket Forging Lesson
NTLM Relay and Authentication Coercion Lesson
DCOM and COM Exploitation Lesson
Delegation and Trust Exploitation Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 11 - Hyper-V and Virtualization Exploitation
Hyper-V Architecture Lesson
Guest-to-Host Escape Techniques Lesson
WSL Exploitation Lesson
VBS and VTL Boundary Attacks Lesson
Sandbox and AppContainer Escapes Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Module 12 - Windows Persistence and Anti-Forensics
Registry-Based Persistence Lesson
WMI Event Subscriptions Lesson
Service and Scheduled Task Persistence Lesson
UEFI Bootkits Lesson
Kernel-Mode Rootkit Techniques Lesson
Anti-Forensics on Windows Lesson
Practical Exercises Hands-On
Quiz Assessment
Lab Hands-On
Capstone Project
The Challenge Project
Deliverables Project
Assessment Criteria Project
Certification Preparation
Exam Overview Lesson
Domains and Weightings Lesson
Exam Environment and Rules Lesson
Preparation Strategy Lesson
Registration and Logistics Lesson
After Certification Lesson
Career Leverage Lesson
Certification Roadmap
Every course leads to its own certification. All are independent - start anywhere, build your path.
TSEC
Security Fundamentals
Foundation
TPEN
Certified Pentester
Offensive
TRED
Red Team Operator
Offensive
TDEF
Certified Defender
Defensive
TFOR
Forensic Analyst
Defensive
TMAL
Malware Analyst
Analytical
TAMI
Advanced Malware Intelligence
Analytical
TCTI
Threat Intelligence Analyst
Analytical
TREV
Reverse Engineer
Analytical