Log inSign up
Antonio Cocomazzi
1,815 posts
@splinter_code

Antonio Cocomazzi

@splinter_code
offensive security - windows internals | BlueSky: bsky.app/profile/splint… | Mastodon: infosec.exchange/@splinter_code
Italy
splintercod3.blogspot.com
Joined August 2016
324
Following
9,357
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @splinter_code
    Antonio Cocomazzi
    @splinter_code
    Nov 3, 2023
    The slides of our joint research talk “10 Years of Windows Privilege Escalation with Potatoes” at #POC2023 are out! 👉 github.com/antonioCoco/in… cc @decoder_it
    Image
    4
  • @splinter_code
    Antonio Cocomazzi
    @splinter_code
    Sep 10, 2025
    I’m hiring Staff Windows Security Researchers to join my XAT (eXploits and Anti-Tampering) team at @SentinelOne! 🔥 👉 sentinelone.com/jobs/?gh_jid=6… More details 👇
    1
  • @splinter_code
    Antonio Cocomazzi
    @splinter_code
    Jan 29, 2025
    Very interesting post by Microsoft about the internals of the new Admin Protection feature It seems they have patched my SSPI UAC bypass based on NTLM as well as the Kerberos UAC bypass in which both were able to bypass AP as well More details here 👇
    Image
    Evolving the Windows User Model – Introducing Administrator Protection | Microsoft Community Hub
    From techcommunity.microsoft.com
    2
  • @splinter_code
    Antonio Cocomazzi
    @splinter_code
    Dec 20, 2024
    Nice catch 👇 A good bypass for abusing the SeLoadDriverPrivilege from a non-admin user (in case of a misconfig)
    @sixtyvividtails
    sixtyvividtails
    @sixtyvividtails
    Dec 19, 2024
    Looks like this mitigation was added in 1803, build 17134. It would be sad 😸 if someone would seamlessly 𝐛𝐫𝐞𝐚𝐤 𝐢𝐭 via user-writeable subkeys under the "\Registry\Machine". Like, you know, HKLM\System\CurrentControlSet\Control\Nsi\{eb004a1c-9b1a-11d4-9123-0050047759bc}\0.
  • @splinter_code
    Antonio Cocomazzi
    @splinter_code
    Nov 28, 2024
    Then ask about the difference between Sysinternals vs impacket psexec
    @HackingLZ
    Justin Elze
    @HackingLZ
    Nov 28, 2024
    “Know your tools” Pick 10 random infosec people and ask psexec works under the hood
Advertisement
Advertisement