BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: The Enclave is Lying to You: Breaking TEE Trust Boun
 daries\n   Through Boot-Time State\n   Tags: DEF CON Official Talk | Demo 
 ðŸ’» | Tool ðŸ› \n   When: Saturday\, Aug 8\, 14:00 - 14:59 PDT\n   Where:
  LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3 - [1]Map\n\n   Descrip
 tion:\n   Confidential computing on cloud TEEs: Nitro Enclaves\, SEV-SNP\,
  and TDX\n   promises that a fully compromised host cannot reach into a\n 
   hardware-isolated enclave. The cryptographic attestation story holds.\n 
   The deployment story does not.\n\n   This talk demonstrates attacks that
  bypass TEE isolation without\n   touching the enclave image. We target th
 e inputs an enclave trusts at\n   boot: cloud object storage\, host-suppli
 ed environment variables\, and\n   KMS keys whose policies forget to enfor
 ce attestation. None are\n   covered by attestation. All reach inside.\n\n
    We demonstrate remote code execution as root inside a Nitro Enclave\n  
  with a single s3:PutObject permission. No host access. No SSH. One\n   fi
 le upload containing a path traversal\, one boot cycle\, and the\n   encla
 ve executes attacker-controlled code.\n\n   From inside we intercept KMS d
 ecrypts live to extract the database\n   encryption key in plaintext\, exf
 iltrate the enclave's IAM credentials\,\n   and establish persistence acro
 ss reboots without re-exploitation - all\n   while PCR measurements remain
  unchanged and attestation reports a\n   healthy enclave.\n\n   We release
  an open-source auditing tool\, walk through which defenses\n   held\, and
  provide a hardening checklist for any team running workloads\n   inside T
 EEs.\n\n   The enclave isn't broken. The way we deploy it is.\n\n   AWS\, 
 "AWS Nitro Enclaves User Guide\,"\n   https://docs.aws.amazon.com/enclaves
 /latest/user/nitro-enclave.html\n   AWS\, "Cryptographic Attestation with 
 AWS KMS for Nitro Enclaves\,"\n   https://docs.aws.amazon.com/kms/latest/d
 eveloperguide/services-nitro-enclaves.html\n   A. Tsow\, "Attacking Confid
 ential Computing: A Survey of TEE\n   Exploitation Techniques\," IEEE S&P 
 Workshop on Offensive Technologies\n   (WOOT)\, 2024 NCC Group\, "Public R
 eport - AWS Nitro System Security\n   Review\," 2023\, https://research.nc
 cgroup.com/2023/04/ Trail of Bits\,\n   "Security Assessment of AWS Nitro 
 Enclaves\," 2022 MITRE ATT&CK\, "Cloud\n   Matrix - Initial Access / Valid
  Accounts\,"\n   https://attack.mitre.org/techniques/T1078/004/ J. Aas et 
 al.\,\n   "Understanding TEE Trust Models in Cloud Deployments\," USENIX S
 ecurity\n   Symposium\, 2023 OWASP\, "Path Traversal\,"\n   https://owasp.
 org/www-community/attacks/Path_Traversal AWS\, "Instance\n   Metadata Serv
 ice Version 2 (IMDSv2)\,"\n   https://docs.aws.amazon.com/AWSEC2/latest/Us
 erGuide/configuring-instance-metadata-service.html\n   Apache Thrift Proje
 ct\, "Thrift Binary Protocol Specification\,"\n   https://github.com/apach
 e/thrift/blob/master/doc/specs/thrift-binary-protocol.md\n\n   SpeakerBio:
   Sandeep "pyro" Jayashankar\, Independent Researcher\n\n   Sandeep Jayash
 ankar is a security researcher specializing in offensive\n   security and 
 adversarial simulations. His work spans AWS\, Azure\, and\n   GCP environm
 ents\, with current research focused on trusted execution\n   environment 
 exploitation\, confidential computing trust boundaries\, and\n   the secur
 ity of AI/ML systems deployed in cloud-native architectures.\n   This rese
 arch was conducted under an authorized adversarial simulation\n   program.
  He approaches security research from a defender's\n   perspective: every 
 offensive finding ships with a concrete\, auditable\n   control that defen
 ders can deploy. He previously presented at RSA\n   Conference 2025.\n\n  
  '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T215900Z
DTSTART:20260808T210000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:The Enclave is Lying to You: Breaking TEE Trust Boundaries Through 
 Boot-Time State
END:VEVENT
END:VCALENDAR
