IRON GIANT: When The Vault Becomes The Victim

Erik Egsgard

OffensiveCon 2026 · Day 2 · Main Stage

In the realm of Windows security, the Local Security Authority Subsystem Service, or **LSASS**, stands as a formidable guardian, often dubbed the "Iron Giant" for its critical role in managing authentication, credential storage, and policy enforcement. For years, the prevailing assumption within the security community has been that LSASS, holding the keys to the kingdom, is exceptionally well-hardened, its interfaces meticulously audited and largely impervious to novel attacks. Erik Egsgard, a Principal Security Developer at Field Effect, challenged this deeply ingrained belief in his OffensiveCon talk, "IRON GIANT: When The Vault Becomes The Victim," revealing a surprisingly vast and underexplored attack surface.

AI review

Egsgard went hunting in a target that the community collectively decided was already solved, and found five distinct bugs — two remote DoS chains, an unprivileged access-check bypass affecting domain controllers, and two heap corruption primitives in SSPs. That's original work with real CVE weight, presented at a conference that demands it. The live demo on a fully-patched box seals the credibility.

Watch on YouTube