Installs into .claude/skills of the current project.
Are you the author of Deep Exploitation?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/0dayinc-deep-exploitation)
---
name: deep-exploitation
description: Turn a crash or primitive into a reliable exploit and a minimal PoC.
license: MIT
allowed-tools: [pwn, terminal]
metadata:
bundled: true
references:
- CWE-119
- CWE-416
- CWE-787
- https://cwe.mitre.org/data/definitions/416.html
---
# Deep Exploitation
Use when a bug already has a crash, a primitive, or a clear memory/logic
flaw and the ask is a reliable PoC - not a first recon pass.
## When to use
- crash triage, heap/stack corruption, UAF, format string, type confusion
- ASLR / NX / canary / CFG / SMEP bypass planning
- kernel, browser, or protocol exploit chains after the root cause is known
## Methodologies
- CWE classes: CWE-119, CWE-416, CWE-787, CWE-134, CWE-190
- MITRE ATT&CK: Execution, Privilege Escalation, Defense Evasion
- NIST SP 800-115: exploitation and evidence sections of a technical test
- Hand off firmware blobs to `hardware-and-firmware-testing` (OWASP FSTM)
## Tooling
- Debug: gdb + pwndbg/GEF, `radare2`, Ghidra/IDA as available.
- Inspect: `checksec`, `readelf`, `objdump`, `PWN::Plugins::Assembly`.
- Gadgets: ROPgadget / ropper.
- Fuzz to feed this skill: `PWN::Plugins::Fuzz`, AFL++, libFuzzer.
- Web follow-on: Burp over ZAP; `PWN::Plugins::BeEF` only if hooks are in
scope of the ask.
- Post-proof: `PWN::Plugins::Metasploit` only when the operator asked for
a module/session, not as the default payload.
## Procedure
1. Reproduce. One command or one `pwn_eval` snippet that crashes or
misbehaves every time.
2. Name the flaw (overflow, UAF, integer wrap, type confusion, race).
3. Map mitigations (`checksec`, `/proc/cpuinfo` SMEP/SMAP, CFG).
4. Build primitives in order: leak, arbitrary read, arbitrary write, control
of a function pointer / GOT / vtable / return.
5. Chain (ROP/JOP/SROP or logic) until controlled execution or the asked
impact (file read, auth bypass, etc.).
6. Stabilize across two runs. Document bad bytes, versions, and the fix.
## Patterns
- Heap overflow -> metadata / tcache -> write -> ROP
- UAF -> type confusion -> leak -> function-pointer write
- Format string -> `%p` leak + `%n` write -> GOT
- Kernel race -> cred / tty struct -> root
## Pitfalls
- Do not skip reproduction. A narrative ROP chain is not a PoC.
- Keep the PoC small and reversible. No persistence unless asked.
- `memory_remember` is not the exploit file. Write the artefact, then read
it back.
## Verification
A second run of the PoC shows the same impact. Notes list target version,
mitigations, and the primitive chain. If blocked, say what is missing
(leak, debugger, target binary) with evidence.