Creator Events List

List of Events presented by Creators ( Villages, Communities, etc)

Creator Events Short Table



.edu Community Mixer

Creator Event Map Page – LVCCW Level 1 Hall 4 1418 (.EDU Community)
When:  Friday, Aug 7, 17:00 – 17:59 PDT

Creator: .EDU Community



“Can it Ham” Antenna Testing

Creator Event Map Page – LVCCW Level 3 Balcony
When:  Sunday, Aug 9, 10:00 – 11:30 PDT

Creator: Ham Radio Village

Come check out the Can it Ham Final testing — the best antennas get exposed to real world conditions to see just how well they radiate. Additional points will be awarded based on performance to truly determine…can it ham?

Come check out the Can it Ham Final testing


People:
    SpeakerBio:  The HRV Contest Team
No BIO available



2027 SECVC Pre-Qualification Round – LIVE CALLS

Creator Event Map Page – LVCCW Level 3 W317-319 (Social Engineering Community Village)
When:  Sunday, Aug 9, 10:30 – 11:30 PDT

Creator: Social Engineering Community Village

The top five scoring teams from the SECVC Pre-Qual Lab will return to the village to put their research and pretexts into action through live vishing calls. Based on their performance, some teams may earn a spot in the 2027 Social Engineering Community Vishing Competition.




2027 SECVC Pre-Qualification Round

Creator Event Map Page – LVCCW Level 3 W320 (Social Engineering Community Village Labs)
When:  Saturday, Aug 8, 15:30 – 17:30 PDT

Creator: Social Engineering Community Village

Think you have what it takes to compete in the 2027 Social Engineering Community Vishing Competition? This first-come, first-served SECVC Pre-Qual event gives attendees an early opportunity to qualify for next year�s competition. Note teams consist of 1 or 2 memebers. During the lab, each team will be assigned a target company and receive instructions, guidance, and dedicated Q&A time with SEC founders JC and Snow. Teams will conduct OSINT on their assigned company, develop potential pretexts, and prepare a short submission using a link provided before the lab closes. The top five teams will be selected and notified by email before 8:00 PM that evening. Those teams will advance to the live-call qualification round in the village on Sunday, August 9, 2026. Following the live calls, up to all five teams will earn a spot in the 2027 SEC Vishing Competition. Participants should bring a laptop or another device with internet access that can be used to conduct OSINT and submit their materials.


People:
    SpeakerBio:  JC, President at Snowfensive

JC is a U.S. Marine Corps veteran, President of Snowfensive, and co-founder of the Social Engineering Community Village at DEF CON. With more than a decade of experience spanning information technology, digital forensics, incident response, penetration testing, and social engineering, he specializes in turning complex security concepts into practical skills people can immediately apply.

At Snowfensive, JC oversees the company’s offensive security services, including phishing, vishing, physical social engineering, covert entry assessments, and technical penetration testing across networks, wireless environments, and applications. He has designed and led human-focused security engagements for organizations across a wide range of industries, combining technical tradecraft with a practical understanding of how people, processes, and technology intersect.

SpeakerBio:  Snow
No BIO available



3d Designing basics, 5 minute prints in Tinkercad

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Sunday, Aug 9, 11:00 – 11:59 PDT

Creator: Maker’s Village

Basic designing tools and functions in tinkercad by customizing your own 5 minute prints. Please sign up for tinkercad in advance.


People:
    SpeakerBio:  hunny
No BIO available



A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure

Creator Event Map Page – LVCCW Level 3 W321 (Telecom Village)
When:  Friday, Aug 7, 10:20 – 10:59 PDT

Creator: Telecom Village
  1. Understand the 5G SA attack surface from an attacker’s perspective
  2. Execute protocol-specific attacks against a live 5G core
  3. Map attack techniques to MITRE FiGHT with defensive context

People:
    SpeakerBio:  Siva Sareddu
No BIO available
SpeakerBio:  T -Mobile CTF Team
No BIO available



A 5G Digital Twin CTF for Hacking Carrier-Grade Infrastructure

Creator Event Map Page – LVCCW Level 3 W321 (Telecom Village)
When:  Saturday, Aug 8, 10:00 – 10:59 PDT

Creator: Telecom Village
  1. Understand the 5G SA attack surface from an attacker’s perspective
  2. Execute protocol-specific attacks against a live 5G core
  3. Map attack techniques to MITRE FiGHT with defensive context

People:
    SpeakerBio:  T -Mobile CTF Team
No BIO available



Ace/Aro Meetup

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Saturday, Aug 8, 13:00 – 13:59 PDT

Creator: Queercon Community



Adversary Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 11:10 – 11:20 PDT

Creator: The Diana Initiative

Interested in visiting Adversary Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Adversary Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Aegis of the Vulnerable: A Unified Pipeline for AI-Based SAST

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Friday, Aug 7, 11:30 – 12:30 PDT

Creator: AppSec Village

Aegis is an open-source, multi-model SAST framework. It analyzes source code for security vulnerabilities using a panel of models instead of a single one. The same scan can run HuggingFace classifiers (CodeBERT, VulBERTa), cloud LLMs (Claude, GPT, Gemini, DeepSeek, Qwen), local models through Ollama, agentic Claude Code, and classical machine learning estimators side by side. The architecture is provider-agnostic, so models are interchangeable and new ones can be added without changing the pipeline. Each model scans the code independently and reports what it finds. A consensus engine then combines those results into a single set of findings. Five consensus strategies are available: union, majority vote, weighted vote, judge, and cascade. This lets you control how strict the agreement has to be. Combining models this way lowers false positives compared to any single model and shows which models supported each finding. Results are exported as CWE-tagged SARIF, CSV, or JSON.


People:
    SpeakerBio:  Can Oztas

Can Oztas is a security researcher with applied R&D experience across several key sectors, including defense, finance, and telecommunications. His background encompasses AppSec, vulnerability research, and offensive security engineering. He is currently a PhD student focusing on the intersection of Artificial Intelligence and cybersecurity.




Aerospace Ecosystem Resilience Innovation Environment (AERIE) Cyber Range

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Aerospace Village
Jump into the AERIE Cyber Range to experience a number of challenges:

• PCD (Portable Cockpit Demonstrator): Attempt an RNAV approach in a simulated general aviation flight deck to your cleared runway in instrument conditions. • CCD (Cockpit Cyber Demonstrator): Fly a set of flight challenges in a simulated narrow-body airliner flight deck while managing cyber effects in the aircraft. • Virtual Tower and TRACON: Use the approach control position and an out-the-window tower view to coordinate with the PCD and CCD to help resolve the cyber scenarios running at each. • Horizon: Take the mission-controller seat for a virtual CubeSat remote-sensing mission. Run an imaging pass in the same world, at the same time, as the scenarios at the other stations. • AirVE: Watch the aircraft cyber range provide the aircraft-network model and the injected attacks behind the cyber effects the crew is managing at the cockpit stations. • OrbitVE: Watch the orbital cyber range provide satellite-constellation modeling behind the scenarios at every other station.




Aerospace Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 13:30 – 13:40 PDT

Creator: The Diana Initiative

Interested in visiting Aerospace Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Aerospace Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



AI finds and writes my Android exploits now

Creator Event Map Page – LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)
When:  Friday, Aug 7, 11:00 – 11:59 PDT

Creator: Mobile Hacking Community

For years, Ken has found and written exploits for Android which ended up winning multiple Pwn2Own competitions. This year, he hasn’t found or written a single exploit. Instead, AI does everything now, from reconnaissance to exploitation to writing bug bounty reports. This is thanks to the AI mobile testing tool, Djini, and the new feature that Ken helped program, called “Deep Scan”. Thanks to “Deep Scan”, Pwn2Own-level exploits can now be found autonomously. Ken will demonstrate the “Deep Scan” feature on stage, and talk about some of the various exploits that were found thanks to this feature.


People:
    SpeakerBio:  Ken Gannon / 伊藤 剣, Mobile Hacking Lab
No BIO available



AI Pentesting Trivia Showdown

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2
When:  Friday, Aug 7, 13:00 – 14:59 PDT

Creator: AppSec Village

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.


People:
    SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  Bill Reyor
No BIO available



AI Pentesting Trivia Showdown

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2
When:  Friday, Aug 7, 15:00 – 16:59 PDT

Creator: AppSec Village

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.


People:
    SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  Bill Reyor
No BIO available



AI Pentesting Trivia Showdown

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3
When:  Saturday, Aug 8, 13:00 – 14:59 PDT

Creator: AppSec Village

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.


People:
    SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  Bill Reyor
No BIO available



AI Pentesting Trivia Showdown

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3
When:  Saturday, Aug 8, 15:00 – 16:59 PDT

Creator: AppSec Village

Think you know AI pentesting? Put it to the test at this fast-paced, interactive trivia session at AppSec Village. AI Pentesting Trivia Showdown challenges participants with questions spanning offensive security fundamentals, real-world attack paths, AI-assisted testing concepts, vulnerability validation, and modern application security practices. Designed for practitioners of all experience levels, the game blends learning with competition in a format that is approachable, engaging, and fun to watch or join. Attendees will sharpen their understanding of how AI is changing penetration testing, pick up practical security insights, and leave with a stronger grasp of modern offensive techniques and terminology.


People:
    SpeakerBio:  Andy Dennis, Head of Field Engineering at XBOW
No BIO available
SpeakerBio:  William Reyor

Bill Reyor is a Lead Solutions Architect at XBOW, where he helps organizations evaluate and adopt autonomous offensive security testing to find exploitable application-layer vulnerabilities at scale. He has over 15 years of security experience spanning penetration testing, incident response, DevSecOps, application security leadership, and security program design, and is a co-author of O’Reilly’s Defensive Security Handbook.




AI Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 12:40 – 12:50 PDT

Creator: The Diana Initiative

Interested in visiting AI Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to AI Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



AI Village: Village Open

Creator Event Map Page – LVCCW Level 1 Hall 2 603 (AI Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: AI Village

We’re bringing AI Village back to focus on what actually matters: practical, no-bullshit AI security. LLMs are an amazing technology, but they’re not magic. We are stripping away the industry hype and focusing on hands-on skills, whether you are building your first exploit or leading an AI red team.

Here is what you can expect this year:

Drop-In Workshops: Walk up, grab a seat, and learn. We have drop in hands on mini-workshops on a bunch of topics. These include basic AI topics like how LLMs actually work, and how to build agents from scratch. For red teamers we have ones ranging from prompt injection to manipulating malware detection models. This is all running locally on a cluster we’re bringing to DEF CON.

HalCTF: Our main competition this year will teach you how to write and fine-tune your own pentesting agent using open-source models. To handle the massive compute load, we’re safely detonating these agents on GCP, giving each participant a dedicated GPU for their models.

Other Agent Shenanigans: The field moves fast and there’s going to be something new by defcon. We’re bringing a lot of compute to host things and we’ll have some surprises in the space.

Whether you want to hear top-tier research from the people actually breaking these models or you just want to sit down and write an autonomous pentesting agent, we have the hardware and the labs ready for you.




AppSec Quiz Gauntlet: Spot the Vulnerability

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4
When:  Friday, Aug 7, 13:00 – 14:59 PDT

Creator: AppSec Village
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.

People:
    SpeakerBio:  Avek Kolech
No BIO available



AppSec Quiz Gauntlet: Spot the Vulnerability

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2
When:  Saturday, Aug 8, 13:00 – 14:59 PDT

Creator: AppSec Village
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.

People:
    SpeakerBio:  Avek Kolech
No BIO available



AppSec Quiz Gauntlet: Spot the Vulnerability

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2
When:  Sunday, Aug 9, 11:00 – 12:59 PDT

Creator: AppSec Village
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.

People:
    SpeakerBio:  Avek Kolech
No BIO available



AppSec Quiz Gauntlet: Spot the Vulnerability

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2
When:  Saturday, Aug 8, 15:00 – 16:59 PDT

Creator: AppSec Village
In AppSec Quiz Gauntlet: Spot the Vulnerability, you’ll join a hands-on security quiz built around real-world software risks. Analyze suspicious dependencies, uncover typosquatted packages, decode obfuscated snippets, and identify hidden vulnerabilities in short code samples.

People:
    SpeakerBio:  Avek Kolech
No BIO available



AppSec Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 10:30 – 10:40 PDT

Creator: The Diana Initiative

Interested in visiting AppSec Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to AppSec Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Arcanum Security Labs

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Noob Community

Arcanum Security delivers modern cybersecurity through cutting-edge training and consulting, led by Jason Haddix and crew, spanning offensive security, bug bounty hunting, and AI security. Stop by during village hours to work through their hands-on labs.




ARINC 664 CTF Challenge

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Aerospace Village

This is a two-part CTF activity designed to immerse participants in an aircraft’s ARINC 664 network.

Virtual Challenge – Test your skills by navigating through a series of interactive tasks that build foundational knowledge of the ARINC 664 protocol – one of the communications protocols for onboard networks. Gain a high-level understanding of how this protocol operates and its security considerations.

Hardware Challenge: Take it to the next level by engaging with model hardware. Send messages to manipulate and interact with simulated aircraft systems!




Aviation ISAC Cybersecurity Challenge

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Aerospace Village

Chaos has ensued at a major international airport. Flight info displays flicker with false data. Baggage systems fail. Aircraft controls and drones (by the riverside) are compromised. Even the skies are no longer safe.

Your mission: investigate the breach, neutralize the threats, and take back control of the airport. The airport depends on you. The clock is ticking!

As a participant, your first step is to register ahead and read the rules at: https://aviationcyberctf.com/ and bring your own laptop to the venue.




Badgelife Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 13:50 – 13:59 PDT

Creator: The Diana Initiative

Interested in visiting Badgelife but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Badgelife and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



BadVR: Signals Everywhere a collaboration with XR Village

Creator Event Map Page – LVCCW Level 1 Hall 4 1415 (OWASP Foundation)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: OWASP Foundation

BadVR Data Exploration through VR visualization. See RF signals, cellular signals and new for 2026, Meshtastic signals, step into the data with a hands-on VR experience


People:
    SpeakerBio:  Jad Meouchy, CTO + Co-Founder at BadVR

Jad, originally from northern Virginia, holds dual B.S. degrees in Computer Engineering and Psychology from Virginia Tech, and is a graduate of the Thomas Jefferson High School for Science and Technology. While in college, he engineered and built the data visualization components of an emergency response simulation that went on to receive 2M in public grant funding. Over his 15-year career, Jad has founded five startups and successfully exited three. His professional expertise is in software architecture and development, specifically big data analytics and visualization, and virtual and augmented reality development. Based in Los Angeles since 2010, Jad promotes the community by organizing developer meetups and events, and volunteering time for STEM initiatives.

SpeakerBio:  Suzanne Borders, CEO + Founder at BadVR

Suzanne studied psychology at University of Missouri, Kansas City and previously worked as Lead UX/Product Designer for over 9 years at companies such as Remine (raised $48M) and CREXi (raised $54M) where she specialized in designing intuitive, high-performant data analytic interfaces. In 2019, Suzanne founded BadVR and was awarded a “Rising Stars” innovation award from IEEE. To date, she’s raised over $4M in non-dilutive funding for BadVR, via grants from the National Science Foundation, NOAA, Magic Leap, Qualcomm, and more. Suzanne has grown the company from 2 to 25 people and was awarded 4 patents for innovations she created while leading the BadVR team. Over the past 5 years, Suzanne emerged as a thought-leader in the immersive data visualization and analytics space. She has been a keynote speaker at over 25 national and international conferences. In her spare time, Suzanne travels for inspiration (81 countries and counting) and is proud to be a published author and former punk.  Suzanne thrives at the intersection of product design, immersive technology, and data; she’s a believer in the artistry of technology and the technicality of art and remains passionately dedicated to democratizing access to data through universally accessible products. 




Battle of the Bots: Vishing Edition

Creator Event Map Page – LVCCW Level 3 W317-319 (Social Engineering Community Village)
When:  Saturday, Aug 8, 10:15 – 13:15 PDT

Creator: Social Engineering Community Village

AI meets vishing in the booth as teams use AI-powered agents to place live calls, chase preset objectives, and test the limits of automation, hacking, and human psychology. Judged by Snow, Perry Carpenter, and Lisa Flynn.




BBWIC Foundation Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 12:30 – 12:40 PDT

Creator: The Diana Initiative

Interested in visiting BBWIC Foundation but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to BBWIC Foundation and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Biohacking Device Lab

Creator Event Map Page – LVCCW Level 1 Hall 1 408 (Biohacking Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Biohacking Village

Get hands-on with real medical devices. Learn to identify vulnerabilities, test security controls, and understand how these critical systems work.

21 devices from 9 different MDMs, including BD, Boston Scientific, Siemens Healthineers, Roche, Solventum, Medtronic, MiniMed, and Philips.




Biohacking Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 11:00 – 11:10 PDT

Creator: The Diana Initiative

Interested in visiting Biohacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Biohacking Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Blacks In Cyber Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 12:50 – 12:59 PDT

Creator: The Diana Initiative

Interested in visiting Blacks In Cyber Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Blacks In Cyber Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Blue Team Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 12:20 – 12:30 PDT

Creator: The Diana Initiative

Interested in visiting Blue Team Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Blue Team Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Bomb Bot Challenge

Creator Event Map Page – LVCCW Level 1 Hall 2 701 (Car Hacking Village)
When:  Saturday, Aug 8, 10:00 – 16:59 PDT
Friday, Aug 7, 10:00 – 16:59 PDT

Creator: Car Hacking Village

In conjunction with the talk, “Hacking the Bomb Bot: How I Learned to Stop Worrying and Love the Boomba”, attendees have the opportunity to operate a bomb disposal robot. For those up for a challenge, you’ll have a limited amount of time to interact with the robot and test your handling skills. The attendees with the best times will be invited back Sunday morning for a face-off challenge.

The winner will get their very own PackBot 510 to take home!




Breaking AWS Bedrock: Novel Attack Techniques Against Cloud Infrastructure

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) A
When:  Saturday, Aug 8, 13:30 – 14:30 PDT

Creator: Cloud Village

Amazon Bedrock is no longer just a research toy. It's embedded in CI/CD pipelines, production applications, and development workflows, often granted sweeping permissions over S3, IAM, and other AWS services. The rapid adoption of agentic AI has reproduced a new class of configuration patterns that security teams haven't caught up with yet. In this hands-on attack lab, Varonis Threat Labs takes you inside real Bedrock deployment patterns observed across AWS environments. Participants will move from initial Bedrock access through data exfiltration, lateral movement, and AWS account compromise, exploiting the same misconfigurations we've found in the wild. No AI hype. No prompt injection gimmicks. This is cloud infrastructure security, and Bedrock just happens to be the way in. Leave with attack paths you can take back to your own environment and the defensive controls to shut them down. Tal’s Bio: Tal Peleg, also known as TLP, is a senior security researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows domains, SaaS applications, and cloud infrastructure. His research is currently focused on cloud applications, APIs, and agentic applications.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Tal Peleg

Tal Peleg, also known as TLP, is a senior security researcher and cloud security team lead at Varonis. He is a full-stack hacker with experience in malware analysis, Windows domains, SaaS applications, and cloud infrastructure. His research is currently focused on cloud applications, APIs, and agentic applications.

SpeakerBio:  Maya Parizer

Maya Parizer is a Security Researcher at Varonis with a passion for cloud security, identity, and data protection, specializing in IaaS and AI. Maya dives deep into every project, thoroughly investigating cloud environments to uncover potential vulnerabilities and stealthy attack techniques. Her experience spans both offensive and defensive disciplines — including CSPM, DSPM, vulnerability research, detection engineering, and product security research in cloud environments.




Bricks in the Air

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Aerospace Village

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft’s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required – all target devices, materials, and interfaces are provided!

No prior aviation or security experience required – a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.




