DEF CON 34 — Workshops

Table of Contents

Source

Friday morning (09:00)

  • Offensive Packet Wizardry with Scapy — Mike "Chicolinux" Guirao — Intermediate/Advanced. Build offensive networking tools from scratch in Python using Scapy. Registration
  • Hands-on IoT firmware extraction and flash forensics — Dennis Giese, Braelynn Luedtke, Arnold Wey, Harsha Potu — Intermediate. Extract firmware from IoT devices via chip-off without expensive hardware.
  • AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover — zeta, Rafa "bane" Gutierrez — Intermediate. SSRF to admin via AWS IAM. Registration
  • Web Hacking 101 — cale "calebot" smith, Ruchik Dave, Young Seuk Kim, Luke Cycon — Beginner-Advanced. Progressive labs across modern web vulnerabilities.
  • Malware Development 101 - From Zero to Hero — Yoann "OtterHacker" DEQUEKER — Intermediate/Advanced. Develop C/C++ malware and adapt payloads to evade EDR. Registration
  • Long Live Empire: A C2 Workshop for Modern Red Teaming — Jake "Hubbl3" Krasnov, Vincent "Vinnybod" Rose, Anthony "Coin" Rose, Dan Niefeld — Beginner-Intermediate. Stand up Empire C2 team server and run post-exploitation. Registration
  • Learning to Hack Bluetooth Low Energy with BLE CTF — Ryan "Hackgnar" Holeman, Alek Amrani — Beginner-Intermediate. BLE device hacking via CTF challenges. Registration
  • Agentic Threat Hunting — Sydney "letswastetime" Marrone — Intermediate. Hunt supply-chain compromises in real telemetry using AI agents. Registration

Friday afternoon (14:00)

  • Investigating and Responding to M365 account compromise on a shoestring — Vince "bitpusher" Weppner — Intermediate. BEC investigation using native M365 tools. Registration
  • OT Systems: how to secure them in practice! — Alexandrine Torrents, Arnaud SOULLIE — Beginner-Intermediate. Hands-on ICS security. Registration
  • AWS Principal Threat Hunting — Rodrigo "Sp0oKeR" Montoro — Intermediate/Advanced. Behavioral baselines for AWS IAM anomalies. Registration
  • Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models — John "clearbluejar" McIntosh — Advanced. Reproduce 0-day discovery using local AI models and open-source pipelines. Registration
  • Solder, Detect, Listen: Build Your Own EMF Explorer — Darcy "@Drc3p0" Neal — Beginner. Surface-mount EMF listening device build. Registration
  • All About Stoopie InfoStealers — Ryan "@rj_chap" Chapman, Aaron "Ironical" Rosenmund — Intermediate/Advanced. Analyze and code infostealers with AI-driven tradecraft. Registration
  • Introduction to Malware Analysis — Sam Bowne, Elizabeth Biddlecome, Kaitlyn Handelman, Irvin Lemus — Beginner-Advanced. Windows executables + memory-corruption defenses. Registration
  • Embedded Computing Tools for Wireless Hardware Hacking — Joseph Long — Intermediate. Wi-Fi and Bluetooth experimentation with embedded HW ($60 kit required). Registration

Saturday morning (09:00)

  • Wi-Fight Club: I am Jack's Evil Twin — James Hawk, Jon "C4V3M4N" Milkins, Brian Burnett — Intermediate. Rogue-AP deployment with EAPHAMMER + HASHCAT. Registration
  • Explore the Windows instrumentation callback — Yoann "OtterHacker" DEQUEKER — Intermediate/Advanced. Weaponize Nirvana Debug for execution hijacking / EDR evasion. Registration
  • Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel — Yu Terada, Kotaro "@Decamark" Osugi — Intermediate/Advanced. Injection techniques + EDR bypass via C2 customization. Registration
  • Words As Weapons: Breaking AI and Agents; Then Securing Them — Pavan "pavanreddysec" Reddy — Intermediate. LLM attacks: prompt injection, data exfiltration. Registration
  • HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure — HackeMate — Intermediate. Intentionally vulnerable cloud labs across AWS/Azure/GCP. Registration
  • Hecate: A Trivial UART Tool — mx, Joe "SecurelyFitz" FitzPatrick, nyx — Intermediate. UART implants + in-flight data manipulation. Registration
  • Detecting and Analyzing Memory Only Malware with Volatility 3 — Andrew Case, Pierre "Abyss Watcher" Breton, David McDonald — Intermediate/Advanced. Memory forensics for sophisticated malware. Registration
  • Battle-Tested Broadcasts: RF Insights From Ukraine — Preston Zen — Intermediate/Advanced. RF detection + direction-finding with SDR tools (includes Signal Compass). Registration

