Talk

Reflecting Your Authentication: Look in the Mirror – It’s You

March 20, 11:30 (CLOUD)

Authentication reflection was long considered a solved problem after MS08-068 closed the classic NTLM loopback path. However, in 2025 multiple independent discoveries, including mines, demonstrated that Windows still contains several reliable ways to coerce a machine into authenticating to its own services.


This talk presents the modern landscape of Windows authentication reflection and shows how recent implementation behaviors, protocol inconsistencies, and overlooked coercion paths have reintroduced privilege-escalation vectors that were believed dead for more than a decade. The research covers Kerberos reflection via SPN manipulation, Ghost SPN exploitation, NTLM local-auth quirks, and also cases where a single reflected authentication was enough to compromise the Active Directory domain.


The goal is to make the topic accessible even for attendees who are not deep experts in Windows internals, while still providing enough technical depth for protocol researchers and red team professionals. The talk explains why reflection keeps surviving across patch cycles, why existing mitigations sometimes fail, and what defenders need to do to harden their environments.


I will also disclose a new reflection attack discovered by me in July 2025, which Microsoft has internally confirmed and marked critical. The fix is currently planned for January 2026.

Speaker

Andrea Pierini

I’m a Senior Security Consultant at Semperis, with deep experience across nearly every layer of IT, from software development to system and network administration, and ultimately security. I’m passionate about both offensive and defensive security, and my research focuses on uncovering overlooked authentication paths, protocol inconsistencies, and privilege-escalation techniques in modern Windows environments.

I consider myself an IT security enthusiast who enjoys exploring emerging technologies, hunting bugs, and sharing knowledge through writing, speaking, and public research. Over the years, I’ve presented at various national and international conferences and published several CVEs. In 2020 and 2022, I was recognized by Microsoft as one of the Top 100 Most Valuable MSRC Security Researchers.

https://decoder.cloud

@decoder_it

www.linkedin.com/in/andrea-pierini

Organized by

Technology partners

Partner events

Scroll to Top