Bug Bounty Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 13:40 – 13:50 PDT

Creator: The Diana Initiative

Interested in visiting Bug Bounty Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Bug Bounty Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Build-A-Badge Workshop

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Saturday, Aug 8, 11:00 – 12:30 PDT
Friday, Aug 7, 11:00 – 12:30 PDT
Friday, Aug 7, 14:00 – 15:30 PDT

Creator: Maker’s Village

Welcome to the Build-A-Badge Workshop! We’ve cultivated some interesting maker mediums to bring you a unique badge that’s all about making it your own. This workshop is a unique experience for the veteran maker or someone new that may be interested in seeing how makers can come together and create something truly unique. A brief workshop introduction, led by project leader and designer Alchemist, will give you some background on the badge. After which, you’ll be assigned a group number and split off into teams within the Makers’ Village, hitting each station for the badge assembly. You’ll get a chance to talk to our 3-D printer Buddha, our Laser Engraver Teazee, Silk Screener hunny, and Board Maker M-Nelly to show you all the ways you can make this Bear Badge your own. Every workshop attendee will also receive a SAO for their badges as well as stickers and links to a Badge Repository with prints files, patterns, and some extras to continue to work on this badge after the con.


People:
    SpeakerBio:  hunny
No BIO available
SpeakerBio:  Teazee
No BIO available
SpeakerBio:  Buddha
No BIO available
SpeakerBio:  MLP
No BIO available
SpeakerBio:  M-Nelly
No BIO available
SpeakerBio:  Alchemmer
No BIO available



Building Silkscreens and carving stamps

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Saturday, Aug 8, 16:00 – 17:45 PDT

Creator: Maker’s Village

See a demonstration of the steps to making your own silk screens and get to explore the Makers’ Village Stamps and screens. Bring swag to experiment on!


People:
    SpeakerBio:  hunny
No BIO available



Call Center Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 12:40 – 12:50 PDT

Creator: The Diana Initiative

Interested in visiting Call Center but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Call Center and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Call Center Village – Open

Creator Event Map Page – LVCCW Level 2 W218 (Call Center Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Call Center Village

Security teams have spent years hardening web-apps, email-gateways, and network-perimeters. Meanwhile, the phone line sitting on every receptionist’s desk remains almost completely unmonitored. Nobody’s deploying a firewall between a caller and the person who picks up. Caller ID authentication has made some progress, but the conversation itself? Wide open.

And now that AI-generated voices can pass for the real thing and automated agents are handling account resets and payment processing, that gap is getting a lot more interesting.Call Center Village is where voice security, conversational AI, and social engineering collide — across both voice and text channels.

Sit down at a workstation and synthesize a copy of your own voice with open-source tools running on a local GPU, or let our staff walk you through the process. Dig into voice pipelines, deepfake audio detection, and the arms race between the two. Wire up a working conversational AI agent — stitching together the real-time audio infrastructure, transcription, language model, and speech synthesis that make these systems speak.

On the text side, go after chatbot agents tasked with handling simulated customer interactions. Find the cracks in their system prompts, hijack conversation logic, and convince them to do things their developers never intended. Once you’re ready, muster all your skills to take on our Escalation Desk CTF, the official Call Center Village contest at DEF CON 34.

We’ve also got a collection of vintage telephones, prank extensions, chatty AI-agents, and a British-style telephone booth worth stopping by for.

No prior experience required. If you know how to make a phone call or type a message, you’re already qualified. Equipment is provided, including laptops and ANC headsets – but you’re more than welcome to bring your own devices.




Car Hacking Village Open

Creator Event Map Page – LVCCW Level 1 Hall 2 701 (Car Hacking Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Car Hacking Village

Welcome to the Car Hacking Village – a place where you can learn all about the cool technology that powers modern connected transportation. The CHV at DEF CON 34 will feature a whole race track of activities including Creator Stage presentations, a competitive CTF (with awesome prizes!), an amazing badge for sale that doubles as a fully functional car hacking tool, a scavenger hunt, and more!




Car Hacking Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 12:30 – 12:40 PDT

Creator: The Diana Initiative

Interested in visiting Car Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Car Hacking Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Cards Against Vulnerabilities

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1
When:  Friday, Aug 7, 11:00 – 12:59 PDT

Creator: AppSec Village

Join us for “Cards Against Security: Trust Me, It’s Secure,” a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!


People:
    SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.




Cards Against Vulnerabilities

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1
When:  Friday, Aug 7, 15:00 – 16:59 PDT

Creator: AppSec Village

Join us for “Cards Against Security: Trust Me, It’s Secure,” a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!


People:
    SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.




Cards Against Vulnerabilities

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1
When:  Friday, Aug 7, 13:00 – 14:59 PDT

Creator: AppSec Village

Join us for “Cards Against Security: Trust Me, It’s Secure,” a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!


People:
    SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.




Cards Against Vulnerabilities

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3
When:  Saturday, Aug 8, 11:00 – 12:59 PDT

Creator: AppSec Village

Join us for “Cards Against Security: Trust Me, It’s Secure,” a hilarious card game inspired by Cards Against Humanity! Test your wit as you create the funniest responses to prompts related to software development and security. Gather your friends at the AppSec Village and dive into a world of Chainguard humor. Compete to be the first to five points and win bragging rights (and prizes)! Don’t miss out on this fun-filled experience that combines laughter with learning—perfect for security enthusiasts and developers alike!


People:
    SpeakerBio:  Patrick Smyth

Dr. Patrick Smyth is Principal Developer Relations Engineer at Chainguard, where he shows developers how to deploy AI and other applications with 0 CVEs using Chainguard Images. Patrick has a PhD in the digital humanities and in a previous life led technical bootcamps for researchers at Columbia University. In his free time you can find Patrick swimming in a frozen lake or hanging out with his six-month-old baby.




Cat-astrophic Hacking: Breaking Into Smart Litter Boxes

Creator Event Map Page – LVCCW Level 1 Hall 1 215 (IoT Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: IoT Village

What happens when your cat’s litter box joins the Internet of Things? Join Suzu Labs as we dissect, analyze, and hack smart litter robots to uncover security risks.

Links:
    More Info – https://iotvillage.org/events/defcon-34/index.html



Chill Zone: Casual Games & TASBot Smash Demo

Creator Event Map Page – LVCCW Level 1 Hall 1 211 (Game Hacking Village)
When:  Friday, Aug 7, 10:00 – 15:59 PDT
Saturday, Aug 8, 10:00 – 15:59 PDT

Creator: Game Hacking Village

DEF CON got you overwhelmed? Come relax and play Project Plus, a modded version of Super Smash Bros Brawl. Or compete against a frame perfect Smash Bot!




Chill Zone: Smash (Project Plus) Tournament with Prizes

Creator Event Map Page – LVCCW Level 1 Hall 1 211 (Game Hacking Village)
When:  Saturday, Aug 8, 16:00 – 16:59 PDT
Friday, Aug 7, 16:00 – 16:59 PDT

Creator: Game Hacking Village

Compete against other attendees in a modded version of Super Smash Bros Brawl! This is a low stakes tourney that is beginner friendly and open to all.




Cirro: Extending Your Azure Graph Beyond Identities

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) A
When:  Friday, Aug 7, 16:00 – 17:59 PDT

Creator: Cloud Village
Most Azure graph analysis tooling focuses primarily on identity relationships: users, groups, service principals, and role assignments. While valuable, modern Azure environments contain far more exploitable context hidden within infrastructure, platform services, application configurations, network relationships, managed identities, and data-plane resources.

Cirro (the spiritual successor to Stormspotter) is an attack graphing tool built to model Azure environments by combining Microsoft Graph identity data with Azure Resource Manager (ARM) infrastructure data. Instead of limiting analysis to Entra ID objects and role assignments, Cirro maps Azure resources into Neo4j for deeper attack path and misconfiguration analysis.

This lab provides a practical understanding of Cirro’s collection, ingestion, and analysis workflow. Attendees will perform enumeration and assessment of an Azure tenant to understand how to view attack paths beyond identities. They will perform Cypher queries and use custom dashboards to visualize and interpret graph data.

Prerequisites: – Docker/Podman Compose – Azure CLI – Web browser – Sqlite3 Browser Recommended (but not required): – Fundamental knowledge of Cypher query language

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Leron Gray

Leron Gray is a Senior Security Consultant at Bishop Fox, specializing in offensive security, cloud attack path analysis, and security tooling research. He is the creator of Cirro, an extensible graph-based framework for analyzing Azure and cloud environments through Microsoft Graph and Azure Resource Manager data. His work focuses on helping security researchers and red teamers better understand complex cloud relationships, identity abuse paths, and infrastructure misconfigurations at scale.




Clash of Prompts: The World’s First Prompt Battle Royale

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1
When:  Sunday, Aug 9, 11:00 – 12:59 PDT

Creator: AppSec Village

Clash of Prompts is the world’s first live, head-to-head AI prompt battle royale. Two developers tackle the same coding challenge, one prompt each, on the clock, while the AI generates the code live on screen. Every prompt is scored in real time on vulnerabilities, security best practices, and prompt efficiency.

Research shows 87-94% of AI-generated code ships with security flaws, even when developers try to prompt securely. This Pod is a hands-on way to see that play out: attendees write and test real prompts and watch them get scored instantly.


People:
    SpeakerBio:  Darren McNelis
No BIO available
SpeakerBio:  Jerome Roberts

With over 20 years of experience in cybersecurity and 15 years as a CxO, Jérôme has a proven track record in driving successful outcomes. He has been instrumental in five successful exits, including Lexsi (acquired by Orange in 2016) and Alsid (acquired by Tenable in 2021). Starting his career in deep-tech, mathematics, and engineering, Jérôme transitioned seamlessly into business leadership, leveraging his technical roots to guide strategic decisions and foster innovation in the cybersecurity landscape.




Clash of Prompts: The World’s First Prompt Battle Royale

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3
When:  Friday, Aug 7, 11:00 – 12:59 PDT

Creator: AppSec Village

Clash of Prompts is the world’s first live, head-to-head AI prompt battle royale. Two developers tackle the same coding challenge, one prompt each, on the clock, while the AI generates the code live on screen. Every prompt is scored in real time on vulnerabilities, security best practices, and prompt efficiency.

Research shows 87-94% of AI-generated code ships with security flaws, even when developers try to prompt securely. This Pod is a hands-on way to see that play out: attendees write and test real prompts and watch them get scored instantly.




Cloud Village CTF: Three Azure Warmups

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Sunday, Aug 9, 10:00 – 10:59 PDT

Creator: DCNextGen

Welcome to Apex Park, where cloud-security mistakes are causing trouble throughout the park! Participants will investigate three beginner-friendly Azure challenges involving an exposed gift shop, an overpowered day pass, and an unlocked control room. They will inspect websites, investigate cloud-storage permissions, follow clues, and recover hidden flags. No access to a real Azure account or the challenge infrastructure is required. Participants interact only with intentionally vulnerable CTF resources created for learning.


People:
    SpeakerBio:  Cloud Village
No BIO available



Cloud Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 13:00 – 13:10 PDT

Creator: The Diana Initiative

Interested in visiting Cloud Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Cloud Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Cloudy with a Chance of Breaches: Hands-On AWS Threat Defense

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) A
When:  Friday, Aug 7, 13:30 – 15:30 PDT

Creator: Cloud Village

Join this hands-on workshop to explore integrated security capabilities for the modern AWS cloud stack, including containers, object storage, and AI applications. You’ll work with a deliberately vulnerable Flask application running on EKS with S3 and Amazon Bedrock, then deploy and configure controls that detect attacks at runtime.

The session will cover behavioral runtime detection for credential-access activity and malware inside live pods, attack-surface mapping, and identity-aware risk analysis to trace the potential blast radius of a compromised workload through its IAM role. You’ll also examine file-borne threat protection across the application boundary and S3, use unified XDR queries to hunt across container and storage detections, and close with runtime guardrails that block direct and document-borne prompt injection against a real Amazon Bedrock model.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Kyle Hubbard

Kyle is a Solutions Architect at TrendAI, where he works within the Global Alliances team across hyperscaler partnerships, with a primary focus on AWS. He specializes in cloud security integrations and in translating the technical capabilities of the Trend Vision One platform into strategies that partners, customers, and executives can act on.

His current work is centered on AI security, including AI security posture management and the protection of agentic workloads. As organizations rapidly adopt agentic architectures, Kyle focuses on how Vision One can secure that transition and how to communicate its value clearly to both technical and executive audiences.




Code Invaders: Stop The Insecure Code

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1
When:  Saturday, Aug 8, 13:00 – 14:59 PDT

Creator: AppSec Village
Recruit: help stop the Vibe Invasion. AI-generated code is flooding the frontier with insecure logic, and it’s your job to intercept it before it hits production. Vulnerable snippets (SQL injections, hardcoded secrets, broken crypto, and risky error handling) are falling toward the pipeline. Eliminate the threats, but stay sharp: secure code is mixed in. One wrong move could cause damage. Defend production and stop the Vibe Coding Invasion.

People:
    SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.




Code Invaders: Stop The Insecure Code

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1
When:  Saturday, Aug 8, 11:00 – 12:59 PDT

Creator: AppSec Village
Recruit: help stop the Vibe Invasion. AI-generated code is flooding the frontier with insecure logic, and it’s your job to intercept it before it hits production. Vulnerable snippets (SQL injections, hardcoded secrets, broken crypto, and risky error handling) are falling toward the pipeline. Eliminate the threats, but stay sharp: secure code is mixed in. One wrong move could cause damage. Defend production and stop the Vibe Coding Invasion.

People:
    SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.




Cold Calls

Creator Event Map Page – LVCCW Level 3 W317-319 (Social Engineering Community Village)
When:  Saturday, Aug 8, 16:30 – 17:59 PDT
Sunday, Aug 9, 11:30 – 12:30 PDT
Friday, Aug 7, 16:00 – 17:59 PDT

Creator: Social Engineering Community Village

Ready for the hot seat? Step into the soundproof booth, grab a mystery target and three escalating objectives, and we’ll place the call. Run by rekdt, Arty Boy, and Shadow Fox. First come, first served, so get your name on the Cold Call list!




Coloring Reset

Creator Event Map Page – LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)
When:  Saturday, Aug 8, 10:00 – 10:59 PDT

Creator: Misc

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you’re decompressing or collaborating on a shared poster, it’s the perfect low-pressure space to connect, reflect, and color outside the lines.




Coloring Reset

Creator Event Map Page – LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)
When:  Friday, Aug 7, 10:00 – 10:59 PDT

Creator: Misc

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you’re decompressing or collaborating on a shared poster, it’s the perfect low-pressure space to connect, reflect, and color outside the lines.




Coloring Reset

Creator Event Map Page – LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)
When:  Sunday, Aug 9, 10:00 – 10:59 PDT

Creator: Misc

Kick off your DEF CON morning with a creative reset. Color with WISP! Choose from different coloring pages and bring them to life with markers, crayons, and your own flair. Whether you’re decompressing or collaborating on a shared poster, it’s the perfect low-pressure space to connect, reflect, and color outside the lines.




Crafting the Future: DEF CON 34 Light-Up Bow Workshop

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Saturday, Aug 8, 13:00 – 13:59 PDT

Creator: Maker’s Village

Level up your wearable tech skills and celebrate DEF CON 34 by making your own interactive, light-up accessory! In this hands-on e-textile workshop, proudly presented by Hack3r Runway, you will learn the basics of wearable electronics and sewing circuits to create a custom glowing bow. Whether you want to rock it in your hair or wear it as a sleek cyberpunk bow tie, you’ll walk away with a unique, handmade piece of hacker fashion. What you’ll learn *Intro to E-Textiles: Learn how to design a basic circuit using a LilyPad battery holder and wearable LEDs. * Conductive Thread Basics: Master the art of hand-sewing with conductive thread to power your creation without bulky wires. * Exclusive Swag: Assemble your circuit onto a custom 3D-printed bow featuring a special glow-in-the-dark DEF CON 34 logo.




Creator Drop-In

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Saturday, Aug 8, 15:30 – 16:59 PDT

Creator: Scambait Village

We know a handful of names you would recognize are wandering this conference. We have invited them to swing by the village during this block and say hi. No stage, no line, no format. Just a shot at an actual conversation with the people behind the calls, so ask what you have always wanted to ask and swap a few stories of your own.

Links:
    scambaitvillage.org/creators – https://scambaitvillage.org/creators



Crypto And Privacy Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 10:20 – 10:30 PDT

Creator: The Diana Initiative

Interested in visiting Crypto And Privacy Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Crypto And Privacy Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Cryptocurrency Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 12:20 – 12:30 PDT

Creator: The Diana Initiative

Interested in visiting Cryptocurrency Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Cryptocurrency Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Cryptographer Recruitment: Crack the Substitution Cipher

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Friday, Aug 7, 12:00 – 12:45 PDT

Creator: DCNextGen

You’re a Cryptographer When Jumbled Letters are Exciting, Not Scary! The substitution cipher is a game of mathematics and patterns. With basic skills (or online tools) ciphers are easy to decipher. Don’t let them fool you! Attendees will need some paper, a writing device, and access to the Substitutor web app.


People:
    SpeakerBio:  Bradán Lane
No BIO available



Cyber Mirage: Realtime Deepfake Demos

Creator Event Map Page – LVCCW Level 1 Hall 2 603 (AI Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: AI Village

Go deepfake yourself! This hands-on demo shows how threat actors leverage open-source deepfake video and voice cloning frameworks to impersonate anyone in realtime, conducting social engineering and compromising organizations using nothing more than a consumer-grade gaming laptop. No specialized hardware, no budget, no nation-state resources required. Come learn the tradecraft firsthand and find out just how convincing you can become.


People:
    SpeakerBio:  Brandon Kovacs

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at offensive cybersecurity firm Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets. Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on the intersection of offensive cybersecurity and artificial intelligence.




Cyberdeck Build

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Friday, Aug 7, 15:00 – 16:59 PDT
Saturday, Aug 8, 15:00 – 16:59 PDT

Creator: Maker’s Village

Learn some in’s and out’s of building your own cyberdeck… by building one with us! Customizable with radio add on, this deck is a great introduction level or intermediate refresher.


People:
    SpeakerBio:  Sk!tz0
No BIO available



Darknet Diaries Meet & Greet with Jack Rhysider

Creator Event Map Page – LVCCW Level 2 W238 (DEF CON Groups)
When:  Friday, Aug 7, 13:30 – 14:30 PDT

Creator: DEF CON Groups

Meet Jack Rhysider, creator and host of Darknet Diaries, during a special fan meet and greet in the DEF CON Groups Community. Stop by to say hello and talk about your favorite stories from the dark side of the internet. First come, first served.


People:
    SpeakerBio:  Jack Rhysider, Creator and Host at Darknet Diaries
No BIO available



Data Duplication Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 10:30 – 10:40 PDT

Creator: The Diana Initiative

Interested in visiting Data Duplication Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Data Duplication Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



DC Maker’s Community Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 12:10 – 12:20 PDT

Creator: The Diana Initiative

Interested in visiting DC Maker’s Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DC Maker’s Community and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



DCNextGen – Bricks in the Air

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Aerospace Village

Step right up to our interactive LEGO aircraft. Can you investigate the aircraft’s control system, identify any vulnerabilities, and “hack” beyond its intended functions?

This exercise uses real-world I2C protocols to simulate potential vulnerabilities in an aircraft control system.

No specialized hardware required – all target devices, materials, and interfaces are provided!

No prior aviation or security experience required – a walkthrough guide is provided for beginners, and volunteers are on hand to help at every step. This activity is accessible to all skill levels.




DCNextGen – RIC-1: ELT Localization Exercise – N3VR-G0N Down

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Aerospace Village

RIC-1, tail number N3VR-G0N, has gone down! You need to use radio direction-finding (RDF) techniques to locate Emergency Locator Transmitter (ELT), report its position, and help rescue our missing pilot!

Participants will use the provided handheld DF equipment provided by the Village, or bring your own, to triangulate the hidden transmitter location within the village area. Your handheld radio must be capable of receiving on the designated frequency with a directional antenna or attenuator. Once you’ve located RIC-1, listen closely… you may recognize the beacon’s “distress tone.” It appears to be broadcasting an audio payload that responders have described as “oddly catchy” and “impossible to stop once you start listening.” Bring your comfortable shoes and strong will to ensure you never give up until you find our missing pilot!

