Subverting the Windows Kernel: Juan Sacco's Research Presented at BruCON 2026

At BruCON 2026, the principal developer of Exploit Pack, Juan Sacco, presented Subverting the Windows Kernel: When VBS, HVCI and kCET Are Enabled, a research talk exploring the limitations of modern Windows kernel security mechanisms.

The presentation focused on how kernel exploitation continues to evolve as Microsoft introduces increasingly sophisticated protections, and how existing assumptions about kernel security can be challenged by vulnerabilities in trusted components.

Beyond Traditional Kernel Exploitation

Modern Windows systems incorporate multiple layers of protection designed to prevent unauthorized kernel execution. Virtualization-Based Security (VBS), Hypervisor-Protected Code Integrity (HVCI) and Kernel-mode Control-flow Enforcement Technology (kCET) significantly change the landscape for vulnerability researchers.

Juan's research explored what happens when traditional exploitation techniques encounter these defenses and why restricting executable memory alone does not eliminate every avenue of kernel compromise.

The research investigated alternative approaches involving existing kernel functionality and the operating system's internal structures.

Exploring Multiple Kernel Attack Surfaces

The presentation covered several areas of Windows kernel internals, examining how different architectural components behave under modern security protections.

Among the subjects explored were:

  • Memory and kernel access: The security implications of vulnerable, signed drivers and the access they can expose.
  • Processor-specific mechanisms: Research into the role of model-specific registers and their relationship with kernel execution.
  • System service dispatch: An examination of the native and graphical system service tables and their security implications.
  • Interrupt and descriptor tables: Research into the security properties of the Interrupt Descriptor Table (IDT) and Global Descriptor Table (GDT).
  • Control-flow protections: An analysis of the limitations and effectiveness of modern defenses against different classes of kernel exploitation.

Together, these subjects provided a broader perspective on the relationship between Windows internals, kernel integrity and the assumptions underlying modern security mitigations.

Live Demonstrations and Research Findings

A big part of Juan's presentation consisted of live demonstrations and practical research findings.

During the session, Juan and the attendees examined how different exploitation approaches behave under varying security configurations, including systems with VBS, HVCI and kCET enabled.

The demonstrations illustrated the differences between traditional code-execution techniques and approaches that leverage existing kernel functionality. They also highlighted how the interaction between multiple security mechanisms can affect exploitation.

The research included several proof-of-concept demonstrations and case studies developed as part of Juan's investigation.

Implications for Security Research

The findings presented at BruCON have broader implications for vulnerability researchers, kernel developers and security teams working with Windows environments.

They demonstrate the importance of continuously reassessing security assumptions as operating systems evolve. They also highlight the value of low-level research in understanding the boundaries of existing security protections.

For defenders, the research reinforces the importance of controlling vulnerable drivers, monitoring sensitive kernel operations and combining multiple layers of detection.

Continuing Our Research

At Exploit Pack, we’re constantly exploring Windows internals, vulnerability research and exploit development. Juan’s presentation at BruCON is a reflection of that ongoing work and our interest in understanding how modern Windows security mechanisms can be challenged.

This research also contributes to the development of our tools and helps us explore new approaches to exploit development.

Interested in learning more? Explore our Windows Kernel Exploitation Trainings, covering everything from the fundamentals to advanced techniques, with a focus on practical, hands-on learning.

You can also find more technical articles and research on our Exploit Pack Technical Blog.

 

Back to blog