<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft on Simon Maxwell-Stewart</title><link>https://kidtronnix.com/tags/microsoft/</link><description>Recent content in Microsoft on Simon Maxwell-Stewart</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 28 May 2026 11:00:00 -0800</lastBuildDate><atom:link href="https://kidtronnix.com/tags/microsoft/index.xml" rel="self" type="application/rss+xml"/><item><title>Troopers 2026</title><link>https://kidtronnix.com/post/troopers-2026/</link><pubDate>Thu, 28 May 2026 11:00:00 -0800</pubDate><guid>https://kidtronnix.com/post/troopers-2026/</guid><description>&lt;img src="https://cdn12.picryl.com/photo/2016/12/31/stormtrooper-star-wars-lego-dfb382-1024.jpg" alt="Featured image of post Troopers 2026" />&lt;p>I&amp;rsquo;m super excited to be speaking at &lt;a class="link" href="https://troopers.de/troopers26/talks/3retq9/" target="_blank" rel="noopener"
>Troopers 2026&lt;/a>, June 24th - 26th.&lt;/p>
&lt;h2 id="popping-microsofts-sandbox">Popping Microsoft&amp;rsquo;s Sandbox
&lt;/h2>&lt;h3 id="what-falls-out-of-a-dataverse-container">What Falls Out of a Dataverse Container
&lt;/h3>&lt;p>Microsoft Dataverse runs customer code inside process-isolated containers that are supposed to keep tenants safely separated. In this talk I&amp;rsquo;ll share research from BeyondTrust&amp;rsquo;s Phantom Labs where we deployed a custom .NET plugin into the sandbox and walked out with system credentials, cryptographic keys, proprietary DLLs, and customer data.&lt;/p>
&lt;p>By decompiling ~14,000 C# source files we reverse-engineered the internal gRPC protocol, documented 27 unauthenticated methods across three services, and explored what cross-tenant code execution actually looks like in practice.&lt;/p>
&lt;h3 id="details">Details
&lt;/h3>&lt;p>What we&amp;rsquo;ll cover:&lt;/p>
&lt;ul>
&lt;li>Standard Dataverse plugin deployment mechanics&lt;/li>
&lt;li>Escalation to SYSTEM privileges via a single command&lt;/li>
&lt;li>Extraction of LSASS dumps, registry hives, and process memory (400+ MB total)&lt;/li>
&lt;li>Recovery of production TLS private keys and 52 customer organization identifiers&lt;/li>
&lt;li>gRPC protocol analysis and custom tooling development&lt;/li>
&lt;li>Cross-tenant execution scenarios and their limitations&lt;/li>
&lt;li>Sandbox defense mechanisms that succeeded versus those that failed&lt;/li>
&lt;li>Disclosure timeline and Microsoft&amp;rsquo;s response&lt;/li>
&lt;/ul></description></item></channel></rss>