No prior RDF experience required – volunteers can walk you through basic triangulation techniques before you start this 15-30 minute event.




DCNextGen – Space Grand Challenge – SatHack: The MOUSE-1 Mission

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Aerospace Village

The MOUSE-1 satellite is currently in Safe Mode, and its attitude and heading systems are behaving unexpectedly. Ground control needs answers NOW!

You are a newly assigned Mission Specialist, and it’s your job to figure out what’s going on. Work through five sequential challenge missions aboard a simulated HUD – complete with live orbital tracking, optical camera feeds, and attitude telemetry – to triage MOUSE-1, uncover what happened, and make it operational again.

Participants will learn how satellites operate, how they stay secure in orbit, and what happens when they don’t – using a fully browser-based, gamified interface developed by California Polytechnic State University students.

Just grab a seat in front of the provided station, no prior cybersecurity or aerospace experience required! Each mission is self-guided with built-in instructions, and volunteers are available to assist. Both beginner and experienced participants will find this 30-minute event challenging and fun.




DDoS Community Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 12:50 – 12:59 PDT

Creator: The Diana Initiative

Interested in visiting DDoS Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DDoS Community and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



DDV open and accepting drives for duplication

Creator Event Map Page – LVCCW Level 2 W203 (Data Duplication Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Thursday, Aug 6, 16:00 – 18:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Data Duplication Village
We start taking drives at 4: 00pm local time on Thursday – possibly a little earlier. We’ll keep accepting drives until we reach capacity (usually late Friday or early Saturday).  Then we copy and copy all the things until we just can’t copy any more – first come, first served. Note that some sources require 8TB drives now.  We run around the clock until we run out of time on Sunday morning with the last possible pickup being before 11:00am on Sunday.



DEF CON Academy Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 12:00 – 12:10 PDT

Creator: The Diana Initiative

Interested in visiting DEF CON Academy but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DEF CON Academy and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



DEF CON Groups (DCG) Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 13:20 – 13:30 PDT

Creator: The Diana Initiative

Interested in visiting DEF CON Groups (DCG) but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to DEF CON Groups (DCG) and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



DEF CON Groups (DCG)

Creator Event Map Page – LVCCW Level 2 W238 (DEF CON Groups)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Thursday, Aug 6, 10:00 – 17:59 PDT

Creator: DEF CON Groups

DEF CON Groups are the year round, local communities that bring the DEF CON spirit home. Run by volunteers around the world, DCGs create spaces where hackers meet, learn, collaborate, and build community outside of conference season.

The DEF CON Groups community space brings together Points of Contact, members, and prospective members to collaborate, share ideas, and learn from one another. Through informal workshops and hands on interaction, participants exchange practical lessons on building, sustaining, and evolving local hacker communities.

The space also serves as a social anchor. A relaxed place to reconnect with old friends, meet new ones, and participate in light interactive activities that reflect the collaborative nature of hacking culture.

DEF CON has always been the island of misfit toys we all return to once a year. DEF CON Groups are how that ethos survives the other fifty one weeks.

Links:
    Website – https://defcongroups.org



Discover GE Appliances!

Creator Event Map Page – LVCCW Level 1 Hall 1 215 (IoT Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: IoT Village

Join us for a self-guided interactive look at GE Appliances and get hands on with some of our most popular home appliances!

Links:
    More Info – https://iotvillage.org/events/defcon-34/index.html



Drogonsec: SAST + SCA + Secrets + IaC in one open-source scanner

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Friday, Aug 7, 12:45 – 13:45 PDT

Creator: AppSec Village

Drogonsec is an open-source, high-performance security scanner built for developers and CI/CD pipelines. In a single run, it combines four analysis engines: SAST for 20+ languages, SCA for dependency CVEs, secret detection with 50+ patterns (AWS, GCP, GitHub, JWTs, SSH keys), and IaC misconfiguration analysis for Terraform and Kubernetes, all mapped to OWASP Top 10:2025 and CWE, with CVSS 3.1 scoring and SARIF output for GitHub and Azure DevOps integration.

This Arsenal session will demo Drogonsec scanning real-world repositories live, showing findings across all four engines, explaining rule design decisions, and showcasing how teams can extend it with custom YAML rules. Attendees leave with a running tool they can drop into their pipelines the same day.


People:
    SpeakerBio:  Filipi Pires, Head of Technical Advocacy at SCYTHE

I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, Advisor & Investor at Sherlockeye, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador, Application Security Specialist and Hacking is NOT a crime Advocate. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA – Middle-East – and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges, in addition, I’m Creator and Instructor of the Course – Malware Attack Types with Kill Chain Methodology (PentestMagazine), PowerShell and Windows for Red Teamers(PentestMagazine) and Malware Analysis – Fundamentals (HackerSec).

Black Hat US 2025 – https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat US 2024 – https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat MEA 2025 – https://blackhatmea.com/speaker/filipi-pires-0 Black Hat MEA 2024 – https://blackhatmea.com/speaker/filipi-pires DEF CON 33 / 32 – https://sessionize.com/filipi-pires/ DEF CON – Adversary Village – https://adversaryvillage.org/adversary-events/DEFCON-33/Filipi-Pires/




Drone Hacking Choose your Own Adventure

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Aerospace Village

Dive into our interactive choose-your-own-adventure web interface and learn how to hack a drone in a fun, storyboard-based game. This graphical user interface simulates the process we use when hacking drones for the Air Force, allowing participants to make decisions and see the outcomes.

It’s a beginner-friendly, 15-30 minute activity offering insights into the steps involved in drone penetration testing.

Participants can access it from their own computers or mobile phones.




Drone Hacking Workshop

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Aerospace Village

Join our Drone Hacking Workshop for hands-on experience hacking drone components. This three-step in-depth activity is designed to teach you about the vulnerabilities and security of autonomous systems. Using sample drones, participants will learn techniques used in government pen tests.

This 2-3 hour workshop suits all skill levels, from beginners to advanced hackers. Come and test your skills in a real-world scenario and understand the intricacies of drone security.

Participants need to bring a laptop capable of running a Linux distribution.




Embedded – 101 Labs

Creator Event Map Page – LVCCW Level 1 Hall 2 503 (Embedded Systems Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Embedded Systems Village

We have a lab platform that brings everyone from every skill level to the same playing field with step by step instructions that aim to teach individuals specific techniques and skills in a hands-on manner on embedded hacking techniques.




Embedded & Shredded: Advanced Embedded System Hacking

Creator Event Map Page – LVCCW Level 1 Hall 1 408 (Biohacking Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Biohacking Village

This course offers a deep dive into practical techniques for dissecting and manipulating embedded systems. Get hands-on with these core activities:

  • Visually inspect and document a device to map components, debug interfaces, and attack surfaces
  • Decode board communication protocols with logic analyzers
  • Exfiltrate live data over SPI, JTAG, and SWD — and use chip-off / deadbugging to reach embedded storage
  • Reverse-engineer bare-metal firmware in Ghidra with advanced plugins
  • Probe embedded defenses — encryption, disabled debug interfaces, glitching, and fault injection
  • Chain hardware-level access into higher-level exploits — from physical interfaces all the way up to network-exposed services



Embedded System Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 11:30 – 11:40 PDT

Creator: The Diana Initiative

Interested in visiting Embedded System Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Embedded System Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Embedded Systems Village CTF

Creator Event Map Page – LVCCW Level 1 Hall 2 503 (Embedded Systems Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Embedded Systems Village

Get hands-on with devices you won’t find anywhere else — rare, hard-to-source embedded devices staged for live exploitation. Hunt real zero-days, and yes, bring your AI: LLM-assisted tooling is fully allowed, so use it to go as deep as you can.

Come break something that’s never been broken.

New to embedded? Just wrapped our 101 Labs? Beginner challenges are available as well to apply your new found knowledge!




Everything I Need to Know About Security, I Learned from Mr. Rogers

Creator Event Map Page – LVCCW Level 2 W209 (Diana Initiative)
When:  Saturday, Aug 8, 13:00 – 13:59 PDT

Creator: The Diana Initiative

The same lessons we learned from children’s programs growing up can help keep organizations safe. Kindness builds trust, and trust gets team buy-in to security processes. Diversity increases the vantage points and perspectives able to spot gaps or loopholes in technology and process. Empathy that puts us in the shoes of our users helps refine workflows, and a company that takes care of its employees reduces the likelihood of internal bad actors. Security is more about effective cooperation than a digital dogfight.


People:
    SpeakerBio:  Zoe
No BIO available



Exploit Bluetooth Low Energy with BLESPloit and optional ESP32

Creator Event Map Page – LVCCW Level 1 Hall 2 503 (Embedded Systems Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Embedded Systems Village

Discover how easy it is to fingerprint and control nearby BLE devices with a tap on your phone – yes, including iPhone that gets BLE superpowers with with an external ESP32. Scan remotely, clone and simulate BLE devices, test a popular headset for known vulnerabilities (or perhaps uncover a new one?) and take control of a robotic dog. Already know some BLE? Crack open our smart safe and claim the BLESPloit hardware reward inside!


People:
    SpeakerBio:  Slawomir Jasek, BLESPlo.it

Seasoned trainer, speaker and IT security consultant with over two decades of expertise. Developed secure embedded systems certified to use by national agencies, participated in dozens assessments of systems, applications, firmware and hardware security for leading financial companies, largest manufacturers and innovative startups. Currently focuses on security research of new technologies (especially Bluetooth Low Energy and NFC/RFID) and provides training in regards to security of devices – based among others on contemporary electronic access control systems and smart locks. Beyond consulting on secure design for various software and hardware projects, impulsively acquires more and more BLE and NFC devices and enjoys reversing and breaking them. Loves sharing his knowledge via trainings, workshops, talks and open source hackme’s (https://www.smartlockpicking.com/) – at OrangeCon, BlackHat, HackInTheBox, Hardwear.io, HackInParis, Deepsec, Appsec EU, BruCon, Confidence, and many others, including private on-demand sessions.




Expose Hidden Surveillance in Everyday Tech

Creator Event Map Page – LVCCW Level 1 Hall 1 215 (IoT Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: IoT Village

Join the Ludlow Institute Surveillance Mission. Dump firmware, capture packets, probe APIs, or tear devices apart however you like. Prizes up for grabs.

Links:
    More Info – https://iotvillage.org/events/defcon-34/index.html



F1NDX OSINT Educational Series

Creator Event Map Page – LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: OSINT For Good Community

The OSINT Educational Series is a 3-level series that introduces Open-Source Intelligence (OSINT). It covers data collection, social media analysis, and investigative techniques, showing how publicly available information is used in cybersecurity and intelligence. Volunteers will be on hand to help you get started and answer questions if you get stuck! Complete all 3 levels and earn a digital badge!

Links:
    More Info – https://tracelabs.org/blog/osint-educational-series



Factory Floor MVP Incident Response Challenge

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4
When:  Saturday, Aug 8, 13:00 – 14:59 PDT

Creator: AppSec Village

Defend the Factory. Beat the Attack. The Factory Floor MVP Incident Response Challenge is a fast-paced, interactive card-and-dice game where teams investigate cyberattacks against a modern manufacturing environment. Use strategy, collaboration, and a little luck to uncover attacker activity before production or safety is impacted. Players will walk away with practical insights into OT security, firmware and SBOM analysis, incident response, and the challenges of protecting connected industrial systems.




Factory Floor MVP Incident Response Challenge

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3
When:  Friday, Aug 7, 13:00 – 14:59 PDT

Creator: AppSec Village

Defend the Factory. Beat the Attack. The Factory Floor MVP Incident Response Challenge is a fast-paced, interactive card-and-dice game where teams investigate cyberattacks against a modern manufacturing environment. Use strategy, collaboration, and a little luck to uncover attacker activity before production or safety is impacted. Players will walk away with practical insights into OT security, firmware and SBOM analysis, incident response, and the challenges of protecting connected industrial systems.




Farsight: Turning OSINT into Actionable Attack Surface Intelligence

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Friday, Aug 7, 14:00 – 14:59 PDT

Creator: AppSec Village

Farsight is an open-source reconnaissance and threat intelligence framework designed to transform fragmented OSINT workflows into a unified, automated intelligence pipeline. Traditional reconnaissance relies on multiple disconnected tools, manual correlation, and inconsistent outputs, limiting scalability and efficiency.


People:
    SpeakerBio:  Arif

Senior Security Engineer with 5+ years of experience helping companies build and ship secure products without slowing down innovation. I specialize in Web, API, and Mobile Pentesting, Cloud Security, Threat Modeling, and embedding scalable SSDLC practices. My security journey began with curiosity and evolved into real-world impact—during an audit, I uncovered a critical flaw that could’ve exposed sensitive internal data. At Poshmark, I’ve led third-party library risk assessments, performed architecture reviews for key features, and rolled out secure coding practices across engineering. My threat modeling work improved early risk detection by 40%. Outside of work, I run hands-on security workshops, organize CTFs, and speak at conferences like c0c0n and Seasides. I’m open to the chance to solve real-world security challenges. Let’s connect and build secure systems that scale.

SpeakerBio:  Sai Vernekar

Sai Santosh Vernekar is a seasoned Application Security Practitioner with over a decade of expertise in application security. Over his career, Sai has undertaken secure code review, DAST, Devsecops, penetration testing as well as threat modeling. He currently works as Senior Security Engineer at Kohl’s. His keen interest lies in Cloud Security & secure CI/CD implementations.

SpeakerBio:  Seedon D’Souza

Hardware security expert with 10+ years in RF hacking, drone security, and exploitation. Speaker at Seasides Goa. Formerly at Sony, now at Festo.

SpeakerBio:  kvprashant

Prashant Venkatesh is an information security expert with over 20 years of experience. He presently works as, Product security Leader

Prashant is an enthusiastic participant in the field who consistently coordinates, reviews papers, and presents his work at numerous InfoSec conferences, including at Nullcon and c0c0n. He is also active through the OWASP Bay Area chapter Leadership and he is co-founder of annual Seasides Conference.




Fix It, Snooze It, or Ignore It? Cloud Security Decisions Under Pressure

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) B
When:  Saturday, Aug 8, 13:30 – 14:30 PDT

Creator: Cloud Village

Cloud security teams rarely struggle to find issues. They struggle to decide what actually matters—and how to fix them with limited resources.

In this interactive CloudSec Village lab hosted by Aikido Security, attendees step into the role of a cloud security lead. Navigating a custom simulation dashboard, you’ll manage a realistic environment spanning containers, Kubernetes, serverless, and virtual machines.

The catch? Your engineering teams have a strict cap on available hours, and every fix comes with an estimated time cost. You must evaluate a live queue of vulnerabilities, assign remediation to the right teams, and decide what to fix, defer, or ignore to find the most optimal defense strategy before your resources run out.

This drop-in lab focuses on real-world decision-making under pressure rather than theory. Join at any time, manage your clock, and see how your prioritization strategy compares.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Mackenzie Jackson

Mackenzie is the Field CTO for Aikido Security, helping tech leaders understand application security through an attacker’s lens. As the co-founder and former CTO health tech company Conpago, he understands the challenges of building secure applications. He has spoken in over 30 countries, hosts the popular Podcast The Secure Disclosure, and contributes to multiple publications including Dark Reading, Financial Times, and Fast Company.




Flight Simulator/EFB

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Aerospace Village

Experience the effects of tampered engine performance data as you take the controls on a departing flight. Feel for yourself how vulnerabilities in electronic flight bags can have a physical impact inside the cockpit.




Friendship Bracelets

Creator Event Map Page – LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)
When:  Saturday, Aug 8, 12:00 – 12:59 PDT

Creator: Misc

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!




Friendship Bracelets

Creator Event Map Page – LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)
When:  Friday, Aug 7, 12:00 – 12:59 PDT

Creator: Misc

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!




Friendship Bracelets

Creator Event Map Page – LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)
When:  Sunday, Aug 9, 12:00 – 12:59 PDT

Creator: Misc

Create a custom bracelet to wear or trade, each featuring a special bead with a hidden message or symbol of empowerment. This tactile, low-key activity is perfect for starting conversations and forming connections across the community. No crafting experience needed, just good vibes and open hands. Join us during this hour for a WISP bead to add to your bracelet (while supplies last)!




From Dashboard to Exploit: Weaponizing and Winning the Cloud Queue

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) B
When:  Friday, Aug 7, 16:00 – 17:59 PDT

Creator: Cloud Village

Finding a vulnerability on a dashboard is only half the battle. Knowing how an attacker will weaponize it is what separates great security engineers from the rest.

In this hands-on CloudSec Village lab hosted by Aikido Security, you will step into the shoes of both defender and attacker. Navigating a custom simulation dashboard, you’ll face live vulnerabilities hidden across containerized apps and serverless functions. Your mission: don’t just trust the scanner. You will dive into live mini-applications, execute real-world exploits to prove their impact, and see exactly how they register on the platform. This drop-in lab bridges the gap between passive triage and active offensive security — join any time and validate threats like a pro.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Mackenzie Jackson

Mackenzie is the Field CTO for Aikido Security, helping tech leaders understand application security through an attacker’s lens. As the co-founder and former CTO health tech company Conpago, he understands the challenges of building secure applications. He has spoken in over 30 countries, hosts the popular Podcast The Secure Disclosure, and contributes to multiple publications including Dark Reading, Financial Times, and Fast Company.




From Findings to Remediations: Open Source Cloud Security at AI Speed with Prowler

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) B
When:  Saturday, Aug 8, 11:00 – 12:59 PDT

Creator: Cloud Village

Cloud security teams are drowning in findings, but isolated misconfigurations rarely tell the full story. This hands-on workshop shows how to use Prowler, the open-source cloud security platform, to detect vulnerabilities and misconfigurations, prioritize risks, and remediate with AI- driven workflows. Participants will learn how to run Prowler from the CLI and import findings into Prowler Cloud using the new Import Findings workflow. From there, the workshop will go beyond traditional compliance reporting and demonstrate Prowler's newer capabilities: Attack Paths for graph- based analysis of cloud resources, permissions, findings, and privilege-escalation chains; Lighthouse AI for natural-language investigation, environment-aware prioritization, and direct guided remediation grounded in Prowler Hub's deterministic database; and the Prowler Claude Code plugin/MCP workflow for bringing security triage, remediation guidance, automated pull- request generation from IaC scanner findings as well as live cloud scans, and re-scanning into the developer workflow. By the end, attendees will understand how to use Prowler not only to assess compliance against frameworks such as CIS, GDPR, HIPAA, and cloud security best practices, but also to identify which findings matter most, explain their blast radius, and accelerate remediation with open source tooling and controlled AI assistance.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Toni de la Fuente

Toni de la Fuente, Prowler’s open-source creator and CEO, has profoundly impacted cybersecurity. His AWS background and passion for FLOSS, cloud computing, and information security have fueled contributions to projects such as phpRADmin and Alfresco BART. An esteemed speaker at Black Hat and DEF CON, de la Fuente champions open-source solutions and advancements in cloud security.

SpeakerBio:  Amit Sharma

Amit Sharma has over a decade of experience as a cloud architect and built cybersecurity and observability products at Splunk, Cisco, and SentinelOne before joining Prowler as Head of Product.




Furs and Kinksters Meetup

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Friday, Aug 7, 15:00 – 15:59 PDT

Creator: Queercon Community



Gamer Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 11:40 – 11:50 PDT

Creator: The Diana Initiative

Interested in visiting Gamer Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Gamer Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



GE(O)SINT Contest

Creator Event Map Page – LVCCW Level 1 Hall 2 501 (Recon Village)
When:  Friday, Aug 7, 11:00 – 16:59 PDT

Creator: Recon Village

Test your geospatial intelligence skills in this unique contest. Identify locations, analyze imagery, and demonstrate your GeoINT expertise.




