Skip to content
Back to skills

Deep Exploitation

ASecurity

Turn a crash or primitive into a reliable exploit and a minimal PoC.

  • 86 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 10, 2026
securitygotesting

Works with

  • terminal

Security analysis

A100/100

Scanned September 10, 2026

npx -y skills add 0dayInc/pwn --skill deep-exploitation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Deep Exploitation?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Deep Exploitation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/0dayinc-deep-exploitation/badge)](https://www.skillsdirectory.com/skills/0dayinc-deep-exploitation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: deep-exploitation
description: Turn a crash or primitive into a reliable exploit and a minimal PoC.
license: MIT
allowed-tools: [pwn, terminal]
metadata:
  bundled: true
  references:
    - CWE-119
    - CWE-416
    - CWE-787
    - https://cwe.mitre.org/data/definitions/416.html
---

# Deep Exploitation

Use when a bug already has a crash, a primitive, or a clear memory/logic
flaw and the ask is a reliable PoC - not a first recon pass.

## When to use

- crash triage, heap/stack corruption, UAF, format string, type confusion
- ASLR / NX / canary / CFG / SMEP bypass planning
- kernel, browser, or protocol exploit chains after the root cause is known

## Methodologies

- CWE classes: CWE-119, CWE-416, CWE-787, CWE-134, CWE-190
- MITRE ATT&CK: Execution, Privilege Escalation, Defense Evasion
- NIST SP 800-115: exploitation and evidence sections of a technical test
- Hand off firmware blobs to `hardware-and-firmware-testing` (OWASP FSTM)

## Tooling

- Debug: gdb + pwndbg/GEF, `radare2`, Ghidra/IDA as available.
- Inspect: `checksec`, `readelf`, `objdump`, `PWN::Plugins::Assembly`.
- Gadgets: ROPgadget / ropper.
- Fuzz to feed this skill: `PWN::Plugins::Fuzz`, AFL++, libFuzzer.
- Web follow-on: Burp over ZAP; `PWN::Plugins::BeEF` only if hooks are in
  scope of the ask.
- Post-proof: `PWN::Plugins::Metasploit` only when the operator asked for
  a module/session, not as the default payload.

## Procedure

1. Reproduce. One command or one `pwn_eval` snippet that crashes or
   misbehaves every time.
2. Name the flaw (overflow, UAF, integer wrap, type confusion, race).
3. Map mitigations (`checksec`, `/proc/cpuinfo` SMEP/SMAP, CFG).
4. Build primitives in order: leak, arbitrary read, arbitrary write, control
   of a function pointer / GOT / vtable / return.
5. Chain (ROP/JOP/SROP or logic) until controlled execution or the asked
   impact (file read, auth bypass, etc.).
6. Stabilize across two runs. Document bad bytes, versions, and the fix.

## Patterns

- Heap overflow -> metadata / tcache -> write -> ROP
- UAF -> type confusion -> leak -> function-pointer write
- Format string -> `%p` leak + `%n` write -> GOT
- Kernel race -> cred / tty struct -> root

## Pitfalls

- Do not skip reproduction. A narrative ROP chain is not a PoC.
- Keep the PoC small and reversible. No persistence unless asked.
- `memory_remember` is not the exploit file. Write the artefact, then read
  it back.

## Verification

A second run of the PoC shows the same impact. Notes list target version,
mitigations, and the primitive chain. If blocked, say what is missing
(leak, debugger, target binary) with evidence.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…