Recon 2026

Alejandro Pinna

Alejandro Pinna is the manager of the Offensive Security Research team in SentinelOne, focusing on Offensive Tradecraft and evasive TTP analysis.
Passionate about CyberSecurity and Offensive Security for many years, belonged to one of the most advanced Red Teams in Spain till he joined SentinelOne in 2022, where he contributed with advanced research till finally he started leading the team in January 2025

Angelo Frasca is part of the Exploits and Antitampering Research team in SentinelOne for the last 2 years.
His work consists on understanding which techniques Windows Exploits use to obtain privileged primitives in the kernel and creating defenses against them, improving SentinelOne EDR self-protection and detection capabilities


Session

06-19
16:00
60min
Chaining Microsoft binaries to get privileged primitives in Windows kernel
Angelo Frasca Caccia, Alejandro Pinna

We leveraged a novel code injection to a PPL process we call ‘Bring Your Own Vulnerable WerFaultSecure’ and then abuse Microsoft System Guard for privileged primitives in the kernel. We’ll explain how to make WerFaultSecure run arbitrary code and the vulnerabilities we found in a Microsoft driver.

Grand Salon Opera