GE(O)SINT Contest

Creator Event Map Page – LVCCW Level 1 Hall 2 501 (Recon Village)
When:  Saturday, Aug 8, 11:00 – 16:59 PDT

Creator: Recon Village

Test your geospatial intelligence skills in this unique contest. Identify locations, analyze imagery, and demonstrate your GeoINT expertise.




Governing the Firehose: Writing Custom OPA Policies to Tame and Remediate Prowler Output

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) B
When:  Friday, Aug 7, 11:00 – 12:59 PDT

Creator: Cloud Village

When you run an opensource CSPM tool like Prowler across an cloud environment, you don’t get an audit; you get a tsunami of raw data. Sifting through thousands of JSON lines to determine what actually poses an active threat to your specific architecture is where most cloud defense pipelines break down.

In this 2-hour handson workshop, I’m going to show you how I bridge the gap between scanning and governance using Policy as Code. We will dive straight into treating Prowler’s raw security findings as structured data input for Open Policy Agent (OPA).

Together, we’ll write custom Rego policies from scratch to parse, filter and logically route Prowler results based on real world business context. I’ll show you how to write policies that evaluate infrastructure as code risk, suppress known risk acceptances safely and isolate critical failures (like exposed storage buckets or unencrypted databases) to trigger automated remediation workflows.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Ram “n2r”

Passionate about Linux, cryptography, and secure SDLC, I love digging into code, threat modeling, and breaking things (responsibly ofc). Whether it’s hardening apps or decoding exploits. I’m all about making software safer – one commit at a time.




Hack The Box DC Junior Ranger Program Challenge

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Noob Community
Hack The Box brings its Junior Ranger Program to DEF CON: a beginner-friendly challenge guide built by the Hack The Box team specifically for the Noob Village, modeled after the U.S. National Park Service’s Junior Ranger booklets. Work through the challenges in the guide and earn custom Junior Ranger badges as you complete them. Hack The Box is the leading cyber readiness platform for the agentic era, battle-testing and upskilling both humans and AI agents to enhance organizational cyber resilience.



Hack the Duck Store

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4
When:  Friday, Aug 7, 11:00 – 12:59 PDT

Creator: AppSec Village

At a developer meetup on secure software development, we asked a simple question: look at this login form, how could a hacker abuse it? Not one developer in the room dared to answer. The referral code field looked harmless. The backend had no validation: self-referrals, circular referrals, unlimited farming – all possible. It’s just the simplest example of how business logic flaws get missed. This card game is built around that gap, showing what business logic vulnerabilities might exist and how the real vulnerabilities, hiding inside the intentionally vulnerable app, Duck Store, can be abused.


People:
    SpeakerBio:  Gwendal Mognier

Gwendal Mognier is a Security Researcher at Escape. He’s passionate about cybersecurity and always eager to learn new ways to break and secure systems. Gwendal is focused on discovering vulnerabilities and helping improve security across the board.

SpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.




Hacker Book Club meet up

Creator Event Map Page – LVCCW Level 2 W209 (Diana Initiative)
When:  Saturday, Aug 8, 14:00 – 15:59 PDT

Creator: The Diana Initiative

Community is essential and so is continual learning. Reading books and discussing books can greatly impact an individual’s access and sense of community and knowledge. This Hacker Book Club book discussion will be an accessible group aiming to build community and share out learnings, all in a quieter setting. Come join us and discuss what you’ve been reading. We also run a year round Discord to discuss books throughout the year, hackerbookclub.com. This Hacker Book Club is not locked to a region and is for those who love books and escaping to the cyberpunk and scifi worlds that inspire DEF CON and modern literature. The DEF CON 34 theme is agency and our DEF CON themed book is The Dispossessed by Ursula Le Guin.

Links:
    Website – https://hackerbookclub.com/



Hacker Culture 101

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Saturday, Aug 8, 13:00 – 14:15 PDT

Creator: DCNextGen

Learn about the K-Rad side of hacking, from media representations in movies and tv shows, to hacker fashion throughout the years (we wear more than black hoodies!). In this session, we will also cover two iconic pieces of hacker culture- Handles and stickers, with an opportunity to make your own stickers and choose your unique handle! If you wanna jam with the console cowboys in cyberspace, this is the event for you!


People:
    SpeakerBio:  medus4
No BIO available



Hacker Runway Crafting Time

Creator Event Map Page – LVCCW Level 2 W209 (Diana Initiative)
When:  Friday, Aug 7, 10:00 – 11:59 PDT

Creator: The Diana Initiative

Hacker Runway Crafting time – didn’t have time, or didn’t know about the Hacker Runway competition? Have no fear we have some supplies to help you put together a last moment entry! Make sure to stop by the DC Maker Village as well!

Links:
    More Info – https://www.dianainitiative.org/events/tdi-def-con/hacker-runway



Hackers with Disabilities Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 13:20 – 13:30 PDT

Creator: The Diana Initiative

Interested in visiting Hackers with Disabilities but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Hackers with Disabilities and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Hacking Android Apps in a Structured Way

Creator Event Map Page – LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)
When:  Friday, Aug 7, 13:00 – 14:30 PDT

Creator: Mobile Hacking Community

Mobile app testing has many pitfalls and a structured approach is needed to get a holistic picture of the attack surface. The OWASP Mobile Application Security (MAS) project is able to support you with that. In this workshop, you’ll get a practical introduction to the MAS ecosystem which consists of the standard, mobile weaknesses and how to test them. You will experience test cases and demos for Android in action for static and dynamic analysis, and learn how to perform a mobile penetration test.

By the end of the workshop, attendees will be able to: – Navigate the OWASP Mobile Application Security (MAS) project (MASVS, MASWE, MASTG) and locate relevant test cases for their own engagements. – Apply a mix of static and dynamic analysis techniques against real Android apps. – Use the right tooling (e.g. frida, semgrep, APKLeaks, jadx, AI-assisted reverse engineering) in their pentest workflow.

Instructions: https://github.com/sushi2k/defcon34-android-workshop

Prerequisites: a laptop with 10 GB free disk space; GitHub account and git installed.


People:
    SpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).




Hacking iOS Apps in a Structured Way

Creator Event Map Page – LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)
When:  Saturday, Aug 8, 13:15 – 14:45 PDT

Creator: Mobile Hacking Community

Mobile app testing has many pitfalls and a structured approach is needed to get a holistic picture of the attack surface. The OWASP Mobile Application Security (MAS) project is able to support you with that. In this workshop, you’ll get a practical introduction to the MAS ecosystem which consists of the standard, mobile weaknesses and how to test them. You will experience test cases and demos for iOS in action for static and dynamic analysis, and learn how to perform a mobile penetration test on a non-jailbroken iOS device.

By the end of the workshop, attendees will be able to: – Navigate the OWASP Mobile Application Security (MAS) project (MASVS, MASWE, MASTG) and locate relevant test cases for their own engagements. – Apply a mix of static and dynamic analysis techniques against real iOS apps. – Use the right tooling (e.g. frida, radare2, AI-assisted reverse engineering) in their pentest workflow.

Instructions: https://github.com/sushi2k/defcon34-ios-workshop

Prerequisites: a laptop with 10 GB free disk space; GitHub account and git installed.


People:
    SpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).




Ham Radio Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 11:00 – 11:10 PDT

Creator: The Diana Initiative

Interested in visiting Ham Radio Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Ham Radio Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Hardhat How-to

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Friday, Aug 7, 12:00 – 12:59 PDT

Creator: Maker’s Village

Do you like hats? Hard Hat Brigade likes hats! Come hang with MrBill and m0nkeydrag0n as we work on building a hard hat and problem solve the build together. See you soon!


People:
    SpeakerBio:  m0nkeydrag0n
No BIO available
SpeakerBio:  MrBill
No BIO available



HHV/SSV Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 11:40 – 11:50 PDT

Creator: The Diana Initiative

Interested in visiting HHV/SSV but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to HHV/SSV and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Hook, Line & Pretext Workshop: Crafting Effective Phish

Creator Event Map Page – LVCCW Level 3 W320 (Social Engineering Community Village Labs)
When:  Saturday, Aug 8, 13:30 – 14:59 PDT

Creator: Social Engineering Community Village

Every effective phishing email is really a marketing email with a hostile goal. It wins attention, builds desire, and drives a single click. This hands-on introductory workshop pulls back the curtain on that craft. In 90 minutes you’ll learn the persuasion techniques that make a lure irresistible, borrowed straight from the sales and marketing playbook: the handful of influence levers that actually move people, the copywriting structure behind a high-converting message, and the emotional triggers that turn a glance into a click. Then you’ll add the ingredient that separates a generic blast from a believable one, which is context, using open-source intelligence (OSINT) to tie a lure to a real department, location, or current event so it feels timely and true. You won’t just watch. After we run the full method end to end against a familiar fictional target, the Scranton branch of Dunder Mifflin, you’ll roll up your sleeves and build your own department or location wide pretext against a real organization you know. You’ll walk out able to reason about why people click, not just that they do, with a repeatable process and a finished lure you can take straight back to your own awareness program. This is a content-creation and analysis workshop. No live phishing is conducted and no email is ever sent. Who it’s for: Aspiring and early-career security practitioners, security-awareness and blue-team staff who want to think like an attacker, IT professionals moving toward security, and students or career-changers exploring offensive security. Anyone who builds or improves a phishing-awareness program will get direct, practical value. Level and prerequisites: Introductory. No prior phishing, red-team, or OSINT experience required. You should be comfortable using a web browser and reading professional email. Nothing to install, no coding, no command line. What to bring � A laptop with a web browser, for light open-source research during the lab � A real organization you know: your employer, your school or university, a nonprofit or club you belong to, or a former workplace, etc. � Something to write with. All worksheets are provided � Curiosity and a willingness to share your draft for friendly peer feedback What you’ll leave with � The three-gates test (legality, then ethics, then morality) for vetting any campaign before it runs � A working command of the four influence levers that drive clicks and the “one hook, one ask, one button” rule for writing them � A repeatable OSINT-to-pretext method for making lures timely and relevant to a department or location � A completed Pretext Canvas and a draft, awareness-grade phishing email you can optionally submit to your own organization’s security-awareness program Format and duration: A hands-on 90 minutes: about 30 minutes of instruction, a 10-minute guided case study against Dunder Mifflin, and roughly 50 minutes of lab with peer review and debrief. What this workshop is not: It’s not a tooling or infrastructure course. There are no phishing frameworks, payloads, landing pages, or email spoofing. It’s not spear-phishing of named individuals; the focus is wide-net, department and location-level pretexts. And nothing is ever sent.


People:
    SpeakerBio:  Jenn

Jenn (@_nextjenn) is a Senior Offensive Security Consultant and a DEF CON Black Badge holder, earned by winning the vishing competition. With over a decade of cybersecurity experience, she specializes in social engineering, physical security testing, and network penetration testing. Leveraging her background in psychology and experience as a licensed Private Investigator and Locksmith, she has led sophisticated red team engagements across physical penetration testing, phishing, vishing, and deepfake-driven operations. An active mentor and coach in the social engineering community, Jenn has judged DEF CON’s 2024 “Humans vs AI” and 2025 Vishing competitions and shares insights through podcasts and conference talks, including Wild West Hackin’ Fest and San Diego Comic-Con.

SpeakerBio:  JC, President at Snowfensive

JC is a U.S. Marine Corps veteran, President of Snowfensive, and co-founder of the Social Engineering Community Village at DEF CON. With more than a decade of experience spanning information technology, digital forensics, incident response, penetration testing, and social engineering, he specializes in turning complex security concepts into practical skills people can immediately apply.

At Snowfensive, JC oversees the company’s offensive security services, including phishing, vishing, physical social engineering, covert entry assessments, and technical penetration testing across networks, wireless environments, and applications. He has designed and led human-focused security engagements for organizations across a wide range of industries, combining technical tradecraft with a practical understanding of how people, processes, and technology intersect.




ICS Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 11:50 – 11:59 PDT

Creator: The Diana Initiative

Interested in visiting ICS Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to ICS Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



IDEViewer – Securing Developer Workstations from IDE Supply Chain Threats

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Friday, Aug 7, 15:15 – 16:15 PDT

Creator: AppSec Village

IDEViewer is an open-source, cross-platform security tool that continuously monitors developer workstations for supply chain threats originating from IDE extensions, software dependencies, plaintext secrets, and AI development tools.

Developer IDEs have become a high-value attack surface. Malicious or over-permissioned VS Code extensions can execute arbitrary code, exfiltrate secrets, and establish persistence. npm lifecycle hooks in dependencies run silently during install. AI coding assistants like Claude Code, Cursor, and MCP servers introduce new data exfiltration vectors through unchecked permissions and network access. IDEViewer addresses this blind spot by scanning extensions across 7+ IDEs, analyzing their permissions against a risk model, detecting plaintext secrets, inventorying all installed packages (including those bundled inside extensions), monitoring for git hook bypasses, and detecting AI tool configurations with their associated permissions.


People:
    SpeakerBio:  securient

Vinod is a Staff Security Engineer at PIP Labs and IEEE Senior Member with over a decade of cybersecurity experience spanning financial services, government, and tech. His career across Amazon, Zapier, and HackerOne has built deep expertise in penetration testing, cloud security architecture, and application security across AWS, GCP, and Azure — now applied at the intersection of traditional enterprise security and Web3/blockchain infrastructure. He is an author and reviewer for the HTTP Archive’s Web Almanac, organizer of the Blockchain Security Village at Seasides, and creator of the open-source API Doc Converter Burp Extension. He actively contributes to the security community through writing on Medium, bug bounty programs, and mentoring aspiring security professionals.




Illumicon Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 14:00 – 14:10 PDT

Creator: The Diana Initiative

Interested in visiting Illumicon but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Illumicon and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Improv

Creator Event Map Page – LVCCW Level 3 W317-319 (Social Engineering Community Village)
When:  Friday, Aug 7, 12:00 – 12:59 PDT

Creator: Social Engineering Community Village

Join Bryan and Kevin for a fun, low-pressure improv showdown where quick reactions, creative thinking, and social engineering skills take center stage.




In Untrust We Can Trust: Enforcing Trust Boundaries for Humans and AI Alike

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Saturday, Aug 8, 10:15 – 11:15 PDT

Creator: AppSec Village

We keep saying “never trust user input.” Yet our frameworks still do not differentiate between trusted data and attacker-controlled data.

OWASP Untrust is an OWASP umbrella project built around a simple invariant: all data is implicitly untrusted and may cross security boundaries only through deliberate, verifiable trust transitions.

Through projects like VV (Validated Values) and BoxedPath, implemented across Python, Java, C#, C++, and Node.js, Untrust makes unsafe states structurally difficult to represent.

Instead of detecting vulnerabilities after they are written, Untrust enforces trust boundaries by construction for humans and AI alike.


People:
    SpeakerBio:  Yariv Tal

Yariv Tal is a senior developer, security researcher, and cofounder of Secure From Scratch, a venture dedicated to teaching developers secure coding from the very first line of code.

A summa cum laude graduate of the Technion, Yariv brings four decades of programming experience and years of university lecturing and bootcamp mentoring to the field of application security.

He lectures on secure coding in academia and the private sector, leads the OWASP-untrust project, and researches the intersection of AI and application security, with a focus on secure code generation, LLM evaluation, and secure-by-construction development.




Intro to Lockpicking

Creator Event Map Page – LVCCW Level 1 Hall 1 407 (Lockpick Village)
When:  Friday, Aug 7, 13:00 – 13:30 PDT
Saturday, Aug 8, 15:00 – 15:30 PDT
Saturday, Aug 8, 10:15 – 10:45 PDT
Friday, Aug 7, 14:30 – 14:59 PDT
Friday, Aug 7, 16:00 – 16:30 PDT
Sunday, Aug 9, 10:15 – 10:45 PDT
Friday, Aug 7, 10:15 – 10:45 PDT
Sunday, Aug 9, 13:00 – 13:30 PDT

Creator: Lockpick Village

New to lock picking? Haven’t picked in a year and need a refresher? Don’t know a half-diamond from a turner? This talk is for you! Join one of our knowledgeable village volunteers as we walk you through the very basics of lock picking, from how to hold your tools to the theory behind the technique that makes lock picking possible.




Intro to Scratch

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Saturday, Aug 8, 10:00 – 10:30 PDT

Creator: DCNextGen

Are you interested in learning to code but don’t know where to begin? This class introduces Scratch, a free visual programming language developed by MIT, and is intended for youth ages 8-16. Use real coding concepts and blocks to develop interactive stories, games, and animations. Come learn how to begin coding in a fun and engaging way and join in with millions of your new global peers. You will need a laptop with Chrome or Edge.


People:
    SpeakerBio:  N3rd H3Rder
No BIO available



IOT Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 10:10 – 10:20 PDT

Creator: The Diana Initiative

Interested in visiting IOT Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to IOT Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Kryptsec Labs

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Noob Community

Kryptsec started as a Discord server for people who wanted to learn cybersecurity together and has grown into a company focused on making security training engaging rather than monotonous, including hands-on, AI-assisted CTF labs and OASIS, its open-source tool for benchmarking AI agent vulnerabilities. Stop by the Kryptsec Labs table during village hours to work through their hands-on challenges.




KSCM Scambait Radio

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Scambait Village

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.

Links:
    scambaitvillage.org/radio – https://scambaitvillage.org/radio



KSCM Scambait Radio

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Sunday, Aug 9, 10:00 – 15:59 PDT

Creator: Scambait Village

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.

Links:
    scambaitvillage.org/radio – https://scambaitvillage.org/radio



KSCM Scambait Radio

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Scambait Village

Prerecorded scambait calls running in Discord voice throughout the day. Bring earbuds and tune in from your phone while you walk the village or the rest of the con. Listen to real interactions, hear how experienced baiters handle different situations, and pick up new techniques and banter styles. Ambient and educational, drop in for a few minutes or stay for a whole set.

Links:
    scambaitvillage.org/radio – https://scambaitvillage.org/radio



Kubernetes CTF at DEF CON Contest Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 12:00 – 12:10 PDT

Creator: The Diana Initiative

Interested in visiting Kubernetes CTF at DEF CON Contest but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Kubernetes CTF at DEF CON Contest and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



La Villa Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 13:50 – 13:59 PDT

Creator: The Diana Initiative

Interested in visiting La Villa but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to La Villa and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Last chance to pick up drives at the DDV

Creator Event Map Page – LVCCW Level 2 W203 (Data Duplication Village)
When:  Sunday, Aug 9, 10:00 – 10:59 PDT

Creator: Data Duplication Village

This is your last chance to pickup your drives whether they’re finished or not. Get here between 10:00am and 11:00am on Sunday as any drives left behind are considered donations.




Let’s Play! OWASP Cornucopia for Mobile Application Security Threat Modeling

Creator Event Map Page – LVCCW Level 1 Hall 4 1415 (OWASP Foundation)
When:  Saturday, Aug 8, 10:00 – 10:59 PDT

Creator: OWASP Foundation

Think threat modeling can’t be fun? Think again! Join us for an interactive OWASP Cornucopia for Mobile Application Security game session, with OWASP MAS/MASTG core team member, Sven Schleier, where you’ll team up to uncover security risks, challenge assumptions, and sharpen your secure design skills through friendly competition. Whether you’re a developer, security professional, or just curious about mobile application security, come play, collaborate, and experience one of the most engaging ways to learn threat modeling.


People:
    SpeakerBio:  Sven Schleier, Co-Founder at Bai7 GmbH

Sven has been involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project lead and author, he has made significant contributions to the OWASP MAS (Mobile Application Security) project, which is considered the industry standard for mobile application security, see https://mas.owasp.org.

Sven is a frequent speaker and trainer around the world. His audiences range from software developers to students and penetration testers. His engagements often take him to conferences, forums and educational institutions, where he shares his extensive knowledge and insights on mobile and application security.

