DEF CON 34 — Workshops
- Offensive Packet Wizardry with Scapy — Mike "Chicolinux" Guirao — Intermediate/Advanced. Build offensive networking tools from scratch in Python using Scapy. Registration
- Hands-on IoT firmware extraction and flash forensics — Dennis Giese, Braelynn Luedtke, Arnold Wey, Harsha Potu — Intermediate. Extract firmware from IoT devices via chip-off without expensive hardware.
- AWS Cloud Security 101: From IAM Misconfigurations to Account Takeover — zeta, Rafa "bane" Gutierrez — Intermediate. SSRF to admin via AWS IAM. Registration
- Web Hacking 101 — cale "calebot" smith, Ruchik Dave, Young Seuk Kim, Luke Cycon — Beginner-Advanced. Progressive labs across modern web vulnerabilities.
- Malware Development 101 - From Zero to Hero — Yoann "OtterHacker" DEQUEKER — Intermediate/Advanced. Develop C/C++ malware and adapt payloads to evade EDR. Registration
- Long Live Empire: A C2 Workshop for Modern Red Teaming — Jake "Hubbl3" Krasnov, Vincent "Vinnybod" Rose, Anthony "Coin" Rose, Dan Niefeld — Beginner-Intermediate. Stand up Empire C2 team server and run post-exploitation. Registration
- Learning to Hack Bluetooth Low Energy with BLE CTF — Ryan "Hackgnar" Holeman, Alek Amrani — Beginner-Intermediate. BLE device hacking via CTF challenges. Registration
- Agentic Threat Hunting — Sydney "letswastetime" Marrone — Intermediate. Hunt supply-chain compromises in real telemetry using AI agents. Registration
- Investigating and Responding to M365 account compromise on a shoestring — Vince "bitpusher" Weppner — Intermediate. BEC investigation using native M365 tools. Registration
- OT Systems: how to secure them in practice! — Alexandrine Torrents, Arnaud SOULLIE — Beginner-Intermediate. Hands-on ICS security. Registration
- AWS Principal Threat Hunting — Rodrigo "Sp0oKeR" Montoro — Intermediate/Advanced. Behavioral baselines for AWS IAM anomalies. Registration
- Reaching Mythos: Hands-On Vulnerability Discovery with Local AI Models — John "clearbluejar" McIntosh — Advanced. Reproduce 0-day discovery using local AI models and open-source pipelines. Registration
- Solder, Detect, Listen: Build Your Own EMF Explorer — Darcy "@Drc3p0" Neal — Beginner. Surface-mount EMF listening device build. Registration
- All About Stoopie InfoStealers — Ryan "@rj_chap" Chapman, Aaron "Ironical" Rosenmund — Intermediate/Advanced. Analyze and code infostealers with AI-driven tradecraft. Registration
- Introduction to Malware Analysis — Sam Bowne, Elizabeth Biddlecome, Kaitlyn Handelman, Irvin Lemus — Beginner-Advanced. Windows executables + memory-corruption defenses. Registration
- Embedded Computing Tools for Wireless Hardware Hacking — Joseph Long — Intermediate. Wi-Fi and Bluetooth experimentation with embedded HW ($60 kit required). Registration
- Wi-Fight Club: I am Jack's Evil Twin — James Hawk, Jon "C4V3M4N" Milkins, Brian Burnett — Intermediate. Rogue-AP deployment with EAPHAMMER + HASHCAT. Registration
- Explore the Windows instrumentation callback — Yoann "OtterHacker" DEQUEKER — Intermediate/Advanced. Weaponize Nirvana Debug for execution hijacking / EDR evasion. Registration
- Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel — Yu Terada, Kotaro "@Decamark" Osugi — Intermediate/Advanced. Injection techniques + EDR bypass via C2 customization. Registration
- Words As Weapons: Breaking AI and Agents; Then Securing Them — Pavan "pavanreddysec" Reddy — Intermediate. LLM attacks: prompt injection, data exfiltration. Registration
- HackTheCloud26: Chaining Cloud Misconfigurations to Compromise Infrastructure — HackeMate — Intermediate. Intentionally vulnerable cloud labs across AWS/Azure/GCP. Registration
