Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"
Joined May 2009
- Tweets1.9K
- Following323
- Followers9.4K
- Likes1.6K
Andrea P retweeted
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed “Dark Elevator”.
But was it really fixed?
Ask @tiraniddo
projectzero.google/2026/09/w…
Andrea P retweeted
Been digging deep into the Windows Endpoint Security Platform (WESP) in Win11 25H2, definitely one of the most fascinating security features Microsoft has built in a while.
The concept is neat: compile rules to decision graphs in user mode, hand them to wesp.sys, and let the kernel evaluate them in-path while telemetry streams asynchronously in the background.
I did an AI-assisted reverse engineering dive into the whole stack (wesp.sys, espclient.dll, and wesp_elam.sys), documented the wire protocols, disposition tables, and the enforcement gate, and built esptool, a research harness with 118 XML rule docs so anyone can test live telemetry and in-kernel blocking.
Repo: github.com/marcosd4h/wesp_re…
Tech doc: github.com/marcosd4h/wesp-re…
Thanks to @yarden_shafir for putting this on my radar
Andrea P retweeted
askWAM - Requests Microsoft Entra access tokens silently through Windows Web Account Manager (WAM) by @_dirkjan
github.com/dirkjanm/askWAM
I just wrote a new blog on bypassing CA policies in Entra ID that have a resource exclusion, and why you probably want to enable baseline enforcement if you have such policies. Enjoy!
dirkjanm.io/bypassing-condit…
Andrea P retweeted
Regarding Active Directory permissions, most people assume that a Deny ACE always wins. It doesn't!
Windows stops the access check the moment enough rights are granted — any ACE after that point is never evaluated.
New post: managedpriv.com/blog/acl-can…
Andrea P retweeted
Replying to @4ndr3w6S
@4ndr3w6S pulled me into this rabbit hole, and it was a fun one.
Took a break from LDAP, fell down the dMSA rabbit hole with @YuG0rd, and watched the snake eat its own tail.
dMSA Ouroboros: self-sustaining credential extraction on patched Server 2025. Six commands. Survives attacker account deletion.
huntress.com/blog/dmsa-ourob…
Andrea P retweeted
This second blogpost concludes @yaumn_'s research on #Windows authentication reflection.
He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥
A little bonus is even included at the end 👀👇
synacktiv.com/en/publication…
Andrea P retweeted
[RELEASE] Better late than never! Part 3 is out! Fantastic unwind information and where to find them. We went digging through .pdata, RTF Lookups, and a few ntdll internals that probably weren't meant to be touched. BYOUD dropping alongside. Enjoy 😉
klezvirus.github.io/posts/By…
Andrea P retweeted
Replying to @decoder_it
@decoder_it breaks down reflection attacks and their impact on enterprise security in this new talk at #INSO26. Are you interested in how modern authentication flow works? So this talk is for you!
Save your spot: ow.ly/cCr450Ykak4
#Infosec #INSO26 #CyberConference
Andrea P retweeted
In the final part of his blog series, @tiraniddo tells the story of how a bug was introduced into a Windows API.
Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process.
projectzero.google/2026/02/g…
Andrea P retweeted
Nuove ricerche svelano la complessità geologica dello Stretto di Messina ingvterremoti.com/2026/02/17…
Andrea P retweeted
Bypassing Windows Administrator Protection projectzero.google/2026/26/w…
Andrea P retweeted
I’ve been a developer for 10 years.
I’ve mastered languages. I’ve optimized databases. I’ve built systems that handle millions of requests.
But last week, a Junior dev outperformed me.
He didn’t know how to write a complex program. He couldn’t explain the difference between a proper monoloth and a microservice. He didn't even know how the code worked in some parts.
But he knew how to talk to the Agents.
He orchestrated three AI workers. One for the frontend. One for the backend logic. One for the unit tests.
In 4 hours, he pushed a feature that would have taken me 3 days.
I felt a cold shiver. "Is this it?" I thought. "Am I finally the legacy hardware?"
But then I looked at his PR. It was fast. It was functional. But it was… fragile.
It lacked architectural vision. It had security holes that only someone who has been "burned" would see. It was a house built on sand.
That’s when I realized the truth about 2026.
The "Senior" title isn't about how fast you type anymore. It's about how well you judge.
We are moving from being "builders" to being "architects." From "coders" to "composers."
If you’re a veteran feeling left behind by AI: Don’t compete on speed. Compete on wisdom.
The machine can write the notes. Only you can write the symphony.
Andrea P retweeted
[RELEASE] As promised, I’m releasing the first blog post in a series. It covers the gaps still present in current stack-based telemetry and how Moonwalking can be extended to evade detection logic and reach “on-exec” memory encryption.
Enjoy ;)
klezvirus.github.io/posts/Mo…
Andrea P retweeted
Tourism Minister Daniela Santanchè posts an article by @annabelmaud from The Telegraph and suggests that a family moved to Italy to live a better life.
Too bad the full article says something completely different.
The post has been removed.
Nov 8, 2025
Andrea P retweeted
Italians still keep moving away from Italy. That’s one reason why youth unemployment improved over the last decade (there are just no young Italians left to be unemployed). Germany remains the top destination. HT @maps_interlude
Andrea P retweeted
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…