Sven is a co-founder of Bai7 GmbH in Austria, which is specialized in trainings and advisory. He has expertise in cloud security, offensive security engagements (Penetration Testing) and Application Security, notably in guiding software development teams across Mobile and Web Applications throughout the Software Development Life Cycle (SDLC) to integrate robust security measures in from the start.

Besides his day job, Sven is involved with the Open Worldwide Application Security Project (OWASP) since 2016. As a co-project leader and author, he has significantly contributed to the OWASP Mobile Application Security Testing Guide (MASTG) and the OWASP Mobile Application Security Verification Standard (MASVS).




Let’s Play! OWASP Cornucopia Threat Modeling

Creator Event Map Page – LVCCW Level 1 Hall 4 1415 (OWASP Foundation)
When:  Sunday, Aug 9, 12:00 – 12:59 PDT

Creator: OWASP Foundation

Think threat modeling can’t be fun? Think again! Join us for an interactive OWASP Cornucopia 3.0 game session where you’ll team up to uncover security risks, challenge assumptions, and sharpen your secure design skills through friendly competition. Whether you’re a developer, security professional, or just curious about application security, come play, collaborate, and experience one of the most engaging ways to learn threat modeling.




Lightning Talks and Unconference

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Saturday, Aug 8, 17:00 – 17:30 PDT

Creator: Nix Vegas Community

Give a talk about whatever you want, as long as it’s less than 10 minutes! Or just come and chill in the Nix Vegas space for the Unconference.




Lightning Talks and Unconference

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Friday, Aug 7, 17:00 – 17:59 PDT

Creator: Nix Vegas Community

Give a talk about whatever you want, as long as it’s less than 10 minutes! Or just come and chill in the Nix Vegas space for the Unconference.




Live Call Listening

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Friday, Aug 7, 14:00 – 17:59 PDT

Creator: Scambait Village

A separate Discord channel running live calls, no recordings, listen-only. Runs periodically through Friday afternoon once the Live Calls Workshop wraps. Sometimes it is experienced baiters working a scammer in real time. Sometimes it is one of our bots, of which there are nearly 80 unique builds developed from call recordings captured during live baits. No participation, no signup, nothing required of you but earbuds. Good for anyone who would rather listen than talk.

Links:
    scambaitvillage.org/join – https://scambaitvillage.org/join



Live Recon Contest — Final Presentations

Creator Event Map Page – LVCCW Level 1 Hall 2 501 (Recon Village)
When:  Saturday, Aug 8, 16:00 – 16:59 PDT

Creator: Recon Village

Final presentations for the Live Recon Contest. Participants present their findings in front of a jury.




Live Recon Contest

Creator Event Map Page – LVCCW Level 1 Hall 2 501 (Recon Village)
When:  Saturday, Aug 8, 12:00 – 13:59 PDT

Creator: Recon Village

Do you fancy doing live recon on Real Organizations? Activate Yourself. And compete in a unique HACKER challenge. Participants will perform live reconnaissance on a specified list of companies. Your mission is to unearth as much critical information as possible. Contest continues from Friday and ends Saturday at 2:00 PM.




Live Recon Contest

Creator Event Map Page – LVCCW Level 1 Hall 2 501 (Recon Village)
When:  Friday, Aug 7, 10:00 – 23:59 PDT

Creator: Recon Village

Do you fancy doing live recon on Real Organizations? Activate Yourself. And compete in a unique HACKER challenge. Participants will perform live reconnaissance on a specified list of companies. Your mission is to unearth as much critical information as possible. Contest runs overnight from Friday into Saturday.




Locked Out? Let’s Fix That: An Introduction to the Art of Lockpicking

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Friday, Aug 7, 13:00 – 13:30 PDT

Creator: DCNextGen

Ever wondered what’s actually happening inside that padlock when you turn the key? This hands-on class pulls back the curtain on one of the oldest security technologies humans ever built — and shows you exactly how (and why) it can be defeated. You’ll get the fundamentals, then the lab to experiment and learn, with several individuals around to help guide you and answer questions


People:
    SpeakerBio:  Greg Anderson
No BIO available



Lonely Hackers Club – CTF Winners Announcement

Creator Event Map Page – LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)
When:  Sunday, Aug 9, 12:00 – 12:59 PDT

Creator: Lonely Hackers Club



Lonely Hackers Club – Lockpicking Table

Creator Event Map Page – LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Lonely Hackers Club

Learn new skills and find new friends at our lockpicking table. We provide you with beginner friendly locks, picks, and experienced volunteers to guide you through the process. Bring your own equipment to talk shop and get some new perspectives.

Links:
    LHC Website – https://lonelyhackers.club/



Lonely Hackers Club – Sticker Swap Table

Creator Event Map Page – LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Lonely Hackers Club

DEF CON and stickers can’t be separated. Visit our sticker swap table to get your hands on the latest sticky art and exchange the ones you made yourself. Check in regularly to get a chance to find rare gems.

Links:
    LHC Website – https://lonelyhackers.club/



Lonely Hackers Club CTF

Creator Event Map Page – LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)
When:  Sunday, Aug 9, 10:00 – 11:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Lonely Hackers Club

We welcome all skill levels, from first-time DEF CON attendees to experienced CTF competitors. The challenges are layered, so newcomers can get meaningful wins while veterans still find plenty to chew on. Participants often team up spontaneously on location, making it as much a social experience as a technical one. Participate for a chance to get awesome prizes!

Links:
    More Info – https://lonelyhackers.club/ctf/



Makers’ Village – Hacker Arts and Crafts

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Maker’s Village

Soldering SAO, Embroidery Machine, Laser Etcher, 3d Printers, Trade Table, Letter Bracelets, FuzeBeads, Stamp Making, Bottle Cap Resin Magnets, and Silk Screening throughout the weekend as volunteer permits.




Malware Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 12:10 – 12:20 PDT

Creator: The Diana Initiative

Interested in visiting Malware Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Malware Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Maritime Hacking Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 11:30 – 11:40 PDT

Creator: The Diana Initiative

Interested in visiting Maritime Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Maritime Hacking Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



MEACS Trivia, Games and Networking

Creator Event Map Page – LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)
When:  Sunday, Aug 9, 13:00 – 13:59 PDT

Creator: Middle Easterns & Africans in Cyber Security (MEACS)

Test what you know and meet the people who know the rest. Bring your team or find one when you get there for a few rounds of security trivia, from the history this community is built on to the attacks making headlines right now. Expect a friendly, competitive crowd, bragging rights on the line, and plenty of time to connect with other Middle Eastern and African practitioners and friends of the community between rounds. Whether you came to win or just to find your people, pull up a chair.




MEACS Trivia, Games and Networking

Creator Event Map Page – LVCCW Level 1 Hall 4 1306 (Middle Easterns & Africans in Cyber Security (MEACS) Community)
When:  Saturday, Aug 8, 17:00 – 17:59 PDT

Creator: Middle Easterns & Africans in Cyber Security (MEACS)

Test what you know and meet the people who know the rest. Bring your team or find one when you get there for a few rounds of security trivia, from the history this community is built on to the attacks making headlines right now. Expect a friendly, competitive crowd, bragging rights on the line, and plenty of time to connect with other Middle Eastern and African practitioners and friends of the community between rounds. Whether you came to win or just to find your people, pull up a chair.




MEACS: Middle Easterns & African in Cyber Security Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 10:10 – 10:20 PDT

Creator: The Diana Initiative
Interested in visiting MEACS: Middle Easterns & African in Cyber Security but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to MEACS: Middle Easterns & African in Cyber Security and be introduced to the community and activities inside!
Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Men Loving Men Meetup

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Saturday, Aug 8, 15:00 – 15:59 PDT

Creator: Queercon Community



Mentoring and Career Advice

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Noob Community

Informal, one-on-one conversations with volunteer mentors and speakers about breaking into cybersecurity, career pivots, resumes, certifications, and next steps. No appointment needed — just come find a mentor in the village during open hours.




Meshpocalypse: Building Your Own Off-Grid Hacker Network

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Saturday, Aug 8, 11:00 – 11:45 PDT

Creator: DCNextGen

Join Adventures of Illya for Meshpocalypse! The internet goes down. Cell towers die. How do hackers still talk? In Meshpocalypse, we’ll use tiny radios and cheap hardware to build a mini off-grid network right in the room. You’ll learn how mesh networks work, try out Meshtastic, and send messages without Wi-Fi or cell data. Each attendee will help build and keep their own radio node device so they can keep experimenting after DEF CON. No experience needed. Basic tech comfort helps but isn’t required. Defcon and I will provide all radios. Each attendee should bring a small USB-C power source (like a power bank or USB-C wall adapter) to power their device. Only 30 radio units available, first come first served.


People:
    SpeakerBio:  Adventures of Illya
No BIO available



Mission: Compromised – Hacking a Satellite from the Ground Up

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Aerospace Village

Ever wondered what it takes to hack a satellite? At this hands-on station, you’ll step into the role of an attacker targeting a CubeSat-class spacecraft and its ground control station — all running in a safe, fully isolated environment.

Working against a live mission control system (OpenC3 COSMOS / Yamcs) and a spacecraft simulator, you’ll follow an attacker’s kill chain across multiple layers — from reconnaissance and ground station compromise all the way to the spacecraft itself. Where does it end? Let’s just say the mission doesn’t survive. Come find out how. Every step is paired with the real-world defense that would have stopped it – so you’ll leave understanding both how these attacks work and how space systems defend against them. Whether you’re new to space security or already deep in the field, come try it out, break a satellite (safely!), and see the attack surface of modern spacecraft up close.

It will take approximately 15-30 minutes to work through this hands-on demo and guided exercises. You can watch attacks demonstrated by our team, then try guided scenarios yourself using real CCSDS space protocols, RF concepts, and industry mission control tooling. A live mission dashboard will reveal the spacecraft’s fate as the scenario plays out.

No prior space experience required – all skill levels welcome. We recommend you bring your own laptop the hands-on portions. A laptop with GNU Radio will let you dig into the RF challenge, and a Kali Linux setup or your equivalent pentesting toolkit are recommended for the more advanced challenge.




Mobile Hacking – Informal CTF

Creator Event Map Page – LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 11:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Mobile Hacking Community

Capture the Flag (CTF) events featuring mobile application security challenges at varying levels of difficulty, also providing a ranking system to evaluate and compare participants’ skills.

Links:
    Discord – https://discord.gg/dHW7PVSCzY



Mobile Hacking Community – Open

Creator Event Map Page – LVCCW Level 1 Hall 4 1422 (Mobile Hacking Community)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Mobile Hacking Community

At the Mobile Hacking Community, attendees will learn about the latest trends in mobile application security through hands-on experiences, including topics such as bypassing security mechanisms and hardening techniques, and exploiting known CVEs.

Additionally, attendees will engage in a competitive process by participating in an onsite CTF (Capture the Flag) event to test their skills, face new challenges, and learn new skills.

Attendees will also have the opportunity to watch cutting-edge research presentations and case studies on various topics within the domain.

Dedicated real devices running vulnerable applications will be available, allowing attendees to actively practice exploitation and analysis in a realistic environment.

Prerequisites:

  • Attendees should bring their own laptop in order to fully participate in the hands-on workshops and CTF challenges.
  • A basic familiarity with using a command line, installing software, and general computing concepts is recommended, but prior mobile security experience is not required.



Mobile Hacking Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 11:20 – 11:30 PDT

Creator: The Diana Initiative

Interested in visiting Mobile Hacking but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Mobile Hacking and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



MOUSE Runner & Flappy Drone

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Aerospace Village

How High Can You Make a Satellite Jump? Can You Fly a Drone Around Aliens and Rockets?

Put your action-hero reflexes and hand-eye coordination to the test as you battle fellow DEF CON attendees for the top scores in MOUSE Runner and Flappy Drone. The highest scores on Friday and Saturday will earn a special prize. Stop by our booth to learn more, show off your button-mashing skills, and prove you’re the ultimate space cyber pilot.




Nebula Showdown: Space Systems Security CTF Adventure

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Aerospace Village

Join the Aurora Alliance in their critical mission to thwart the notorious Nebula Syndicate and save the Earth! The Syndicate threatens to destroy historic monuments around the world with their Space Laser unless their demands are met. Do you have what it takes to dismantle their malevolent plans and deorbit a menacing space threat?

This entry-level CTF kicks off as soon as the village opens – no pre-registration necessary. Just bring your laptop and your go-to cybersecurity tools – Wireshark, NMAP, and any FTP client you prefer. We know the DEF CON wifi can be unpredictable, so this CTF will be local only to the Aerospace village via an isolated local range. The CTF is designed to be completed in under an hour, making it perfect for a quick yet engaging challenge. Team collaboration is encouraged, and if you encounter obstacles, numerous hints are available to guide you. There are no penalties for using hints. Our goal is for you to learn something new and make it all the way through the CTF. Excel in the challenge, and you could walk away with an exclusive CT Cubed SAO prize while supplies last.




Nix Vegas Closing Ceremony

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Sunday, Aug 9, 13:00 – 13:30 PDT

Creator: Nix Vegas Community

Closing out Nix Vegas at DEF CON 34




Nix Vegas Opening Ceremony

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Saturday, Aug 8, 10:00 – 10:30 PDT

Creator: Nix Vegas Community

Kickoff and opening of the Nix Vegas space on Saturday.




Nix Vegas Opening Ceremony

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Friday, Aug 7, 10:00 – 10:30 PDT

Creator: Nix Vegas Community

Kickoff and opening of the Nix Vegas space on Friday, and start of the Nix CTF!


People:
    SpeakerBio:  Daniel Baker

Daniel Baker is a developer, engineer, and mathematician passionate about reproducible software. An active NixOS community member and educator, he authored the NixCon NA 2024 Nix module system workshop and nixos-modules-lessons. He serves on the NixOS Marketing Team and helps organize both Nix Vegas and Planet Nix. He believes any system worth building is worth rebuilding, bit for bit.

SpeakerBio:  Morgan Jones

Embedded security engineer who does too many weird things with Nix.

SpeakerBio:  Tristan Ross

I work on supply chain security at Determinate Systems.




No Stupid Questions

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Noob Community

Ongoing AMA booth with volunteers and speakers answering all your DEF CON and cyber questions




Non-Binary/Gender Non-conforming Meetup

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Friday, Aug 7, 13:00 – 13:59 PDT

Creator: Queercon Community



Novice design in 3d space

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Sunday, Aug 9, 12:00 – 12:59 PDT

Creator: Maker’s Village

Broad to narrow review of several 3d design programs such as Fusion, Onshape, FreeCAD, TinkerCAD, and OpenSCAD and an assessment of their features and flaws. An Onshape account is recommended prior to attending the workshop.


People:
    SpeakerBio:  RedThorn
No BIO available



NPM Imposters – The malware detection card game

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4
When:  Sunday, Aug 9, 11:00 – 12:59 PDT

Creator: AppSec Village

NPM Imposters is a fast-paced educational card game designed to teach players about supply chain security risks in software development, particularly through malicious NPM packages.


People:
    SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.




NPM Imposters – The malware detection card game

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4
When:  Friday, Aug 7, 15:00 – 16:59 PDT

Creator: AppSec Village

NPM Imposters is a fast-paced educational card game designed to teach players about supply chain security risks in software development, particularly through malicious NPM packages.


People:
    SpeakerBio:  Mackenzie

Mackenzie is a developer advocate with a passion for DevOps and code security. As the co-founder and former CTO of a health tech startup, he learnt first-hand how critical it is to build secure applications with robust developer operations.

Today as the Developer Advocate at GitGuardian, Mackenzie is able to share his passion for code security with developers and works closely with research teams to show how malicious actors discover and exploit vulnerabilities in code.




Objectively Awesome Robots: A Hands-On Introduction to Python Classes and Objects

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Saturday, Aug 8, 17:00 – 17:45 PDT

Creator: DCNextGen

Python has rules and structure like any language, but we’re skipping the boring grammar lesson. You’ll jump straight into building a robot that appears on your screen and comes to life as you code it. As you customize and experiment, you’ll naturally learn classes and objects by using them to define your robot’s appearance and behavior. At the end, we’ll finish with a Kahoot challenge where you’ll test your new skills and compete for prizes.

Requirements/Prerequisites: A laptop with a USB port (for workshop files) Python 3 installed and able to run VS Code or another IDE that supports Jupyter Notebooks Some basic Python experience is helpful, but not required, we’ll provide a cheat sheet to help you along


People:
    SpeakerBio:  4ng3lhacker
No BIO available



OCIguana – A vulnerable-by-design OCI lab

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) A
When:  Saturday, Aug 8, 16:00 – 17:59 PDT

Creator: Cloud Village

This workshop will discuss Oracle Cloud Infrastructure (OCI) and its unique take on IAM in [kcomparison to other major cloud providers. We will explore how OCI’s policy language, dynamic groups, and principal types (instance principals, resource principals) create an attack surface that differs from other major cloud providers. Attendees will also get hands-on experience with attacking OCI environments by completing a vulnerable-by-design lab, designed to highlight the unique design decisions of OCI and its IAM system in general.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Eli Shparaga

Eli Shparaga is a Security Researcher in XM Cyber, specializing in cloud and AI security. His work involves identifying attack vectors and adversarial tactics in major cloud providers. Before that, Eli worked as a red teamer, helping secure multiple Fortune 500 companies.




Oh hai! Meet Jason Haddix

Creator Event Map Page – LVCCW Level 1 Hall 4 1415 (OWASP Foundation)
When:  Saturday, Aug 8, 12:00 – 12:59 PDT

Creator: OWASP Foundation

Ever spotted someone from InfoSec Twitter in the wild and chickened out on saying hi? Yeah, us too. Come embrace the social awkwardness in a safe space where everyone’s just as nervous as you are – but also just as excited to connect. We’re gathering the chronically online, the terminally technical, and even the legend himself, @JHaddix. Haddix is dropping by for an hour, come and say hai!


People:
    SpeakerBio:  Jason “jhaddix” Haddix, CEO and “Hacker in Charge” at Arcanum Information Security

Jason Haddix AKA jhaddix is the CEO and “Hacker in Charge” at Arcanum Information Security. Arcanum is a world class assessment and training company.

Jason has had a distinguished 20-year career in cybersecurity previously serving as CISO of FLARE, CISO of Buddobot, CISO of Ubisoft, Head of Trust/Security/Operations at Bugcrowd, Director of Penetration Testing at HP, and Lead Penetration Tester at Redspin. He has also held positions doing mobile penetration testing, network/infrastructure security assessments, and static analysis. Jason is a hacker, bug hunter and currently ranked 57th all-time on Bugcrowd’s bug bounty leaderboards. Currently, he specializes in recon, web application analysis, and emerging technologies. Jason has also authored many talks on offensive security methodology, including speaking at cons such as DEFCON, Bsides, BlackHat, RSA, OWASP, Nullcon, SANS, IANS, BruCon, Toorcon and many more.




Oh hai! Meet Tanya “SheHacksPurple” Janca

Creator Event Map Page – LVCCW Level 1 Hall 4 1415 (OWASP Foundation)
When:  Saturday, Aug 8, 11:00 – 11:59 PDT

Creator: OWASP Foundation

Ever spotted someone from InfoSec Twitter in the wild and chickened out on saying hi? Yeah, us too. Come embrace the social awkwardness in a safe space where everyone’s just as nervous as you are – but also just as excited to connect. We’re gathering the chronically online, the terminally technical, and even the legend herself, SheHacksPurple (Tanya Janca). Tanya is dropping by for an hour, come and say hai!


People:
    SpeakerBio:  Tanya “SheHacksPurple” Janca

Tanya Janca, known online as SheHacksPurple, is the best-selling author of Alice and Bob Learn Secure Coding and Alice and Bob Learn Application Security. She is the CEO of She Hacks Purple Consulting, where she delivers high-impact, live, secure-coding training for engineering teams. She is also the host of DevSec Station Podcast.

