Recon 2026

Angelo Frasca Caccia

Angelo is a security researcher specialised in Windows Internals. He currently works at SentinelOne, where he conducts research on advanced exploits and tampering techniques targeting the Windows ecosystem. Angelo’s background also includes web application penetration testing and red teaming, particularly assume-breach adversary simulations.

Angelo is eCXD, eCPPT, eJPT and OSCP certified. He enjoys reverse engineering and programming. His GitHub profile (https://github/lem0nSec) features his main contributions to the cybersecurity community.

Angelo has a master’s degree in International Security Studies from University of Leicester, where he graduated in 2021 with the ‘Best Campus-Based Masters Dissertation Prize’ and the ‘Best Campus-Based Masters Student Performance Prize’.


Intervention

19/06
16:00
60minutes
Chaining Microsoft binaries to get privileged primitives in Windows kernel
Angelo Frasca Caccia, Alejandro Pinna

We leveraged a novel code injection to a PPL process we call ‘Bring Your Own Vulnerable WerFaultSecure’ and then abuse Microsoft System Guard for privileged primitives in the kernel. We’ll explain how to make WerFaultSecure run arbitrary code and the vulnerabilities we found in a Microsoft driver.

Grand Salon Opera