Angelo Frasca Caccia
Angelo is a security researcher specialised in Windows Internals. He currently works at SentinelOne, where he conducts research on advanced exploits and tampering techniques targeting the Windows ecosystem. Angelo’s background also includes web application penetration testing and red teaming, particularly assume-breach adversary simulations.
Angelo is eCXD, eCPPT, eJPT and OSCP certified. He enjoys reverse engineering and programming. His GitHub profile (https://github/lem0nSec) features his main contributions to the cybersecurity community.
Angelo has a master’s degree in International Security Studies from University of Leicester, where he graduated in 2021 with the ‘Best Campus-Based Masters Dissertation Prize’ and the ‘Best Campus-Based Masters Student Performance Prize’.
Session
We leveraged a novel code injection to a PPL process we call ‘Bring Your Own Vulnerable WerFaultSecure’ and then abuse Microsoft System Guard for privileged primitives in the kernel. We’ll explain how to make WerFaultSecure run arbitrary code and the vulnerabilities we found in a Microsoft driver.
