offensive-tools/windows/watson/SKILL.md
Auth/lab ref: Windows patch vulnerability analyzer that identifies missing KB patches and maps to known exploitable CVEs.
npx skillsauth add aeondave/malskill watsonInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Windows patch vulnerability scanner — identifies missing KBs and maps to exploitable CVEs.
# Basic patch check
Watson.exe
# Verbose output
Watson.exe -v
# Export to file
Watson.exe > watson_output.txt
Watson automatically:
| Category | Examples | |---|---| | Kernel Exploits | DirtyCOW, Dirty Pipe, OverlayFS (CVE variants) | | Privilege Escalation | ElevatedPotato, PrintNightmare, PetitPotam | | Credential Dumping | LSASS dumping CVEs | | Authentication Bypass | Zero-click admin elevation bugs | | Information Disclosure | Kernel pointer leaks, memory disclosure |
Watson displays:
Example output:
[!] CVE-2016-3309 — Windows Kernel Elevation of Privilege
Affected: Windows 7 SP1, Windows Server 2008 R2 SP1
Severity: Critical
Status: VULNERABLE (KB missing)
PoC: Available (github.com/abysssol/CVE-2016-3309)
# Run Watson on target
Watson.exe > patching_status.txt
# Review output for CRITICAL + VULNERABLE
# Identify exploits with public PoC
Focus on:
# Check if services are running
sc query spooler # Print Spooler
sc query WinRM # Windows Remote Management
tasklist | findstr service # Check for running services
# Example: PrintNightmare (CVE-2021-34527)
# 1. Watson shows "VULNERABLE" + PoC available
# 2. Check if Print Spooler is running
# → sc query spooler
# 3. If running + vulnerable, exploit
# Example: ElevatedPotato
# 1. Watson shows kernel CVE exploitable
# 2. Compile/obtain ElevatedPotato
# 3. Run → SYSTEM shell
| Tool | Focus | |---|---| | Watson | Kernel patches + public CVE mapping | | WinPEAS | Configuration misconfigurations (services, SUID, perms) | | Together | Complete privilege escalation surface → patch + misconfig vectors |
Use Watson first (fast, specific), then WinPEAS for broader enumeration.
Watson.exe
# Usually many CRITICAL vulnerabilities
# High likelihood of working PoC
Watson.exe
# Fewer vulnerabilities, but newer patches often take time to roll out
# Check monthly security updates status
Watson.exe
# May show many gaps; check last Windows Update date
# Can be indicator of other misconfigurations
If Watson output is unclear:
# Get all installed patches
Get-HotFix | Select HotFixID
# Check specific KB
Get-HotFix | Select HotFixID | Select-String "KB2999226"
# Returns nothing → patch NOT installed → VULNERABLE
# Get Windows version
[System.Environment]::OSVersion.Version
# or
Get-WmiObject -Class Win32_OperatingSystem | Select Caption, BuildNumber
| Tool | Use | |---|---| | WinPEAS | Run first for full enum, Watson confirms kernel vulns | | Exploit frameworks | SearchSploit / Metasploit to find working exploits | | Custom exploit repos | GitHub has PoCs for most Watson-identified CVEs |
| File | When to load |
|---|---|
| references/ | Kernel exploit compilation, CVE remediation, safe testing practices |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.