BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Chaining Microsoft Binaries to get Privileged Primit
 ives in\n   the Windows kernel\n   Tags: DEF CON Official Talk | Demo 💻
  | Exploit 🪲\n   When: Sunday\, Aug 9\, 12:30 - 13:30 PDT\n   Where: LV
 CCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]Map\n\n   Descriptio
 n:\n\n   System Guard Runtime Monitor was meant to be an OS integrity anch
 or on\n   Windows. A kernel driver\, gated behind Protected Process Light 
 (PPL)\,\n   and a runtime attestation engine running in a secure enclave. 
 In this\n   talk\, we revisit a classic code injection technique and adapt
  it into\n   what we call "Bring Your Own Vulnerable WerFaultSecure". Inst
 ead of\n   loading a third-party vulnerable driver\, we bring our own vuln
 erable\n   copy of a PPL-enabled Microsoft binary and its dependencies to 
 get\n   code execution as a protected process. From there\, we pivot into 
 the\n   Microsoft System Guard kernel driver\, a component that was built 
 to\n   support the integrity attestation of kernel objects\, specifically\
 n   processes\, but which can be abused to tamper with those exact objects
 \n   instead. We will close by sharing Indicators of Compromise (IOCs)\,\n
    along with prevention and detection ideas for defenders\, and by\n   di
 scussing the innovation this exploit chain brings to the offensive\n   sec
 urity landscape.\n\n   https://infocon.org/mirrors/vx%20underground%20-%20
 2025%20June/Papers/Windows/Internals%20and%20Analysis/2022-08-02%20-%20Ins
 ide%20Windows%20Defender%20System%20Guard%20Runtime%20Monitor.pdf\n   http
 s://www.microsoft.com/en-us/security/blog/2018/04/19/introducing-windows-d
 efender-system-guard-runtime-attestation/\n   https://googleprojectzero.bl
 ogspot.com/2018/10/injecting-code-into-windows-protected.html\n   https://
 googleprojectzero.blogspot.com/2018/11/injecting-code-into-windows-protect
 ed.html\n   https://x.com/GabrielLandau/status/1683854578767343619\n   htt
 ps://blog.scrt.ch/2023/03/17/bypassing-ppl-in-userland-again/\n   https://
 iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html\n   https://github.com/
 Slowerzs/PPLSystem\n   https://github.com/mdsecactivebreach/com_inject/\n 
   https://helgeklein.com/blog/anatomy-of-werfault-exe-application-crash-er
 ror-reporting/\n\n   SpeakerBio:  Angelo Frasca Caccia\, SentinelOne\n\n  
  Angelo is a security researcher specialized in Windows Internals. He\n   
 currently works at SentinelOne\, where he conducts research on advanced\n 
   exploits and tampering techniques targeting the Windows ecosystem.\n   A
 ngelo’s background also includes web application penetration\n   testing
  and red teaming\, particularly assume-breach adversary\n   simulations.\n
 \n   Angelo is eCXD\, eCPPT\, eJPT and OSCP certified. He enjoys reverse\n
    engineering and programming\, mostly in C/C++. His GitHub profile\n   (
 https://github/lem0nSec) features his main contributions to the\n   cybers
 ecurity community.\n\n   Angelo has a master’s degree in International S
 ecurity Studies from\n   University of Leicester\, where he graduated in 2
 021 with the ‘Best\n   Campus-Based Masters Dissertation Prize’ and th
 e ‘Best\n   Campus-Based Masters Student Performance Prize’.\n\n   '\n
 \n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T203000Z
DTSTART:20260809T193000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Chaining Microsoft Binaries to get Privileged Primitives in the Win
 dows kernel
END:VEVENT
END:VCALENDAR
