windows-kernel-security
Provides guidance on Windows kernel security, driver development, and analysis of low-level system mechanisms.
Install
mkdir -p .claude/skills/windows-kernel-security && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/4184" && unzip -o skill.zip -d .claude/skills/windows-kernel-security && rm skill.zipInstalls to .claude/skills/windows-kernel-security
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Guide for Windows kernel internals and security mechanisms used in game protection and low-level research. Use this skill when working with drivers, IRQL-sensitive callbacks, EPROCESS, ETHREAD, MMVAD internals, IOCTL paths, DSE, PatchGuard, HVCI, PiDDBCache, MmUnloadedDrivers, or kernel memory inspection.Key capabilities
- →Inspect EPROCESS/ETHREAD structures
- →Enumerate system callbacks
- →Walk kernel memory structures via debug symbols
- →Analyze driver object dependencies
- →Resolve symbol offsets for driver research
How it works
Uses symbol servers to map memory address space to Windows kernel data structures and inspects system-level bookkeeping tables.
Inputs & outputs
When to use windows-kernel-security
- →Research Windows kernel internals
- →Analyze system callbacks
- →Study driver security mechanisms
- →Inspect kernel memory structures
About this skill
Windows kernel security
Match undocumented structures, offsets, globals, and allocator behavior to the exact Windows build and symbols. Separate documented contracts, observed state, and inference.
Topic routing
- Foundations and security for driver surfaces, symbols, PatchGuard, DSE, VBS/HVCI, and Secure Boot.
- Drivers and observation for callbacks, IRQL, APCs, driver structure, hooking, and ETW.
- Memory and forensics for pool architecture, memory access, dumps, and tools.
- Threats and virtualization for vulnerable drivers, boot threats, PatchGuard research, and hypervisor defenses.
- Repository resources and repository map for source selection.
Use dma-attack-techniques for device-originated memory access and game-security-research-rigor for version-sensitive conclusions.
When not to use it
- →General application security auditing
- →Non-Windows environments
- →Tasks involving high-level framework security only
Prerequisites
Limitations
- →High risk of system instability during live analysis
- →Requires deep knowledge of OS internals
How it compares
It provides deep-dive debugging methodology specifically for the Windows kernel, rather than generic vulnerability scanning.
Compared to similar skills
windows-kernel-security side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| windows-kernel-security (this skill) | 7 | 4mo | No flags | Advanced |
| security-header-generator | 5 | 11mo | Caution | Intermediate |
| backend-security-coder | 24 | 5mo | No flags | Intermediate |
| api-security-best-practices | 15 | 8mo | Review | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by gmh5225
View all by gmh5225 →You might also like
security-header-generator
Dexploarer
Generates security HTTP headers (CSP, HSTS, CORS, etc.) for web applications to prevent common attacks. Use when user asks to "add security headers", "setup CSP", "configure CORS", "secure headers", or "HSTS setup".
backend-security-coder
sickn33
Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
api-security-best-practices
davila7
Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
springboot-security
affaan-m
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
django-security
affaan-m
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
xss-testing
Ed1s0nZ
XSS跨站脚本攻击测试的专业技能