Uploaded August 2026 | Updated September 2026, 3 weeks ago
For years, macOS researchers have focused on high-privilege system and user domain services—yet a vast class of background daemons has quietly operated beneath the radar: PID-domain services. These processes, often reachable even from sandboxed apps, expose privileged functionality and sensitive system controls. Despite their enormous attack surface, they've remained largely unexplored and unprotected—until now.
In this Briefing, we will unveil the first large-scale automated framework for discovering logic vulnerabilities in PID-domain services, powered by LLM-assisted static analysis. We will start by dissecting historical flaws and Apple's patching patterns to formalize a repeatable attack model. Building on that foundation, our framework automatically enumerates connectable PID-domain daemons, decompiles their exported APIs, and leverages LLM semantic reasoning to classify sensitive operations across five categories—from file and privacy access to interprocess privilege crossing. We then map entitlements to these operations and apply taint analysis to trace attacker-controlled data into privileged sinks—surfacing hidden logic flaws that manual auditing would almost certainly miss.
Our evaluation uncovered 12 previously unknown vulnerabilities, including multiple sandbox escapes and TCC privacy bypasses—six of which have already been assigned CVEs by Apple. This research exposes a massive, underestimated attack surface within macOS's userspace and demonstrates how LLMs can be weaponized for scalable vulnerability discovery in closed-source ecosystems. Attendees will gain new insights into Apple's userspace attack surface, automated bug-hunting methodologies, and the next frontier of human–AI collaboration in exploit development.
l_m_h l_m_h | Independent Security Researcher
Yinyi Wu | Security Researcher, Dawn Security Lab, JD.com
Yingqi Shi | Security Researcher, DBAPPSecurity
Yuchong Xie | Security Researcher, The Hong Kong University of Science and Technology
Cheng Li | Security Researcher
Yizhuo Wang | Security Researcher
blackhat.com/asia-26/briefings/schedule/?#ai-in-the-loop-large-scale-macos-pid-domain-vulnerability-discovery-with-llm-reasoning-on-demand-only-50233
For years, macOS researchers have focused on high-privilege system and user domain services—yet a vast class of background daemons has quietly operated beneath the radar: PID-domain services. These processes, often reachable even from sandboxed apps, expose privileged functionality and sensitive system controls. Despite their enormous attack surface, they've remained largely unexplored and unprotected—until now.
In this Briefing, we will unveil the first large-scale automated framework for discovering logic vulnerabilities in PID-domain services, powered by LLM-assisted static analysis. We will start by dissecting historical flaws and Apple's patching patterns to formalize a repeatable attack model. Building on that foundation, our framework automatically enumerates connectable PID-domain daemons, decompiles their exported APIs, and leverages LLM semantic reasoning to classify sensitive operations across five categories—from file and privacy access to interprocess privilege crossing. We then map entitlements to these operations and apply taint analysis to trace attacker-controlled data into privileged sinks—surfacing hidden logic flaws that manual auditing would almost certainly miss.
Our evaluation uncovered 12 previously unknown vulnerabilities, including multiple sandbox escapes and TCC privacy bypasses—six of which have already been assigned CVEs by Apple. This research exposes a massive, underestimated attack surface within macOS's userspace and demonstrates how LLMs can be weaponized for scalable vulnerability discovery in closed-source ecosystems. Attendees will gain new insights into Apple's userspace attack surface, automated bug-hunting methodologies, and the next frontier of human–AI collaboration in exploit development.
l_m_h l_m_h | Independent Security Researcher
Yinyi Wu | Security Researcher, Dawn Security Lab, JD.com
Yingqi Shi | Security Researcher, DBAPPSecurity
Yuchong Xie | Security Researcher, The Hong Kong University of Science and Technology
Cheng Li | Security Researcher
Yizhuo Wang | Security Researcher
blackhat.com/asia-26/briefings/schedule/?#ai-in-the-loop-large-scale-macos-pid-domain-vulnerability-discovery-with-llm-reasoning-on-demand-only-50233


![Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)
Event Tracing for Windows (ETW) is a built-in Windows logging and tracing framework that collects system and application events, providing detailed visibility into whats happening on a machine. In security, ETW is widely leveraged as one of the key telemetry sources for modern Endpoint Detection and Response (EDR) products because of the wealth of data it provides.
This trace data is generated by components known as providers. While four types exist—Managed Object Format (MOF), Windows software trace preprocessor (WPP), Manifest-based, and TraceLogging—Microsoft generally recommends using the two modern variants: Manifest-based and TraceLogging providers [1].
However, a significant knowledge gap exists. While Manifest-based providers are relatively well-understood [2], information regarding TraceLogging providers remains scarce. Consequently, it is questionable whether the security community is truly maximizing ETWs full potential.
To bridge this gap and enable defenders to better leverage ETW, we will present our findings on TraceLogging providers in the latest Windows. We will cover how to work with them, highlight providers potentially useful for security (e.g., AttackSurfaceMonitor), and walk through practical use cases.
Asuka Nakajima | Senior Security Research Engineer, Elastic
https://blackhat.com/asia-26/briefings/schedule/?#hidden-telemetry-uncovering-tracelogging-etw-providers-youre-not-using-yet-51991 Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)](https://i.ytimg.com/vi/ubFcs1M62P4/mqdefault.jpg)







