BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Be like a BRAT(BLE Recon and Attack Toolkit): Skip t
 he\n   Handshake\, Own the Device\n   Tags: Intro/Beginner | DEF CON Demo 
 Labs | AppSec | Hardware/IoT |\n   Mobile | Offense/Red Team | Wireless/RF
  | DEF CON Demo Labs\n   When: Friday\, Aug 7\, 11:00 - 11:45 PDT\n   Wher
 e: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - [1]Map\n\n   Descriptio
 n:\n\n   What happens when you buy a popular medical device and realize it
 \n   blindly trusts any BLE connection within 30 meters?\n\n   BRAT (BLE R
 econ and Attack Toolkit) is the open-source Python arsenal\n   we built to
  systematically take over an FDA-listed consumer hormone\n   analyzer and 
 generalize the attack to the class of devices behind it.\n   Relying on th
 e Nordic UART Service (NUS)\, the target blindly trusts\n   any connection
  within 30 meters. BRAT automates the exact attack chain\n   we used to co
 mpromise it: passive BLE discovery\, protocol reverse\n   engineering\, un
 authenticated command injection\, full bind takeover\,\n   and rogue perip
 heral impersonation to hijack live API session tokens.\n\n   Every script 
 is built on the ā bleakā  async BLE library and\n   deliberately kept sm
 all so you can read the code and understand the\n   exploit in minutes. Ou
 r Demo Lab features live\, end-to-end attacks\n   against a consumer medic
 al device. Weāll demonstrate unauthenticated\n   command injection\, rog
 ue peripheral spoofing that intercepts companion\n   app handshakes\, and 
 how we injected spoofed hormone sensor data\n   without ever pairing.\n\n 
   Speakers:Gigi Xiaoqing Liu\,Muzzammil Mohammed\,Narmina Karimova\n\n   S
 peakerBio:  Gigi Xiaoqing Liu\n\n   Gigi Liu is a graduate security resear
 cher at Northeastern's Security\n   And Privacy Research (SPQR) Group unde
 r Professor Kevin Fu\, where her\n   work covers embedded systems security
 \, medical device attack surfaces\,\n   and AI-generated media detection. 
 She interns at Lila Sciences as a\n   Security and Cloud Engineer\, buildi
 ng enterprise-wide agentic AI\n   security infrastructure and detection ca
 pabilities for unauthorized AI\n   activity across cloud and SaaS environm
 ents.\n\n   Her technical work spans wireless protocol reverse engineering
 \, binary\n   exploitation\, web and mobile reverse engineering\, cloud an
 d AI\n   security. She has applied these skills across medical hardware\,\
 n   automotive platforms\, and enterprise cloud environments ā from BLE\
 n   command injection on FDA-listed devices to CarPlay API exploitation to
 \n   building agentic AI detection controls at scale. As a UCLA\n   psycho
 biology alum with a consulting background\, she brings a\n   multidiscipli
 nary lens to every system: understand what it's designed\n   to do first\,
  then find where it breaks.\n\n   SpeakerBio:  Muzzammil Mohammed\n\n   Mu
 zzammil Mohammed is an offensive security researcher\, penetration\n   tes
 ter at Maltek Solutions\, and MS in Cybersecurity at Northeastern\n   Univ
 ersity. Operating out of the SPQR Lab under Professor Kevin Fu\,\n   and s
 erving as a Teaching Assistant Network Security\, his work bridges\n   aca
 demic vulnerability research with real-world red team execution. As\n   a 
 core developer of WandKit an open-source BLE attack toolkit built to\n   a
 udit medical devices. Muzzammil led the cloud API exploitation phase\,\n  
  successfully confirming a complete authentication bypass and\n   engineer
 ing the rogue peripheral session hijack chain. Beyond hardware\n   and API
  hacking\, he is actively developing autonomous multi-agent AI\n   framewo
 rks designed to orchestrate local LLMs for automated security\n   auditing
  and vulnerability analysis.\n\n   SpeakerBio:  Narmina Karimova\n\n   Nar
 mina Karimova is a cybersecurity graduate researcher at\n   Northeastern U
 niversity with a background in enterprise technology\n   across financial 
 institutions and the United Nations. She came to\n   security research fro
 m the infrastructure side\, which shaped how she\n   approached tearing ap
 art a consumer fertility monitor. For BRAT\, she\n   wrote the core BLE at
 tack suite in Python: replay modules\, rogue\n   peripheral session captur
 e\, unauthenticated hormone data extraction\,\n   and the bind takeover ch
 ain that captures device ownership in under 15\n   seconds. She also rever
 se-engineered the APK with JADX\, found\n   hardcoded credentials\, and co
 nfirmed a CVSS 9.1 IDOR in the\n   third-party integration. Her interest i
 s in the gap between how\n   consumer health devices are marketed and how 
 they actually handle\n   sensitive data.\n\n   '\n\n   1. #LVCCW_Level1_Ha
 ll3\n\n\n
DTEND:20260807T184500Z
DTSTART:20260807T180000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)
SUMMARY:Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake\, 
 Own the Device
END:VEVENT
END:VCALENDAR
