
GIAC Exploit Researcher and Advanced Penetration Tester
The GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) certification validates your ability to pinpoint and mitigate significant security flaws in systems and networks. It is designed for penetration testers and security professionals who conduct advanced attacks by modeling attacker behavior. Earning GXPN proves you can demonstrate and mitigate business risk with expert-level exploitation knowledge.
510 practice questions · Updated 2026-07-30
5Domains
14Objectives
117Concepts
510Questions
GXPN Curriculum
Every domain, objective, and concept the GXPN exam measures.
- Linux Process Memory Layout
- Stack Frames and Function Call Mechanics
- x86 and x86-64 Calling Conventions
- Endianness and Data Representation
- Shellcode Fundamentals
- Shellcode Encoding and Decoding
- Position-Independent Code
- System Calls and Syscall Numbers
- Executable Memory and Protections
- Windows Memory Layout
- Paging and Page Tables
- Heap Internals
- Stack Internals
- PE File Format
- Windows Process Execution
- Memory Protection Mechanisms
- Kernel vs User Mode
- ROP Fundamentals
- Gadget Identification
- Stack Layout and Chaining
- Bypassing Protections
- Function Call Conventions
- Practical Exploitation
- Windows Memory Layout
- Stack Overflow Fundamentals
- SEH Overwrite Exploitation
- Heap Overflow Exploitation
- DEP and ASLR Bypass Techniques
- Return-Oriented Programming (ROP)
- Egg Hunters and Shellcode Placement
- Windows Exploit Mitigation Controls
- Practical Execution Control Techniques
- Linux exploit mitigation landscape
- Bypassing ASLR
- Bypassing NX/DEP
- Bypassing stack canaries
- Bypassing RELRO
- Bypassing PIE
- Bypassing seccomp and sandboxes
- Bypassing CFI and other forward-edge protections
- Combining bypass techniques
- Understanding Windows Memory Protections
- Bypassing Data Execution Prevention (DEP)
- Bypassing Address Space Layout Randomization (ASLR)
- Bypassing Stack Cookies (GS)
- Bypassing SafeSEH and SEHOP
- Bypassing Control Flow Guard (CFG)
- Bypassing Heap Protections
- Combining Bypass Techniques
- Network Access Establishment
- Infrastructure Discovery
- Protocol Exploitation
- Network Device Attacks
- Traffic Interception and Manipulation
- Infrastructure Pivoting
- Redundancy and Failover Exploitation
- Infrastructure Persistence
- Traffic Interception Techniques
- Traffic Manipulation Techniques
- Man-in-the-Middle (MITM) Attacks
- Network Protocol Exploitation
- Tools for Traffic Interception and Manipulation
- Detection and Mitigation
- Symmetric Encryption
- Asymmetric Encryption
- Hashing and Integrity
- Digital Signatures
- Key Exchange Protocols
- Cryptographic Attacks
- Cryptographic Implementations in Scripting
- Cryptographic Vulnerabilities
- Scripting Fundamentals for Offense
- Network Interaction Scripting
- Exploit Development Scripting
- Encryption and Encoding in Scripts
- Obfuscation and Evasion Techniques
- Automating Post-Exploitation Tasks
- Integrating Third-Party Tools
- Script Debugging and Optimization
- Endpoint Control Evasion Fundamentals
- Antivirus Evasion Techniques
- Host-Based Intrusion Detection System (HIDS) Evasion
- Application Whitelisting Bypass
- Endpoint Detection and Response (EDR) Evasion
- Privilege Escalation Fundamentals
- Windows Privilege Escalation Techniques
- Linux Privilege Escalation Techniques
- Token Manipulation and Impersonation
- Service and Scheduled Task Exploitation
- Credential Harvesting and Reuse
- UAC Bypass Techniques
- Kernel Exploitation Basics
- Product Security Testing Concepts
- Threat Modeling for Products
- Secure Code Review
- Fuzzing and Vulnerability Discovery
- Exploit Development for Product Testing
- Patch Analysis and Reverse Engineering
- Reporting and Remediation Guidance
- Fuzzing Fundamentals
- Fuzzing Techniques
- Fuzzing Tools and Frameworks
- Fuzzing Target Analysis
- Fuzzing Test Case Generation
- Fuzzing Execution and Monitoring
- Crash Triage and Analysis
- Fuzzing Integration in Product Security
- Fuzzing Fundamentals
- Fuzzing Workflow
- Coverage-Guided Fuzzing
- Mutation-Based Fuzzing
- Generation-Based Fuzzing
- Fuzzing Engines and Frameworks
- Instrumentation for Fuzzing
- Input Corpus Management
- Crash Analysis and Triage
- Fuzzing in CI/CD
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for GXPN, so none is invented.