Andrea Brancaleoni

Andrea Brancaleoni

About

Detail

Staff Security Engineer @ Brave Software
United States

Timeline


work
Job
school
Education
folder
Project

Résumé


Jobs verified_user 0% verified
  • Brave
    Senior Security Engineer
    Brave
    Oct 2021 - Current (5 years)
  • freelance
    Freelance Security Engineer
    freelance
    Nov 2018 - Current (7 years 11 months)
  • Doyensec
    Security Researcher & Penetration Tester
    Doyensec
    Nov 2018 - Oct 2021 (3 years)
  • Famoco
    OS Security Engineer
    Famoco
    Nov 2017 - Oct 2018 (1 year)
  • Cleafy
    Software Engineer
    Cleafy
    Oct 2015 - Nov 2017 (2 years 2 months)
  • Politecnico Di Milano
    Software Engineering 2 Assistant
    Politecnico Di Milano
    Sep 2015 - Feb 2016 (6 months)
    I managed the workflow for the course students. Moreover, I advise and help during the lessons.
Education verified_user 0% verified
  • Politecnico Di Milano
    Master's degree, Computer Engineering
    Politecnico Di Milano
    Jan 2013 - Dec 2016 (4 years)
    Computer Engineering Master Degree
  • Politecnico Di Milano
    Bachelor's degree, Information Technology
    Politecnico Di Milano
    Jan 2009 - Dec 2012 (4 years)
Projects (professional or personal) verified_user 0% verified
  • I
    InQL: GraphQL Scanner
    Sep 2019 - Current (7 years 1 month)
    GraphQL Introspection Scanner, is a Burp and Stand-alone recon interface for GraphQL endpoints.
  • C
    CVE-2019-12384
    Jul 2019
    Jackson Gadget leads to RCE
  • t
    tHYPon: Hypervisor Less Secure Reference Monitor
    Jan 2016 - Apr 2017 (1 year 4 months)
    Userspace software fault mechanisms increasingly depend on kernel space security mechanisms that extend DAC (Discretionary Access Control). These mechanisms have been targeted and exposed by various Linux kernel vulnerabilities, such as Mempodipper (CVE-2012-0056) or {get,put}_user on ARM (CVE-2013-6282). Currently, hardware IOMMU (Input/Output Memory Management Unit) mitigates hardware-based side channel attacks that target the kernel memory, however, IOMMU cannot mitigate vulnerabilities introduced by software developers in device drivers. Moreover, it is not practical to guarantee the security of the Linux kernel with formal methods given the big trusted computing base. The aim of this thesis is to extrude the kernel Reference Monitor in
This is a community-created genome.