A Practical Windows Kernel Research Workflow

A repeatable workflow for going from an interesting Windows kernel component to a controlled vulnerability research target.

From target selection to hypothesis

Kernel research becomes much easier when the process is broken into small, testable stages.

Target
  ↓
Attack surface
  ↓
Input discovery
  ↓
Reverse engineering
  ↓
Invariant / bug hypothesis
  ↓
Controlled reproduction
  ↓
Root cause
  ↓
Impact analysis