Saturday afternoon (14:00)

  • Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices — wasabi, Ø1, Tokugero — Beginner. HID attacks with DuckyScript v3 + O.MG. Registration
  • Purple Teaming Industrial Control Systems — Arnaud SOULLIE, Alexandrine TORRENTS — Intermediate. Purple-team ICS via CALDERA. Registration
  • Entra ID Persistence - Because Passwords Were Never the Problem — Raunak "Trouble1" Parmar, Chirag "3xpl01tc0d3r" Savla — Intermediate/Advanced. Identity-layer backdoors in Entra. Registration
  • From Prompt to PWN: Exploiting LLM Powered Web Applications — Abhinav Verma — Intermediate. AI agents attacked via prompt injection + MCP tool-calling. Registration
  • Intro to Writing Windows Malware with Rust! — iDigitalFlame, Daniel Bravo — Intermediate/Advanced. Windows malware in Rust without std imports/API calls. Registration
  • Building Agentic Reverse Engineering "Skills" — John "clearbluejar" McIntosh — Intermediate/Advanced. Structured agent workflows for multi-platform driver analysis. Registration
  • Learning to Reverse Engineer Compiled C as We Learn to Write It — Wesley McGrew — Beginner-Intermediate. Disassembly + debugging alongside C fundamentals. Registration
  • Salesforce Apex Predator: Breaking Salesforce Sites — Nitay Bachrach, Cynthia Ardman — Intermediate/Advanced. Enumerate + exploit Salesforce Experience Sites (Aura, LWR). Registration

Sunday morning (09:00)

  • Attacking Cloud APIs from the IoT Edge — Rodney "BenevolentWorm" Beede — Intermediate. Extract + abuse cloud API creds from compromised IoT. Registration
  • Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more — Dallas — Beginner-Intermediate. ESP32-based kit assembly (free kit included). Registration
  • Post-Quantum Cryptography (PQC) for Hackers — Eric "Eijah" Anderson — Intermediate/Advanced. Implement NSA CNSA Suite 2.0 in C++/OpenSSL/Linux. Registration
  • Purple Protocol: Adversary emulation for everyone — Patrick "PilotPat" Raiden, Ben "Marba$" Strout, Brandon "D43m0n" Kraycirik — Beginner-Intermediate. TI-led purple-team engagements with OSS tools. Registration
  • CI/CD Weaponization: Build It, Deploy It, Own It — Ricardo Sanchez, Daniel Malvaceda — Intermediate/Advanced. End-to-end GitHub Actions attack chains in a controlled lab. Registration

Not detailed on source page (placeholders)

  • ICS Hack 'n Track
  • Creating Shellcode for Hackers
  • Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams

Adjacencies to current work

  • Agentic Threat Hunting (Marrone), Reaching Mythos (McIntosh), Words As Weapons (Reddy), From Prompt to PWN (Verma), Building Agentic RE Skills (McIntosh), All About Stoopie InfoStealers (Chapman/Rosenmund) — all overlap the AI-in-security thread; cross-link once slides drop.
  • Battle-Tested Broadcasts (Zen) — SDR/RF; adjacent to ADS-B / aviation-sdr crawler category.
  • Post-Quantum Cryptography for Hackers (Anderson) — pairs with the reversible-pipeline / crypto notes.

TODO

  • [ ] Confirm room assignments once posted.
  • [ ] Pick top-3 workshop lottery preferences before July 14, 2026 12:00 PT.
  • [ ] Cross-link agent-tooling workshops to agentic-systems notes.