Hyper-V is a type-1 hypervisor that runs the Windows host as a privileged parent partition managing child-partition guests. Offensive interest is in reaching that parent partition, breaking out of a child partition through the synthetic device stack (VMBus, the virtual switch, the vmwp.exe worker process), controlling guests through the WMI and PowerShell management plane, and lifting checkpoints and VHD files.
Subtopics#
- Host access and shell: reaching the parent partition.
- Guest to host escape: breaking out of a child partition.
- Management plane and WMI abuse: controlling guests through management interfaces.
- Checkpoint and VHD theft: lifting guest disks and checkpoints.
- Known escape exploits: named Hyper-V breakouts.