WI

windows-kernel-security

Provides guidance on Windows kernel security, driver development, and analysis of low-level system mechanisms.

Install

mkdir -p .claude/skills/windows-kernel-security && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4184" && unzip -o skill.zip -d .claude/skills/windows-kernel-security && rm skill.zip

Installs to .claude/skills/windows-kernel-security

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Guide for Windows kernel internals and security mechanisms used in game protection and low-level research. Use this skill when working with drivers, IRQL-sensitive callbacks, EPROCESS, ETHREAD, MMVAD internals, IOCTL paths, DSE, PatchGuard, HVCI, PiDDBCache, MmUnloadedDrivers, or kernel memory inspection.
306 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Advanced

Key capabilities

  • →Inspect EPROCESS/ETHREAD structures
  • →Enumerate system callbacks
  • →Walk kernel memory structures via debug symbols
  • →Analyze driver object dependencies
  • →Resolve symbol offsets for driver research

How it works

Uses symbol servers to map memory address space to Windows kernel data structures and inspects system-level bookkeeping tables.

Inputs & outputs

You give it
Kernel structure name or target driver file
You get back
Memory offset, structure layout, or callback analysis

When to use windows-kernel-security

  • →Research Windows kernel internals
  • →Analyze system callbacks
  • →Study driver security mechanisms
  • →Inspect kernel memory structures

About this skill

Windows kernel security

Match undocumented structures, offsets, globals, and allocator behavior to the exact Windows build and symbols. Separate documented contracts, observed state, and inference.

Topic routing

Use dma-attack-techniques for device-originated memory access and game-security-research-rigor for version-sensitive conclusions.

When not to use it

  • →General application security auditing
  • →Non-Windows environments
  • →Tasks involving high-level framework security only

Prerequisites

Windows Kernel Debuggerdbghelp

Limitations

  • →High risk of system instability during live analysis
  • →Requires deep knowledge of OS internals

How it compares

It provides deep-dive debugging methodology specifically for the Windows kernel, rather than generic vulnerability scanning.

Compared to similar skills

windows-kernel-security side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
windows-kernel-security (this skill)74moNo flagsAdvanced
security-header-generator511moCautionIntermediate
backend-security-coder245moNo flagsIntermediate
api-security-best-practices158moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

game-engine-resources

gmh5225

Guide for game engine development resources including engine source code, plugins, and development guides. Use this skill when researching game engines (Unreal, Unity, Godot, custom engines), engine architecture, or game development frameworks.

1485

mobile-security

gmh5225

Guide for mobile game security on Android and iOS platforms. Use this skill when working with Android/iOS reverse engineering, mobile game hacking, APK analysis, root/jailbreak detection bypass, or mobile anti-cheat systems.

1469

anti-cheat-systems

gmh5225

Guide for understanding anti-cheat systems and bypass techniques. Use this skill when researching game protection systems (EAC, BattlEye, Vanguard), anti-cheat architecture, detection methods, or bypass strategies.

813

graphics-api-hooking

gmh5225

Guide for graphics API hooking and rendering techniques for DirectX, OpenGL, and Vulkan. Use this skill when working with graphics hooks, overlay rendering, shader manipulation, or game rendering pipeline analysis.

725

Search skills

Search the agent skills registry