Alejandro Pinna
Alejandro Pinna is the manager of the Offensive Security Research team in SentinelOne, focusing on Offensive Tradecraft and evasive TTP analysis.
Passionate about CyberSecurity and Offensive Security for many years, belonged to one of the most advanced Red Teams in Spain till he joined SentinelOne in 2022, where he contributed with advanced research till finally he started leading the team in January 2025
Angelo Frasca is part of the Exploits and Antitampering Research team in SentinelOne for the last 2 years.
His work consists on understanding which techniques Windows Exploits use to obtain privileged primitives in the kernel and creating defenses against them, improving SentinelOne EDR self-protection and detection capabilities
Session
We leveraged a novel code injection to a PPL process we call ‘Bring Your Own Vulnerable WerFaultSecure’ and then abuse Microsoft System Guard for privileged primitives in the kernel. We’ll explain how to make WerFaultSecure run arbitrary code and the vulnerabilities we found in a Microsoft driver.