Over 29 years in the industry Tanya has received numerous awards, spoken at events worldwide, and built a reputation as one of the most approachable and influential voices in application security. She has trained thousands of developers and security practitioners through her academies and live programs. Her experience includes counter-terrorism work, leading security for the 42nd Canadian federal election, as well as building and securing a vast range of applications. Today, she is recognized internationally as a leading authority on the security of software.




Open Q&A

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Sunday, Aug 9, 10:00 – 15:59 PDT

Creator: Scambait Village

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.

Links:
    scambaitvillage.org – https://scambaitvillage.org



Open Q&A

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Scambait Village

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.

Links:
    scambaitvillage.org – https://scambaitvillage.org



Open Q&A

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Scambait Village

Drop-in Q&A running throughout the village whenever the hall is open. Knowledgeable volunteers are stationed across the booth and can answer questions about scambaiting techniques, tools, safety, community norms, legal considerations, and anything else related to fighting scammers. No session times, no signup. Come by whenever, ask whatever. Casual and welcoming for both newcomers and veterans. Note that Q&A pauses briefly during scheduled talks and sessions at the village, listed separately on this schedule.

Links:
    scambaitvillage.org – https://scambaitvillage.org



Operation Restoration

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Saturday, Aug 8, 14:15 – 14:45 PDT

Creator: Maker’s Village

Every forgotten machine has a story—and a second chance. This talk explores the multidisciplinary maker ethos through restoration: where machining, woodworking, sewing, CAD, 3D printing, and whatever other skills you have in your toolbox come together to resurrect forgotten machines and breathe new life into once-loved objects.


People:
    SpeakerBio:  Cannibal
No BIO available



OSINT Search Party CTF Prize and Award Announcements.

Creator Event Map Page – LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)
When:  Saturday, Aug 8, 17:00 – 17:15 PDT

Creator: OSINT For Good Community

Prizes and awards from the Gobal OSINT Search Party CTF will be announced.




OSINT4Good Community – DC NextGen Content

Creator Event Map Page – LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: OSINT For Good Community

Make this a stop on your DC NextGen journey, solve the challenge, and earn a digital badge!




OSINT4Good Sticker Swap

Creator Event Map Page – LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)
When:  Saturday, Aug 8, 17:15 – 17:59 PDT

Creator: OSINT For Good Community

Bring some stickers, take some stickers. There will be some specially themed OSINT4Good stickers available only here!




OWASP AIBOM Generator

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Saturday, Aug 8, 14:00 – 14:59 PDT

Creator: AppSec Village

AI systems increasingly depend on opaque model, dataset, and tooling supply chains, but most teams still lack a practical way to capture what is inside them. This Arsenal session demonstrates the OWASP AIBOM Generator, an open-source tool from the OWASP GenAI Security Project that creates CycloneDX-based AI Bills of Materials (AIBOM) for AI/ML assets. Attendees will see how to generate AIBOMs that can support AI transparency, security review, governance, incident response, and software supply chain risk management without turning the process into a manual documentation review exercise.


People:
    SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.

SpeakerBio:  Helen Oakley

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.




OWASP Chapter Meetup

Creator Event Map Page – LVCCW Level 1 Hall 4 1415 (OWASP Foundation)
When:  Sunday, Aug 9, 11:00 – 13:59 PDT

Creator: OWASP Foundation

This one’s for the chapter leads, the regulars, the new folks, and everyone who makes OWASP what it is. Join us at DEFCON 33 for a meetup made to foster connection between OWASP chapters. It’s a chance to share wins, swap challenges, build relationships, and spark ideas that reach beyond our local scenes. Whether you’re repping your city or just curious about how others are building community, pull up. The global OWASP family is real—and this is where we get to feel it.




OWASP FinBot CTF: Hands-On Agentic AI Threats

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Saturday, Aug 8, 12:45 – 13:45 PDT

Creator: AppSec Village

OWASP FinBot is an intentionally vulnerable agentic AI application designed to teach real-world security risks in AI agents beyond prompt injection alone. This Arsenal session demonstrates how an AI assistant connected to business tools can be manipulated through indirect prompts, unsafe tool use, broken authorization, and weak runtime controls. Attendees will see and experience first-hand how attacker-controlled inputs can influence agent behavior, trigger unsafe actions, and expose sensitive data.


People:
    SpeakerBio:  Helen Oakley

Helen Oakley, CISSP, GPCS, GSTRT, works at the intersection of AI, cybersecurity, and software supply chains—where the rules are still being written. At SAP, she leads a global team of architects, security experts, and scientists, securing development and pipelines at scale. Helen is part of the core leadership team of the OWASP GenAI Security Project and co-leads initiatives on AIBOM and Agentic Security, contributes into industry papers like Agentic AI Threats & Mitigations Guide, OWASP Top 10 for Agentic Apps, and more. Helen has co-led AIBOM efforts with CISA, and is the original creator of the OWASP FinBot CTF and the first open-source OWASP AIBOM Generator for Hugging Face models. Named one of the Top 20 Canadian Women in Cybersecurity, she co-founded LeadingCyberLadies.com to support the next wave of builders, breakers, and leaders.

SpeakerBio:  saikishu

Venkata Sai Kishore Modalavalasa is Chief Architect & Engineering Leader at Straiker, building AI security products for AI-native apps at scale. With 15+ years in cybersecurity and distributed systems, he scaled Cyberfend to acquisition by Akamai, where he led bot detection and web security engineering. He’s an OWASP author contributing to AI Exchange, AIBOM, Top 10 for Agentic Applications, OWASP GenAI Security Project, creator and co-lead of OWASP FinBot CTF, and holds multiple security patents.




Packet Hacking Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 11:10 – 11:20 PDT

Creator: The Diana Initiative

Interested in visiting Packet Hacking Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Packet Hacking Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Patch Me If You Can: Hands-On Network Threat Defense

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) A
When:  Saturday, Aug 8, 11:00 – 12:59 PDT

Creator: Cloud Village

Join this hands-on workshop to explore an integrated set of network security capabilities designed for real-time threat detection, prevention, and proactive risk management. You’ll see how inline traffic inspection can block threats with virtual patching, helping reduce exposure before vendor patches are available.

The session will also cover how deep network visibility supports detection of command-and-control activity, lateral movement, and advanced malware using behavioral analysis and custom sandboxing. You’ll learn how continuous asset monitoring can uncover misconfigurations, exposure, and other risk factors across the environment, then use that insight to prioritize response and reduce overall risk.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Don Bogert

With more than 25 years of experience in cybersecurity, Don brings a comprehensive approach to organizational defense. Grounded in a strong network security foundation, his expertise spans physical security, compliance auditing, and the deployment of cloud, workload, and endpoint solutions. Throughout his career, Don has secured commercial, federal, and public sector organizations globally; and understands the challenges of a secure air-gapped environment. Currently, he focuses on delivering tailored security solutions to public sector customers in the Northeastern United States.




Payment Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 10:40 – 10:50 PDT

Creator: The Diana Initiative

Interested in visiting Payment Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Payment Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Pentester vs AI: Race The Machine, In Real Life

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2
When:  Saturday, Aug 8, 11:00 – 12:59 PDT

Creator: AppSec Village

The machine already solved it. Could you? Pentester vs AI brings our race-the-machine CTF off the screen and onto the table. Draw a card, read the challenge, a leaky query, a forged token, a broken access check, and walk us through how you’d break it. No laptop, no flag to submit. Just talk through your approach: what’s the flaw, what would you reach for, where’s the path in. Then flip the card and see how the AI reasoned through the same target. Where you agreed, where you didn’t. The clock is ticking for each challenge; come show us your line.


People:
    SpeakerBio:  Gwendal Mognier

Gwendal Mognier is a Security Researcher at Escape. He’s passionate about cybersecurity and always eager to learn new ways to break and secure systems. Gwendal is focused on discovering vulnerabilities and helping improve security across the board.

SpeakerBio:  Samantha Pearlstein, Founding Solutions Engineer at Escape

Samantha is a solutions engineer with a strong background in security research, executive cyber resilience, and nation-state threats. As a former consultant at Accenture, she led cyber resilience initiatives for Fortune 100 executives, developed GenAI-powered security tools, and delivered workshops on emerging cyber challenges. Today, as a Sales Engineer at Escape, Samantha helps AppSec teams secure their APIs and SPAs, combining her passion for cybersecurity with hands-on problem-solving.




Pentesting made easy – Keeping sessions alive with session chains

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Friday, Aug 7, 10:15 – 11:15 PDT

Creator: AppSec Village

Modern web applications require pentesters to manage multiple accounts, roles, and tenants while dealing with short-lived sessions, multi-step logins, and MFA. This complexity regularly breaks authenticated tooling and slows down assessments, forcing testers into repetitive manual re-authentication.

Our open-source tool, session-chains, addresses this challenge by automatically creating and maintaining authenticated sessions for any number of users. Testers define reusable authentication flows, while the tool keeps sessions valid in the background and exposes them to other tools.

It integrates with Burp Suite and CLI tools like sqlmap, enabling consistent authenticated testing even in complex environments. This allows security professionals to spend less time on authentication hurdles and more time identifying impactful vulnerabilities.


People:
    SpeakerBio:  Kai Glauber

Kai Glauber is a senior security consultant and penetration tester at usd AG with experience in web application pentests, SSO assessments and Kubernetes security. With a background in software development, his early work in software testing led him to specialize in the security domain. He’s passionate about workflow automation and making pentesting more efficient.

SpeakerBio:  Matthias Göhring

Matthias Göhring is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. He is Head of usd HeroLab, the division of usd specialized in technical security assessments. In addition, he holds lectures at Technical University Darmstadt and University of Applied Sciences Darmstadt on ethical hacking and penetration testing. In previous scientific work, he focused on network and communication security as well as software security.

Previous publications: – Catching the Clones – Insights in Website Cloning Attacks, Risk Connect Conference, 2021 – Path MTU Discovery Considered Harmful, IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018 – Tor Experimentation Tools, IEEE Security and Privacy Workshops, 2015 – On randomness testing in physical layer key agreement, IEEE 2nd World Forum on Internet of Things (WF-IoT), 2015




Physical Securty Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 10:50 – 10:59 PDT

Creator: The Diana Initiative

Interested in visiting Physical Securty Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Physical Securty Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Pickpocketing for Red Teamers: A Hands-On Experience

Creator Event Map Page – LVCCW Level 3 W320 (Social Engineering Community Village Labs)
When:  Friday, Aug 7, 10:00 – 11:30 PDT

Creator: Social Engineering Community Village

Seven years ago, pradameinhof ran the world’s first public pickpocketing competition with about 200 people at a social engineering conference. The inspiration? His dad got pickpocketed right next to him on the Paris Metro. What started as frustration turned into obsession�not just with preventing it, but with understanding how easy it is to pull off. It was hard enough finding good resources. The real problem? Testing your skills in realistic scenarios can land you in jail.

In this two-hour Social Engineering Community session, pradameinhof will teach what he learned: the core techniques of attention manipulation�directing and surfing attention, relative touch, entering personal space, giving shade, fanning, and working in teams. You’ll learn to lift wallets, watches, phones, badges, and keys, and apply these skills to red-teaming.

Here’s how it works: You’ll pair up and take turns�one practitioner, one target. No prior experience necessary.

What to bring: A jacket and pants with pockets that aren’t too tight. Wear a watch if you have one. Because you will need to steal from other people and be pickpocketed, expect to touch and be touched by others in order to participate�all appropriately and with clear consent.

Join us in this group exercise to understand the human blind spots that make physical social engineering so effective. Walk away with skills for your next red-team engagement�and better awareness so you don’t become a target.

(Disclaimer: This exercise is for educational purposes only. If you pickpocket people without their consent, expect to get into trouble.)


People:
    SpeakerBio:  pradameinhof

pradameinhof has worked in cyber security startups for over two decades. Most of his skills he acquired by pestering his friends and colleagues over coffee. He has a passion for OSINT and Social Engineering.




Policy @ Defcon Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 10:50 – 10:59 PDT

Creator: The Diana Initiative

Interested in visiting Policy @ Defcon but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Policy @ Defcon and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Polycon

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Saturday, Aug 8, 11:00 – 11:59 PDT

Creator: Queercon Community



Precogly: Open-Source Threat Modeling for the AI-Coding Era

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Saturday, Aug 8, 11:30 – 12:30 PDT

Creator: AppSec Village

AI agents are beginning to write larger parts of applications, from individual features to complete services. But if agents can build software, they also need a reliable way to threat model what they build.

Precogly is an open-source (Apache 2.0) OWASP project for repeatable, human-reviewable threat modeling in the AI-coding era. It uses structured, community-curated library packs that connect components, threats, and countermeasures to sources such as CWE, CAPEC, and compliance frameworks.

This gives AI agents guardrails. Instead of inventing threat models freely, they work off installed libraries, producing outputs that are easier to review, reproduce, and audit.

In this demo, attendees will see Precogly’s DFD editor, library pack ecosystem, threat generation workflow, completion status dashboard, pack cross-checks for detecting untraced AI-generated items, and the OpenAPI REST API that agents can build on top of.


People:
    SpeakerBio:  Vikramaditya Narayan

Vikramaditya Narayan is the creator of OWASP Precogly, an open-source, enterprise-grade threat modeling platform designed for repeatable, AI-agent-ready threat modeling. Previously, he designed the prototype for a YC-funded AI governance platform. Vikramaditya leads the Bangalore chapter of Threat Modeling Connect and has spoken at ThreatModCon DC on emergent risks in multi-agentic systems and at OWASP on using AI in threat modeling. He holds an MS from Carnegie Mellon and is a Certified Threat Modeling Professional.




Proactive Malicious Package Defense

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Saturday, Aug 8, 15:15 – 16:15 PDT

Creator: AppSec Village

Whole development orgs are still rawdogging npm and other package registries, despite the continued rise of supply chain attacks involving malware targeted at both developers and the organizations they work for. Check out open-source tooling that can contribute to proactive defense, using either open or vendor-proprietary data sets


People:
    SpeakerBio:  Darren Meyer

Darren is a security research advocate and practitioner that has worked on every side of the AppSec world at some point in the past 20 years. He’s passionate about making security work more accessible and less stressful.




Q&A with the “How to Profile an entire C-suite in 10 days” speaker

Creator Event Map Page – LVCCW Level 1 Hall 4 1307 (OSINT4Good Community)
When:  Sunday, Aug 9, 11:00 – 11:15 PDT

Creator: OSINT For Good Community

Stop by and chat with Sarah Muriel the speaker on How to Profile and Entire C-Suite in 10 days.


People:
    SpeakerBio:  Sarah Muriel, Bishop Fox

Sarah Muriel is an Intelligence Analyst from Mexico with more than 6 years of experience in open source investigations, currently working with the Attack Surfaces of companies all over the world. In her spare time she likes participating in various international OSINT related CTFs and developing retro-style websites. She’s also fairly active in the cybersecurity community, being part of the organization team for one of Mexico’s top conferences.




Q&A with the Classical OSINT Using AI speaker

Creator Event Map Page – LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage
When:  Friday, Aug 7, 14:30 – 14:59 PDT

Creator: OSINT For Good Community

Stop by and chat with reconcerto, the speaker on Classical OSINT using AI (Actual Intelligence)


People:
    SpeakerBio:  Bianca C. Ionescu/reconcerto

Bianca Ionescu is a CyberCorps SFS scholar pursuing a master’s degree in cybersecurity at UNLV. She’s served as a leader within cybersecurity student organizations, promoting growth, inclusion, and professional development. Her interests include open-source intelligence and mentoring new learners entering the field. Offline, she enjoys strength training and playing the viola. She’s motivated by community building, continuous learning, and the challenge of solving complex security problems that inspire her growth and resilience every day.




Q&A with the OSINT4Good Panel

Creator Event Map Page – LVCCW Level 1 Hall 4 1307 (OSINT4Good Community) Stage
When:  Friday, Aug 7, 11:00 – 11:30 PDT

Creator: OSINT For Good Community

Stop by and chat with the panelists from the OSINT4Good panel.


People:
    SpeakerBio:  Angela Ramos, University of Tampa

Angela Ramos is a University of Tampa cybersecurity lecturer. She leads the Scam Busters student program, coaches Trace Labs Search Party CTFs, and volunteers with US Cyber Games. She holds the GCIH, GSLC, and CEH certifications and spent a decade in DoD cyber operations.

SpeakerBio:  Kenny J, Trace Labs

Senior Infrastructure Engineer by day. Osint for Good by night. His is the only Trace Labs coach to have coached 20+ CTFs, earning him the singular rank of Legendary Coach.

SpeakerBio:  Brent Louie, Reporting Team Lead at Trace Labs

Brent Louie is the Reporting Team Lead at Trace Labs and an Associate Director of Data Science with more than 15 years of experience in the biotechnology industry. He focuses on applying OSINT methodologies to missing persons investigations and helping transform crowdsourced research into actionable investigative leads for law enforcement.




Quantum Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 10:20 – 10:30 PDT

Creator: The Diana Initiative

Interested in visiting Quantum Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Quantum Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Queercon Community Lounge Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 11:50 – 11:59 PDT

Creator: The Diana Initiative

Interested in visiting Queercon Community Lounge but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Queercon Community Lounge and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



QueerCon Opening Meet and Greet

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Friday, Aug 7, 12:00 – 12:59 PDT

Creator: Queercon Community

Join us for the opening of this years queercon lounge




Quiet Room

Creator Event Page –
When:  Friday, Aug 7, 10:00 – 01:59 PDT
Saturday, Aug 8, 10:00 – 01:59 PDT
Saturday, Aug 8, 10:00 – 01:59 PDT
Sunday, Aug 2, 12:17 – 13:16 PDT

Creator: The Diana Initiative

Diana Initiative is excited to offer up a “Quiet Room” again this year. This room is a library vibes environment where people can calm down or recharge before going back out to experience more DEF CON, or even safely have a meltdown, stim, and take time to recenter. In our library area we will have fidget toys, coloring pages and more. This year we are partnering with Mental Health Hackers to make it even better!




Radio Frequency Village Events

Creator Event Map Page – LVCCW Level 1 Hall 1 409 (Radio Frequency Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Radio Frequency Village

In addition to the CTF and talks, which are elsewhere on the schedule, the RF Village is also a place to hang out and chat with like minded folks who share your interests.

Links:
    Website – https://rfhackers.com
    Scoreboard – https://scoreboard.rfhackers.com/



Radio Frequency Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 11:20 – 11:30 PDT

Creator: The Diana Initiative

Interested in visiting Radio Frequency Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Radio Frequency Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Rebuilding Code Security with Signal, Speed and AI

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Friday, Aug 7, 16:30 – 17:30 PDT

Creator: AppSec Village
Modern AppSec tooling is fragmented: one scanner for secrets, another for dependencies, another for SAST, another for containers, another for SBOMs, and then a separate workflow for triage. Broly is an open source Go scanner built to collapse that workflow into one fast App and finding model.

This Arsenal session walks through Broly’s current design: Titus-backed secrets scanning, osv-scalibr + OSV.dev dependency analysis, Together AI powered SAST, container image scanning, license policy checks, SBOM output with baselines, incremental scans, SARIF/JSON/table output, and built in AI triage with optionality. The demo will show Broly scanning a vulnerable repo, producing actionable findings, filtering noise and fitting into a PR workflow.

The session is also a candid engineering case study on what broke, what was rebuilt, where & how AI helped, where deterministic engines still lead, and why security tools need to be attacked with the same rigor as the code they judge.


People:
    SpeakerBio:  Derek C.

Derek is the Head of Security at Together.ai and the former Head of Infrastructure Security at Cloudflare. He has over 20 years of experience in designing security frameworks at scale. His main focus is on research and development within the fields of encryption and infrastructure security.

He earned a masters in cybersecurity from Purdue University and now owns more than 60 global patents related to cryptography, key management, and distributed ledger technology.

SpeakerBio:  Shasheen Bandodkar

Shasheen Bandodkar is a security engineer passionate about safeguarding technology and innovation. With deep cybersecurity expertise, he frequently shares insights on his blog and is known for turning rants into revelations.




