Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"

In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed “Dark Elevator”. But was it really fixed? Ask @tiraniddo projectzero.google/2026/09/w…
3
46
212
16,937
Finally got LocalKDC working on W11 insider, now let's see... 😅
4
2
70
4,042
Works also for loopback authentication
2
356
Andrea P retweeted
Been digging deep into the Windows Endpoint Security Platform (WESP) in Win11 25H2, definitely one of the most fascinating security features Microsoft has built in a while. The concept is neat: compile rules to decision graphs in user mode, hand them to wesp.sys, and let the kernel evaluate them in-path while telemetry streams asynchronously in the background. I did an AI-assisted reverse engineering dive into the whole stack (wesp.sys, espclient.dll, and wesp_elam.sys), documented the wire protocols, disposition tables, and the enforcement gate, and built esptool, a research harness with 118 XML rule docs so anyone can test live telemetry and in-kernel blocking. Repo: github.com/marcosd4h/wesp_re… Tech doc: github.com/marcosd4h/wesp-re… Thanks to @yarden_shafir for putting this on my radar
1
61
182
13,464
AI may eventually become the new Cold War: everyone keeps building more powerful systems because they can’t afford to let the other side get ahead. Chip manufacturers may become the equivalent of uranium supplier controlling access to the resource that makes the race possible
4
695
Andrea P retweeted
A new O'Reilly bestseller!
179
1,037
8,154
362,335
Super cool research from my colleague Shai Laron on new attack paths to Active Directory that can lead to full domain takeover 😜 . It was presented at Black Hat and he will be speaking again at DEF CON this weekend. Don't miss this 💪 : semperis.com/blog/identity-c…
1
77
219
10,629
Although this is a well-known topic, it's still one of my favorites. I put together a concise reference covering the most dangerous Windows privileges, how they can be abused, and why you should think twice before assigning them 👉 semperis.com/blog/windows-pr…
25
56
4,280
Turning an idea into something more concrete: importing vulnerable GPOs into Neo4j/BH and creating dedicated relationship edges to make GPO-based attack paths easier to visualize.
2
26
1,704
Andrea P retweeted
Regarding Active Directory permissions, most people assume that a Deny ACE always wins. It doesn't! Windows stops the access check the moment enough rights are granted — any ACE after that point is never evaluated. New post: managedpriv.com/blog/acl-can…
1
7
19
1,693
MSRC stories? I have several. One of the funniest: I submitted a vuln and was told it didn't meet the bar. Blogged about this finding. A few months later, someone else submitted the exact same vuln and suddenly it was confirmed, awarded a bounty, and assigned a CVE. 🤦‍♂️
6
30
320
19,092
I think a lot of people publishing 0-days for childish reasons are mostly chasing visibility.
19
1,939
Turns out that the fix for the CVE-2020-17103 , the Cloud Filter HsmOsBlockPlaceholderAccess driver bug reported by @tiraniddo was never ported to Windows 11 / Server 2025 and still not fixed. LPE from user to SYSTEM 🤦‍♂️
2
36
111
12,768
Server 2019 before patch (CVE-2020-17103 , december 8th 2020) is vulnerable, after patch not. The patch was ported on 2022 too
3
892
I published a new "security research" post, and for once, it’s not about Windows 😅 This time I took a look at the myAudi connected vehicle platform and its APIs..🤓 Curiosity drives security research, no matter the target Read it here 👇 decoder.cloud/2026/05/08/oh-…
2
11
29
4,242
Andrea P retweeted
Replying to @4ndr3w6S
@4ndr3w6S pulled me into this rabbit hole, and it was a fun one.
Took a break from LDAP, fell down the dMSA rabbit hole with @YuG0rd, and watched the snake eat its own tail. dMSA Ouroboros: self-sustaining credential extraction on patched Server 2025. Six commands. Survives attacker account deletion. huntress.com/blog/dmsa-ourob…
2
3
1,317
Andrea P retweeted
This second blogpost concludes @yaumn_'s research on #Windows authentication reflection. He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥 A little bonus is even included at the end 👀👇 synacktiv.com/en/publication…
2
56
124
12,154