- Hecate: A Trivial UART Tool — mx, Joe "SecurelyFitz" FitzPatrick, nyx — Intermediate. UART implants + in-flight data manipulation. Registration
- Detecting and Analyzing Memory Only Malware with Volatility 3 — Andrew Case, Pierre "Abyss Watcher" Breton, David McDonald — Intermediate/Advanced. Memory forensics for sophisticated malware. Registration
- Battle-Tested Broadcasts: RF Insights From Ukraine — Preston Zen — Intermediate/Advanced. RF detection + direction-finding with SDR tools (includes Signal Compass). Registration
- Hands-on DuckyScript: An Introduction to HID Attack Tools with O.MG Devices — wasabi, Ø1, Tokugero — Beginner. HID attacks with DuckyScript v3 + O.MG. Registration
- Purple Teaming Industrial Control Systems — Arnaud SOULLIE, Alexandrine TORRENTS — Intermediate. Purple-team ICS via CALDERA. Registration
- Entra ID Persistence - Because Passwords Were Never the Problem — Raunak "Trouble1" Parmar, Chirag "3xpl01tc0d3r" Savla — Intermediate/Advanced. Identity-layer backdoors in Entra. Registration
- From Prompt to PWN: Exploiting LLM Powered Web Applications — Abhinav Verma — Intermediate. AI agents attacked via prompt injection + MCP tool-calling. Registration
- Intro to Writing Windows Malware with Rust! — iDigitalFlame, Daniel Bravo — Intermediate/Advanced. Windows malware in Rust without std imports/API calls. Registration
- Building Agentic Reverse Engineering "Skills" — John "clearbluejar" McIntosh — Intermediate/Advanced. Structured agent workflows for multi-platform driver analysis. Registration
- Learning to Reverse Engineer Compiled C as We Learn to Write It — Wesley McGrew — Beginner-Intermediate. Disassembly + debugging alongside C fundamentals. Registration
- Salesforce Apex Predator: Breaking Salesforce Sites — Nitay Bachrach, Cynthia Ardman — Intermediate/Advanced. Enumerate + exploit Salesforce Experience Sites (Aura, LWR). Registration
- Attacking Cloud APIs from the IoT Edge — Rodney "BenevolentWorm" Beede — Intermediate. Extract + abuse cloud API creds from compromised IoT. Registration
- Building your own hardware hacking kit to Pentest Bluetooth, WIFI, and more — Dallas — Beginner-Intermediate. ESP32-based kit assembly (free kit included). Registration
- Post-Quantum Cryptography (PQC) for Hackers — Eric "Eijah" Anderson — Intermediate/Advanced. Implement NSA CNSA Suite 2.0 in C++/OpenSSL/Linux. Registration
- Purple Protocol: Adversary emulation for everyone — Patrick "PilotPat" Raiden, Ben "Marba$" Strout, Brandon "D43m0n" Kraycirik — Beginner-Intermediate. TI-led purple-team engagements with OSS tools. Registration
- CI/CD Weaponization: Build It, Deploy It, Own It — Ricardo Sanchez, Daniel Malvaceda — Intermediate/Advanced. End-to-end GitHub Actions attack chains in a controlled lab. Registration
- ICS Hack 'n Track
- Creating Shellcode for Hackers
- Pivot, Hunt, Publish: An Offline, Hands-On CTI Workshop for Blue Teams
- Agentic Threat Hunting (Marrone), Reaching Mythos (McIntosh), Words As Weapons (Reddy), From Prompt to PWN (Verma), Building Agentic RE Skills (McIntosh), All About Stoopie InfoStealers (Chapman/Rosenmund) — all overlap the AI-in-security thread; cross-link once slides drop.
- Battle-Tested Broadcasts (Zen) — SDR/RF; adjacent to ADS-B / aviation-sdr crawler category.
- Post-Quantum Cryptography for Hackers (Anderson) — pairs with the reversible-pipeline / crypto notes.
[ ] Confirm room assignments once posted.
[ ] Pick top-3 workshop lottery preferences before July 14, 2026 12:00 PT.
[ ] Cross-link agent-tooling workshops to agentic-systems notes.