Recon Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 13:00 – 13:10 PDT

Creator: The Diana Initiative

Interested in visiting Recon Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Recon Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Red Team Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 13:30 – 13:40 PDT

Creator: The Diana Initiative

Interested in visiting Red Team Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Red Team Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



Resume Review with the Lonely Hackers Club

Creator Event Map Page – LVCCW Level 1 Hall 4 1419 (Lonely Hackers Club)
When:  Friday, Aug 7, 10:30 – 16:30 PDT
Saturday, Aug 8, 10:30 – 16:30 PDT

Creator: Lonely Hackers Club

Free, one-on-one resume reviews, run by people from this community who have actually hired and managed technical teams. No recruiters. No corporate fluff. Just honest feedback from people who have sat on both sides of the table and know what works.

Sessions are 15 minutes. Walk up, sit down and get real feedback. Book your slot in advance or show up early to secure your spot if you missed the online registration.

Links:
    Link – https://lonelyhackers.club/resumereviews/
    Registration – https://tickets.lonelyhackers.club/resume/



Riot Games Vanguard: Pwn to own

Creator Event Map Page – LVCCW Level 1 Hall 1 211 (Game Hacking Village)
When:  Saturday, Aug 8, 10:00 – 16:59 PDT
Friday, Aug 7, 12:00 – 16:59 PDT

Creator: Game Hacking Village

(Exact times TBD) Try your hand at hacking Riot Game’s signature anti-cheat: Vanguard!




Robot Hacking Community Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 10:40 – 10:50 PDT

Creator: The Diana Initiative

Interested in visiting Robot Hacking Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Robot Hacking Community and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



ROP for the Web: Smuggling XSS, SQLi, and Web Shells Past Every WAF Using Compression Dictionaries

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Sunday, Aug 9, 10:15 – 11:15 PDT

Creator: AppSec Village

Compression Dictionary Transport (RFC 9842) shipped in Chrome 130+ in 2025. Any JavaScript asset designated as a dictionary becomes a set of gadgets an attacker can chain into responses that bypass signature-based WAFs and IDSes. gadget-scanner is the a tool to evaluate that surface: drop in a candidate dictionary and a payload, and it reports how much of the payload hides inside backreferences and how much leaks as literal bytes on the wire. At the table you will score real-world JS libraries as attack primitives, generate the DCB blob with brotli -D, and watch the side-by-side: the raw bytes a WAF would see vs. the payload a browser would execute


People:
    SpeakerBio:  alevsk

Lenin Alevski is a Full Stack Engineer and generalist with a lot of passion for Information Security. Currently working as a Security Engineer at Google. Lenin specializes in building and maintaining Distributed Systems, Application Security and Cloud Security in general. Lenin loves to play CTFs, contributing to open-source and writing about security and privacy on his personal blog https://www.alevsk.com.




SANS Institute NetWars Labs

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Noob Community

SANS NetWars is a suite of advanced cyber ranges offering interactive, hands-on learning exercises created by SANS faculty in realistic network environments, gamifying cybersecurity training through compelling storylines and real-world challenges. Drop in during village hours to work through NetWars challenges at your own pace.




Satellites Under Attack: Hands-On Satellite Security Threat Scenarios

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT

Creator: Aerospace Village

In this “Satellite Attack Lab” you can explore how cyber-attacks against satellite systems can be launched, observed, and understood through a hands-on, attacker-centric experience. Rather than focusing on normal satellite operations, you will step into the role of a threat actor and directly exploit vulnerabilities in a simulated space environment by interacting with a physical setup of model satellites and ground stations to witness the immediate consequences of malicious actions, including intercepted data, unauthorized command execution, and visible disruption of satellite behavior.

We provide hacker workstations pre-configured with satellite command tools and signal-processing software. Large displays show the victim system’s telemetry and status in real time, allowing participants to immediately see the effects of their attacks.

This session is designed to be highly interactive and accessible to newcomers while still offering meaningful technical depth for advanced attendees.




SBOM Find the Flaws

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3
When:  Sunday, Aug 9, 11:00 – 12:59 PDT

Creator: AppSec Village

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.


People:
    SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.




SBOM Find the Flaws

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 1
When:  Saturday, Aug 8, 15:00 – 16:59 PDT

Creator: AppSec Village

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.


People:
    SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.




SBOM Find the Flaws

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4
When:  Saturday, Aug 8, 11:00 – 12:59 PDT

Creator: AppSec Village

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.


People:
    SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.




SBOM Find the Flaws

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 3
When:  Friday, Aug 7, 15:00 – 16:59 PDT

Creator: AppSec Village

SBOM Find the Flaws is a short hands-on activity where participants review SBOM files and identify intentional mistakes in the data, learning how to recognize common issues in software supply-chain documentation.


People:
    SpeakerBio:  Dmitry Raidman

Dmitry Raidman is the Co-Founder and CTO of CyBeats, where he leads product and technology strategy focused on software supply chain security, SBOM management, and product security compliance. He works with organizations across regulated industries to operationalize SBOMs, improve software transparency, and manage vulnerability and third-party component risk at scale.

Dmitry is also active in the cybersecurity community, contributing to initiatives around AI security, SBOM adoption, and software supply chain risk. He is involved with the OWASP GenAI Security Project and the AIBOM Initiative, helping advance practical approaches for documenting and managing AI-related software and model supply chain exposure.

His work focuses on helping organizations move beyond checklist compliance toward measurable product security capabilities, continuous visibility, and faster response to emerging software and supply chain threats.




Scambait Bingo

Creator Event Map Page – LVCCW Level 1 Hall 1 208 (Scambait Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Scambait Village

A fun, interactive group activity that turns classic bingo into a scambaiting game. Mark off common scam phrases, tactics, and red flags as they come up in curated recordings of real scam calls. Great for all skill levels, whether you are playing along or just hanging out. A low-pressure way to learn the language of scams while spending a few hours with the community. Prize-free by design. Winners get a certificate printed on the spot with a ridiculous honorific and a photo with village staff. Nothing of material value is awarded.

Links:
    scambaitvillage.org/bingo – https://scambaitvillage.org/bingo



Scambait Community Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 13:40 – 13:50 PDT

Creator: The Diana Initiative

Interested in visiting Scambait Community but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Scambait Community and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



SE Improv

Creator Event Map Page – LVCCW Level 3 W320 (Social Engineering Community Village Labs)
When:  Friday, Aug 7, 15:30 – 16:59 PDT

Creator: Social Engineering Community Village

Join Kevin and Bryan from Black Box Improv Security for more hands-on activities putting their approach to improv theater to work in social engineering. Following their main-room lunchtime presentation on how improv skills can make or break an SE engagement, they will host a workshop in the SEC Labs that will include chances for participants to immediately put what they learn into practice. There will be games, there will be prizes, and there will inevitably be lots of laughs. There will also be the return of some favorite activities from previous years, including the One-Word Story Competition and Improvised Cold Calls. Attendee participation will not be mandatory, though it is always encouraged.


People:
    SpeakerBio:  Bryan
No BIO available
SpeakerBio:  Kevin
No BIO available



search_vulns: Navigating the Fragmented Landscape of Vulnerability Data

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Sunday, Aug 9, 11:30 – 12:30 PDT

Creator: AppSec Village

Due to advances in AI‑assisted vulnerability discovery, more vulnerabilities are published than ever before, while traditional aggregators like the NVD have long reached their limits. This makes it increasingly difficult to obtain reliable information for prioritization in the fragmented landscape of known vulnerability data. Our open-source tool, search_vulns, addresses this by consolidating various sources through a modular architecture that works with product identifiers, like CPEs or PURLs, and regular product banners. It maintains accuracy when incorporating data without CPEs or PURLs, derives valid CPEs when upstream data is incomplete and reconciles duplicate product identities. Ultimately, it delivers a unified and precise view of known vulnerabilities, exploits, KEV, software recency and backpatch information, which we believe outperforms similar solutions.


People:
    SpeakerBio:  Dustin Born

Dustin Born is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. Within pentesting, he focuses on web applications, cloud environments and mobile applications. Apart from this, Dustin supports the development of several internal tools that focus on automated reconnaissance and vulnerability assessment. This aligns with his interests in developing tools related to IT security and his previous scientific work. Specifically, he has built a framework for a general purpose vulnerability scanner as well as one for the dynamic analysis of iOS apps.

SpeakerBio:  Matthias Göhring

Matthias Göhring is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. He is Head of usd HeroLab, the division of usd specialized in technical security assessments. In addition, he holds lectures at Technical University Darmstadt and University of Applied Sciences Darmstadt on ethical hacking and penetration testing. In previous scientific work, he focused on network and communication security as well as software security.

Previous publications: – Catching the Clones – Insights in Website Cloning Attacks, Risk Connect Conference, 2021 – Path MTU Discovery Considered Harmful, IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018 – Tor Experimentation Tools, IEEE Security and Privacy Workshops, 2015 – On randomness testing in physical layer key agreement, IEEE 2nd World Forum on Internet of Things (WF-IoT), 2015




Securing the AI Stack and Hunting Across Clouds

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) B
When:  Saturday, Aug 8, 16:00 – 16:59 PDT

Creator: Cloud Village

Teams are deploying AI agents fast, often without guardrails. Attackers are exploiting cross-cloud trust to pivot between environments. This lab tackles both.

Part A (30 min): Securing the AI Stack- Find over-broad permissions on an AI agent’s execution role – Discover prompt injection evidence in model invocation logs – Review Amazon Bedrock Guardrails that block injection, prevent system prompt leakage, and filter PII

Part B (30 min): Cross-Cloud Threat Hunting with OCSF- See how AWS, Azure, and GCP logs map to the same OCSF schema – Trace lateral movement across three clouds using federated identity – Write a detection rule that catches cross-cloud federation abuse

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Bryant Pickford

Bryant Pickford is a Security Specialist Solutions Architect at AWS, where he leads security, risk, and compliance discussions with enterprise customers to align strategies and drive secure outcomes on the AWS platform. With over five years at AWS and deep expertise in Edge Security, Threat Detection, and Generative AI, Bryant specializes in identifying emerging threats and developing practical defense strategies for cloud-native environments.




Skillbit Labs

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Noob Community

SkillBit Labs is a continuous learning platform designed to help assess and develop cybersecurity skills through hands-on, bite-sized labs. Drop in during village hours and work through beginner-friendly challenges at your own pace, brought to you by SkillBit (formerly MetaCTF), led by CEO Roman Bohuk.




Smart Home in the Matter: Blink, Race, Attack CTF

Creator Event Map Page – LVCCW Level 1 Hall 1 215 (IoT Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: IoT Village

Bitdefender and Netgear invite you into the smart-home arena, where the Matter fabric pulses with secrets, traps, and unexpected twists, and where AI can finally take a break while your critical thinking takes the lead.

Links:
    More Info – https://iotvillage.org/events/defcon-34/index.html



Social Engineering 101: The Four Psychological Backdoors to Scam Your Way into Anything

Creator Event Map Page – LVCCW Level 3 W320 (Social Engineering Community Village Labs)
When:  Saturday, Aug 8, 11:30 – 12:30 PDT
Saturday, Aug 8, 10:00 – 10:59 PDT

Creator: Social Engineering Community Village

Social engineering not just a specialized skill used by elite hackers, professional con artists, or unnervingly charismatic strangers. In reality, the same few psychological vulnerabilities show up everywhere: in negotiations, job interviews, sales pitches, security breaches, party tricks, and everyday conversations…

And YOU can use them, too.

In this interactive session, magician and social-engineering educator Brian Brushwood reveals four psychological backdoors that can make people more likely to trust, comply, disclose, and cooperate. You will see each principle demonstrated, learn why it works, and practice using it through safe, low-stakes exercises with other attendees.

These are the tricks that can be used by good guys and bad to convince, and build rapport quickly, lower resistance, and make an unlikely request feel surprisingly reasonable.

By learning how these techniques feel from the inside, attendees will become better at using influence deliberately, and better at recognizing when someone is using it on them.

No previous social-engineering experience is required. Just bring a willingness to talk to strangers, learn a magic trick or two, and discover how alarmingly hackable human beings really are.


People:
    SpeakerBio:  Brian Brushwood
Brian Brushwood has spent 25 years teaching millions of people how deception works: first as a touring magician, then as creator/host of Scam School / Scam Nation, host of National Geographic’s Hacking the System, creator of The Modern Rogue, and host of World’s Greatest Con. His work focuses on scams, magic, persuasion, social engineering, and the mechanics of trust: how it is built, exploited, defended, and rehearsed. Through Scam School and Scam Nation, Brian spent nearly two decades turning ordinary non-deceivers into capable ethical deceivers, helping them understand cons and persuasion from the inside. Brian has delivered keynotes to audiences of thousands and recently developed an experimental offense-to-defense social engineering curriculum, piloted at Clemson University with CISO John Hoyt.



Social Engineering Community Village – Open Hours

Creator Event Map Page – LVCCW Level 3 W317-319 (Social Engineering Community Village)
When:  Sunday, Aug 9, 10:00 – 12:30 PDT
Friday, Aug 7, 08:30 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Social Engineering Community Village

Morning, social engineers! Swing by for your SEC merch, claim your seat, and prepare for action… the phones start ringing soon.

The Social Engineering Community village dives into one of the most powerful attack surfaces in security: humans. Our village creates a space where attendees can explore the psychology, tactics, and tradecraft behind human-focused hacking. Through presentations, live demonstrations (via contests), and interactive activities, students, defenders, hackers, and the curious can see how reconnaissance, persuasion, and improvisation are used to bypass even the best defenses.

At DEF CON the village becomes a live stage for the craft. In the Social Engineering Community Vishing Competition (SECVC), competitors step into a soundproof booth and place real calls using OSINT, creative pretexts, and quick thinking while the audience watches the strategy unfold in real time. In Battle of the Bots, human-created AI agents attempt social engineering calls of their own, exploring what happens when automated systems try their hand at elicitation. Alongside the contests, attendees can have the opportunity to place calls in our “Cold Calls” or listen in to some presentations.

The village is built by the community that practices the craft. Volunteers, researchers, hackers, defenders, and curious newcomers all contribute to the content each year, creating space for new voices and ideas to take the stage. Whether you want to watch live un-scripted social engineering calls, understand the psychology behind it, or meet others who love the human side of security, the Social Engineering Community village is the place to experience it at DEF CON.

Prerequisites:

Attendees are welcome to watch contests, join discussions, and participate in interactive activities with no preparation needed.

Competitors in the Social Engineering Community Vishing Competition and Battle of the Bots Contest are selected in advance through a Call for Competitors prior to DEF CON, but some activities such as Cold Calls allow audience members to sign up onsite and participate.

Attendees who want to participate in Cold Calls may benefit from brushing up on basic social engineering skills such as rapport building, influence and elicitation techniques.




SpaceCOP – Catch Me If You Can

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT

Creator: Aerospace Village

Think you can hack a spacecraft?

We’ve deployed a vulnerable Pisat and made the software available ahead of time so you can prove it. Study it, reverse engineer it, find weaknesses, and develop your attack plan before stepping up to the console.

When your turn comes, you’ll only have 15 minutes at a time to compromise the spacecraft and achieve a mission objective. There’s just one problem, the SpaceCOP, an intrusion detection system based on the Aerospace Corporation’s SPARTA matrix, has been deployed. The spacecraft is intentionally hackable – the real challenge is accomplishing your objective without triggering an alert and getting arrested by SpaceCOP.

Earn rewards based on how well you hack and hide from SpaceCOP.

Rules of Engagement: • Recon and vulnerability research before sitting at the terminal are highly encouraged. • You will have 15 minutes at the workstation to execute your attack. • Modifying files, changing registry settings, taking pictures, and other spacecraft effects are fair game. • Do not intentionally wipe, brick, destroy, or otherwise render the system unusable. • No “rm -rf”, disk wipes, ransomware, bootloader destruction, or similar actions.

Links:
    Github – https://github.com/the-aerospace-corporation/spacecop-demo



Spotlight: Choose Your Own Adventure with InfoSecMap

Creator Event Map Page – LVCCW Level 1 Hall 4 1415 (OWASP Foundation)
When:  Friday, Aug 7, 11:30 – 11:59 PDT
Sunday, Aug 9, 10:00 – 10:30 PDT
Saturday, Aug 8, 10:30 – 10:59 PDT

Creator: OWASP Foundation

Opportunities in InfoSec are everywhere, but they’re often buried across scattered websites, social media posts, or chat channels. Whether it’s a local meetup, a CFP deadline, a volunteer opportunity, or the chance to sponsor an initiative, many people and organizations miss out simply because they don’t know where to look or find info bloated by pay-to-play noise.

InfoSecMap was created to solve this. It’s a free, community-driven platform that brings the global InfoSec ecosystem together in one place. From major conferences to CTFs and grassroots meetups, InfoSecMap helps users explore what’s happening by geographic region or focus area and discover where they can connect and contribute.

InfoSecMap is proud to partner with OWASP, bringing together volunteer-led chapters and global events while fostering stronger connections and community growth. We believe open source should mean open access, and we’re building the infrastructure to make that real.


People:
    SpeakerBio:  W. Martín Villalba, OWASP

Martín is an application and product security consultant with over 15 years of industry experience. He founded C13 Security, where he specializes in Secure SDLC, pentesting, and vulnerability management. He is an active member of the InfoSec community, collaborating with local groups and global organizations such as BSides and OWASP. He also built InfoSecMap, an open-access platform for discovering InfoSec events and communities from all around the world.




SR-71 Blackbird Badge Challenge

Creator Event Map Page – LVCCW Level 1 Hall 2 700 (Aerospace Village)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Aerospace Village

Think faster. Fly higher. Stay unseen.

Only the sharpest contenders will earn the limited-edition SR-71 PCB badge, inspired by the legendary Blackbird. Put your technical skills, aerospace knowledge, and analytical thinking to the test in this exclusive challenge. Like the aircraft itself, success demands precision, ingenuity, and the ability to stay one step ahead. Complete the mission and earn your wings.

New challenges launch all weekend long.




tAIrot Readings

Creator Event Map Page – LVCCW Level 1 Hall 4 1303 (Women in Security and Privacy (WISP) Community)
When:  Friday, Aug 7, 15:30 – 16:30 PDT

Creator: Misc

Curious about what the cards have in store for you? For a suggested donation, WISP Board Chair Alyssa Coley give you an AI-assisted tarot reading! Drop by for a fresh perspective on your burning questions, blending ancient symbolism with modern tech to offer personalized, reflective insights for your journey.




TCM Security Labs

Creator Event Map Page – LVCCW Level 1 Hall 4 1417 (Noob Community)
When:  Sunday, Aug 9, 10:00 – 13:59 PDT
Friday, Aug 7, 10:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Noob Community

TCM Security offers 250+ hours of practical, hands-on cybersecurity training across 28 courses and 13 certifications, built by hackers and trusted by teams. Drop in during village hours to work through their hands-on labs.




Telecom Village CTF Awards Ceremony

Creator Event Map Page – LVCCW Level 3 W321 (Telecom Village)
When:  Sunday, Aug 9, 14:00 – 14:15 PDT

Creator: Telecom Village



Telecom Village CTF Closure

Creator Event Map Page – LVCCW Level 3 W321 (Telecom Village)
When:  Friday, Aug 7, 16:30 – 16:59 PDT

Creator: Telecom Village



Telecom Village CTF Closure

Creator Event Map Page – LVCCW Level 3 W321 (Telecom Village)
When:  Saturday, Aug 8, 16:45 – 16:59 PDT

Creator: Telecom Village



Telecom Village CTF

Creator Event Map Page – LVCCW Level 3 W321 (Telecom Village)
When:  Sunday, Aug 9, 10:20 – 13:59 PDT

Creator: Telecom Village

People:
    SpeakerBio:  T -Mobile CTF Team
No BIO available



Telecom Village Open Forum: Talks & Workshops: Review, Highlights, and Key Learnings

Creator Event Map Page – LVCCW Level 3 W321 (Telecom Village)
When:  Friday, Aug 7, 17:00 – 17:59 PDT
Saturday, Aug 8, 17:00 – 17:59 PDT

Creator: Telecom Village



Telecom Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Friday, Aug 7, 13:10 – 13:20 PDT

Creator: The Diana Initiative

Interested in visiting Telecom Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Telecom Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



The Agent Asked. We Allowed. Now What?

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Sunday, Aug 9, 12:45 – 13:45 PDT

Creator: AppSec Village

AI agents are already running on developer machines, inside terminals, IDEs, and internal workflows. They are useful, but they can also read code, access files, execute commands, call tools, use credentials, and send data to LLM providers.

In this Arsenal demo, we will present an open-source runtime discovery tool for identifying LLM-powered applications and AI agents on live machines without requiring code changes. The tool correlates local processes with LLM-provider traffic, detects known and unknown AI service usage, monitors subprocess and file activity, and applies basic policy controls for coding agents.

We will show what AI agents look like at runtime, what they do beyond the chat interface, and how AppSec teams can see, understand, and control them.


People:
    SpeakerBio:  Liran Lavi

A senior security researcher from Tel Aviv specializing in web application security and advanced bot detection. With over 9 years of experience with small and large companies. To balance my tech-savvy life, you might find me hiking or skydiving – chasing new heights both literally and technically. I am always exploring edge cases and smarter ways to build and break systems.

SpeakerBio:  Sarit Yerushalmi

Sarit Yerushalmi is an experienced security researcher at Imperva. Her research mainly focuses on application security and APIs. She analyzes traffic to detect new threats, writes security blogs and talks at conferences. Some of her work has been presented at security conferences such as Botconf, Bsides TLV, NorthSec, and Kernelcon.




The Autonomous Insider

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) A
When:  Sunday, Aug 9, 11:00 – 12:59 PDT

Creator: Cloud Village

In 2026, the ‘Cloud Perimeter’ has shifted from IP addresses to Agent Identities. This lab explores the intersection of Generative AI and Cloud Misconfiguration. We move beyond the prompt, demonstrating how classic architectural flaws-like over-permissive VPC Endpoints, missing IAM Conditions, and SSRF-prone Tool-call environments-allow attackers to turn a ‘helpful’ AI assistant into a cross-account exfiltration engine. Attendees will learn to exploit and then ‘shackle’ these agents using VPC Service Controls, SCPs, and automated remediation workflows.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Naveen Reddy Pogalla

Naveen works within the Product Security Engineering team at Google Cloud, operating at the intersection of data and defense. Specializing in Cloud Security Posture Management and engineering automated remediation accelerators, he analyzes the broader risk landscape to drive remediation and hardening at scale. Rather than just hunting for individual bugs, his goal is to build a more secure cloud by identifying and eliminating entire classes of vulnerabilities before they can be exploited. Naveen thrives on solving high-stakes security challenges that require a blend of analytical rigor and an offensive security mindset. Prior to Google, he empowered clients as a Security Consultant at EY and Grant Thornton, with expertise spanning network security, vulnerability assessments, and GRC. He holds a Master’s degree in Cybersecurity Analytics and Operations from Penn State University and a Bachelor’s in Computer Science Engineering.

SpeakerBio:  Hari Pranav Arun Kumar
No BIO available



The Autonomous Security Loop

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) B
When:  Friday, Aug 7, 13:30 – 14:30 PDT

Creator: Cloud Village

SOCs get thousands of alerts daily. Most orgs take days to triage and fix critical findings. Attackers exploit that gap.

This lab walks through the three stages of a continuous security loop. Do each phase by hand, then see how the latest AWS capabilities compress it to seconds:

Discovery: Review output from a continuous security scan that found a multi-step attack path. Understand why this catches things annual pen tests miss. Triage: Manually triage 5 out of 30 Security Hub findings using the same signals AI triage uses. Compare your calls against the automated system. Remediation: Examine proposed fixes. Understand the difference between human-approved and autonomous remediation. Submit a fix and confirm it works.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Jeremy Schiefer

Jeremy is a Pr. Security Solution Architect at AWS focused on helping customers improve their security posture.

SpeakerBio:  Lawton Pittenger

Lawton is a Worldwide Security Specialist Solutions Architect at AWS, based in New York City. He specializes in helping customers design and implement effective network security controls. At AWS, he works with customers at scale and collaborates closely with service teams to drive continuous improvement in security services based on customer needs and feedback




The Call Stack Experience

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 2
When:  Friday, Aug 7, 11:00 – 12:59 PDT

Creator: AppSec Village

Let’s play with blocks… and learn how real application attacks unfold.

You will build real application call stacks, one foam block at a time, with each block representing function calls in a normal execution flow.

Once your stack is complete, you will see first-hand how easy it is for exploits to blend in with normal application behavior.


People:
    SpeakerBio:  Victoria Keeler
No BIO available



The Call Stack Experience

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) POD 4
When:  Saturday, Aug 8, 15:00 – 16:59 PDT

Creator: AppSec Village

Let’s play with blocks… and learn how real application attacks unfold.

You will build real application call stacks, one foam block at a time, with each block representing function calls in a normal execution flow.

Once your stack is complete, you will see first-hand how easy it is for exploits to blend in with normal application behavior.


People:
    SpeakerBio:  Victoria Keeler
No BIO available



The Diana Initiative – Open time

Creator Event Map Page – LVCCW Level 2 W209 (Diana Initiative)
When:  Friday, Aug 7, 14:00 – 14:59 PDT
Saturday, Aug 8, 12:00 – 12:59 PDT
Friday, Aug 7, 12:00 – 12:59 PDT
Sunday, Aug 9, 13:00 – 13:59 PDT
Sunday, Aug 9, 10:00 – 10:59 PDT
Saturday, Aug 8, 16:00 – 17:59 PDT

Creator: The Diana Initiative

In our community room between our birds of a feather conversations, meetups, workshops, and talks we have open time where you can come in and hang out – we have games and puzzles and lego!

We also have our “Reference Desk”, not the NFO desk, but a service for overwhelmed individuals. Our friendly volunteers at our reference desk can help you come up with a plan before going back out into DEF CON. The reference desk will work to find and connect you with the amazing events and communities at the conference, as well as in the community at large, that are best suited to your interests.




Thread Carefully

Creator Event Map Page – LVCCW Level 1 Hall 2 503 (Embedded Systems Village)
When:  Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Embedded Systems Village

Presentation about open thread networks, what a thread devices can see from your home network, what can it access. And how this mighty be miss-used. Some theoretical attack scenarios. Like how to turn a thread only lightbulb with ota update into a residential proxy node.




Threat Model your Career Workshop

Creator Event Map Page – LVCCW Level 2 W209 (Diana Initiative)
When:  Sunday, Aug 9, 11:00 – 12:59 PDT

Creator: The Diana Initiative

We threat model systems all the time. Almost nobody runs that same thinking on their own career, which is usually the most valuable thing they own. Let’s spend two hours looking at your career the way you would look at something you are paid to defend: what is worth protecting, what could go wrong, where they are exposed, and what you are actually going to do about it. 

Everyone will leave with a filled-in canvas and one specific thing they have committed to in the next month. This workshop is for any experience level.


People:
    SpeakerBio:  Chandan Vedavyas
No BIO available



TrackTheFugitive Contest

Creator Event Map Page – LVCCW Level 1 Hall 2 501 (Recon Village)
When:  Friday, Aug 7, 10:00 – 23:59 PDT

Creator: Recon Village

The manhunt is on. TrackTheFugitive drops you into real, active cases where the suspects are still out there—no simulations, no canned flags. Armed with nothing but open-source intelligence, you’ll chase digital breadcrumbs, unmask aliases, and surface the leads that help bring real fugitives to justice.




TrackTheFugitive Contest

Creator Event Map Page – LVCCW Level 1 Hall 2 501 (Recon Village)
When:  Saturday, Aug 8, 12:00 – 17:59 PDT

Creator: Recon Village

The manhunt is on. TrackTheFugitive drops you into real, active cases where the suspects are still out there—no simulations, no canned flags. Armed with nothing but open-source intelligence, you’ll chase digital breadcrumbs, unmask aliases, and surface the leads that help bring real fugitives to justice. Contest continues from Friday and ends Saturday at 6:00 PM.




Trans Meetup

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Saturday, Aug 8, 12:00 – 12:59 PDT

Creator: Queercon Community



Trans Townhall

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Friday, Aug 7, 11:00 – 11:59 PDT

Creator: Queercon Community

Join us for the Trans Town Hall to find connections, discuss challenges facing the trans community, and engage in converations critical to the community.




Unconference

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Sunday, Aug 9, 13:30 – 14:30 PDT

Creator: Nix Vegas Community

Come and chill in the Nix Vegas space for the Unconference.




Visable Mending, repair and reinforce

Creator Event Map Page – LVCCW Level 1 Hall 1 301 (Makers’ Village)
When:  Sunday, Aug 9, 13:30 – 13:59 PDT

Creator: Maker’s Village

We’ll be going over the types of tools, stitches. And techniques that go into mending, darning, and reinforcing clothes.




Voting Village Lab

Creator Event Map Page – LVCCW Level 2 W219 (Voting Village) (Voting Village Lab)
When:  Friday, Aug 7, 10:00 – 17:59 PDT
Sunday, Aug 9, 10:00 – 13:59 PDT
Saturday, Aug 8, 10:00 – 17:59 PDT

Creator: Voting Village

The Voting Village Lab is a hands-on, self-directed workshop space where attendees can learn about and experiment with dozens of different pieces of election equipment used in current and past US elections.




Voting Village Tour

Creator Event Map Page – LVCCW Level 1 South Lobby / Atrium
When:  Saturday, Aug 8, 13:10 – 13:20 PDT

Creator: The Diana Initiative

Interested in visiting Voting Village but afraid to go by yourself? The Diana Initiative is hosting tours! Follow a volunteer to Voting Village and be introduced to the community and activities inside!

Links:
    The Diana Initiative Website – https://tdi.mobi/DEFCON



WarDriver Meetup

Creator Event Map Page – LVCCW Level 1 Hall 1 409 (Radio Frequency Village)
When:  Sunday, Aug 9, 10:00 – 11:55 PDT

Creator: Radio Frequency Village



Weaponizing CloudFormation: Privilege Escalation via Infrastructure as Code in AWS

Creator Event Map Page – LVCCW Level 3 W311 (Cloud Village Labs) A
When:  Friday, Aug 7, 11:00 – 12:59 PDT

Creator: Cloud Village

CloudFormation is widely trusted as a secure and declarative Infrastructure as Code (IaC) service inside AWS environments. In practice, however, CloudFormation frequently operates with permissions far beyond those of individual users, CI/CD pipelines, or developers. This workshop explores how attackers can abuse that trust model to achieve privilege escalation and persistence in realistic AWS environments.

In this fully hands-on offensive cloud security workshop, attendees will begin with limited IAM permissions and learn how to identify and exploit misconfigured CloudFormation execution roles using iam:PassRole, service roles, and Lambda-backed Custom Resources. Participants will weaponize CloudFormation templates to create persistence mechanisms inside service-scoped IAM paths without requiring direct administrative permissions.

The workshop emphasizes realistic cloud attack paths, delegated execution abuse, and the security risks introduced by over-permissioned automation. Attendees will also explore rollback abuse scenarios and learn how these attacks appear in CloudTrail and IAM logs.

Links:
    Pre-registration – https://forms.gle/62vUrxFuW7prwUze9

People:
    SpeakerBio:  Samanta Aranda

Samanta Aranda serves as a Managing Senior Consultant at Bishop Fox, leading security assessments and initiatives focused on strengthening organizations’ technological resilience. She holds a degree in Electronics and Communications Engineering and a Master’s in Computer Science and Technology Management. From the very beginning of her career, she found in cybersecurity not just a profession but a genuine passion. Over the years, she has collaborated with national and international firms such as KPMG, Scitum, EC-Council LATAM, and INFOTEC, contributing to projects that bridge technology, strategy, and security.

Samanta holds 16 professional certifications, including GPEN, GWAPT, CEH, and CND, and has been recognized as an EC-Council Certified Instructor, earning a place in the organization’s Circle of Excellence in 2021. She blends technical expertise with a human and collaborative approach to security, firmly believing that shared knowledge is the strongest defense.




Welcome to your Airbnb, the key is under the mat -or- Alice and Bob with Padlocks

Creator Event Map Page – LVCCW Level 3 W316 (DC NextGen)
When:  Friday, Aug 7, 17:00 – 17:45 PDT

Creator: DCNextGen

We teach everyone how to verify “there’s a padlock” but there’s a lot of cool math behind that padlock, and we will show, with everyday props and actors, how modern cryptography works under the hood. Can we implement Diffie-Hellman with padlocks? Instead of memorizing complicated math, we’ll solve puzzles together as a team and reveal how computers securely exchange secrets, protect private information, and prove someone’s identity online. Along the way, you’ll recreate the ideas behind the same technologies used by websites, games, banks, and messaging apps. Prerequisites: none. All props are provided and participants will keep some props.


People:
    SpeakerBio:  Gilgamesh
No BIO available



What is AI? Interactive, Unplugged Activity

Creator Event Map Page – LVCCW Level 1 Hall 2 603 (AI Village)
When:  Saturday, Aug 8, 11:00 – 11:59 PDT
Sunday, Aug 9, 11:00 – 11:59 PDT

Creator: AI Village

Ever wonder what’s actually happening inside an AI? In this hands-on, no-screens-required workshop, you’ll build your own neural network out of flashcards and pipe cleaners, “train” it, and watch it try (and sometimes fail!) to answer prompts. You’ll grow your model, give it tools and skills, and then turn the tables: try out real attacks like prompt injection, tool misuse, and data poisoning, and learn the defenses AI security researchers use to stop them, like containerization. No coding or experience required, just curiosity!


People:
    SpeakerBio:  Sam Mosley, CodeBloom
No BIO available



Whose PR Is It Anyway?

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Saturday, Aug 8, 13:00 – 13:45 PDT

Creator: Nix Vegas Community

In this audience participation-heavy session, you can get your PRs to nixpkgs reviewed and maybe even merged… if the build on one of our systems passes. Come with PRs in hand and call them out, and we’ll review, build, and maybe even merge them on stage.

This is Whose PR Is It Anyway, where the version bumps are made up and the builds don’t matter.




Whose PR Is It Anyway?

Creator Event Map Page – LVCCW Level 1 Hall 4 1310 (Nix Vegas Community)
When:  Friday, Aug 7, 13:00 – 13:45 PDT

Creator: Nix Vegas Community

In this audience participation-heavy session, you can get your PRs to nixpkgs reviewed and maybe even merged… if the build on one of our systems passes. Come with PRs in hand and call them out, and we’ll review, build, and maybe even merge them on stage.

This is Whose PR Is It Anyway, where the version bumps are made up and the builds don’t matter.




Women Loving Women Meetup

Creator Event Map Page – LVCCW Level 3 W325 (QueerCon Lounge)
When:  Friday, Aug 7, 14:00 – 14:59 PDT

Creator: Queercon Community



Yoga

Creator Event Map Page – LVCCW Level 2 W209 (Diana Initiative)
When:  Friday, Aug 7, 17:00 – 17:59 PDT
Saturday, Aug 8, 10:00 – 10:59 PDT

Creator: The Diana Initiative

Come join us for morning yoga and meditation. This workshop is inclusive of all bodies. Meditation can help quiet the mind, manage stress, and enhance overall emotional well-being, making it a great way to start the day.


People:
    SpeakerBio:  Deanna Heon
No BIO available



Your SaaS Is My Foothold: Weaponizing Shadow SaaS for Initial Access and Persistence

Creator Event Map Page – LVCCW Level 1 Hall 2 604 (Appsec Village) Arsenal
When:  Saturday, Aug 8, 16:30 – 17:30 PDT

Creator: AppSec Village

Modern enterprise environments have shifted beyond traditional network perimeters, with SaaS applications and identity providers becoming the primary attack surface. However, a significant portion of this still remains unmanaged or invisible commonly referred as Shadow SaaS.

This session explores Shadow SaaS from an attacker’s perspective, demonstrating how adversaries can identify, evaluate, and abuse unmanaged SaaS applications to gain initial access and maintain persistence within target environments.

Rather than focusing on inventory or governance, this talk reframes Shadow SaaS as an offensive opportunity. It highlights how implicit trust relationships, and third-party SaaS connections expand the attack surface beyond traditional security visibility.

Using the Shadow SaaS Surface Scanner, we demonstrate how attackers can uncover hidden SaaS exposure and leverage it as a foothold into enterprise environments.


People:
    SpeakerBio:  Jordan Bonagura

Senior Security Consultant at Secure Ideas Researcher in Information Security Stay Safe Podcast Founder Computer Scientist Post Graduated in Business Strategic Management, Innovation and Teaching Founder – Vale Security Conference – Brazilian Conference Consultant Member – Brazilian Comission of High Tech Crime (OAB / SP) Coordinator and Teacher in IT area SJC Hacker Space President Speaker (DefCon, Hack Space Con, Hack Red Con, Hack Miami, Triangle InfoSec, AppSec California, GrrCon, BalCCon2k14, BSides Augusta, H2HC, Angeles Y Demonios, Silver Bullet, Seginfo, ITA, INPE, etc)




Zero Day Hire: Can You Spot the Spy?

Creator Event Map Page – LVCCW Level 3 W320 (Social Engineering Community Village Labs)
When:  Friday, Aug 7, 13:30 – 14:30 PDT
Friday, Aug 7, 12:00 – 12:59 PDT

Creator: Social Engineering Community Village

If your hiring process relies solely on traditional background checks, you’re already behind. You think you’re hiring a Senior Backend Engineer. You’ve reviewed the resume, passed the technical interview, and cleared the automated background check. But you’ve actually just handed a corporate laptop to a spy.

This 60-minute workshop puts the attendee in the seat of an OSINT lead during a live-fire exercise. This isn’t a lecture; it’s a test to stop a breach before it starts. Attendees will be provided with the same “evidence” a recruiter would see, and the goal is simple: perform a background check to identify fake personas. You have 60 minutes. Can you do it?

Key Takeaways: – Learn why standard background checks miss AI-generated personas and synthetic identities – Leave with a practical, legally-conscious verification process you can use by Monday morning

Note: Please bring your own laptop. Attendees should be comfortable installing and using common OSINT tools to participate in the live investigation.


People:
    SpeakerBio:  Michael Reimsbach, Product Security Specialist at SAP

Michael is a Product Security Specialist at SAP, working with the SAP Cloud Infrastructure security team. His focus areas include vulnerability management, secrets management, and building secure internal services.

He obtained multiple industry certifications such as OSCP, GCPN, and CISSP.

A healthy dose of paranoia led him to explore OSINT and the surprising power of publicly available information.

Beyond his day-to-day work, Michael is an active member of the cybersecurity community and helps organize BSides Luxembourg.

SpeakerBio:  Rishi “rxerium” C, Security Researcher

Rishi is a London-based security researcher with over five years of hands-on experience in IT. He currently specializes in vulnerability research, threat intelligence, and enterprise risk analysis. His current focus lies in identifying and analyzing zero-day vulnerabilities and emerging CVEs, often working to reverse engineer exploit mechanics and build detection logic before public weaponization. Rishi’s work spans both offensive and defensive domains—developing threat models based on real-world TTPs, crafting custom detection rules, and automating reconnaissance pipelines to uncover exploitable misconfigurations and exposed assets. He is particularly active in attack surface management (ASM) and OSINT, where he leverages DNS enumeration, passive data correlation, and large-scale infrastructure scanning to surface unknown entry points and map adversary-accessible exposure. Outside of research, Rishi integrates findings into operational tooling and supports data-driven prioritization strategies to bridge technical risk and business impact. His work reflects a deep commitment to adversary-informed defense and proactive discovery across modern hybrid environments.