BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: How much of our Bluetooth firmware reverse engineeri
 ng work\n   can now be automated with LLMs?\n   Tags: DEF CON Official Tal
 k | Demo ðŸ’» | Tool ðŸ› \n   When: Saturday\, Aug 8\, 16:30 - 17:30 PDT\n
    Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - [1]Map\n\n
    Description:\n\n   Last year Xeno manually reverse-engineered Realtek R
 TL8761B* Bluetooth\n   chips' ROM & firmware\, to inject code into them th
 at allows everyone\n   to send custom packets that aren't supposed to be p
 ossible on a\n   well-behaved device. Previous to that Veronica manually\n
    reverse-engineered multiple firmware to find link layer over-the-air\n 
   exploitable vulnerabilities. This year we wanted to understand how\n   m
 uch time we could have saved on past projects if we had used LLMs to\n   a
 utomate the reversing process.\n\n   The answer turns out to be "quite a l
 ot!". In this talk we'll discuss\n   how we've created skills for LLMs to 
 almost entirely automate the\n   reverse engineering of Bluetooth Low Ener
 gy / Classic chip firmwares'\n   low level packet handling & Host Controll
 er Interface layers. The key\n   is to focus on helping the LLMs find the 
 code that you know must be\n   there in order for a chip to be spec-compli
 ant ("Waypoints").\n\n   If you work in another firmware/OS RE domain\, wi
 th well-defined\n   specification-required interfaces and data structures\
 , we expect\n   you'll be able to follow the same process as us to signifi
 cantly\n   accelerate your reversing. Especially if you have binaries that
  you've\n   already reverse-engineered in the past that you can feed into 
 an\n   automation process for grading purposes.\n\n   [1] "Reverse enginee
 ring Realtek RTL8761B* Bluetooth chips\, to make\n   better Bluetooth secu
 rity tools & classes" - Xeno Kovah -\n   https://darkmentor.com/publicatio
 n/2025-11-hardweario/\n   [2] "DarkFirmware_real_i" - Xeno Kovah -\n   htt
 ps://github.com/darkmentorllc/DarkFirmware_real_i [3]\n\n   Speakers:Veron
 ica Kovah\,Xeno Kovah\n\n   SpeakerBio:  Veronica Kovah\, Dark Mentor LLC\
 n\n   Veronica is a researcher who has created and released multiple\n   o
 ver-the-air arbitrary code execution exploits which target Bluetooth\n   c
 hip firmware. She presented these attacks at BlackHat USA 2020. In\n   201
 8 she founded the security consultancy Dark Mentor LLC. She has\n   previo
 usly worked at companies like Tesla on vehicular security and\n   NSA as a
 n adjunct instructor and Capability Development Specialist\n   developing 
 CNE tools for embedded systems. She is currently using her\n   background 
 in reverse engineering and exploitation to specialize in\n   the security 
 analysis of Bluetooth systems.\n\n   SpeakerBio:  Xeno Kovah\, Dark Mentor
  LLC\n\n   Prior to working full time on OpenSecurityTraining2 (ost2.fyi)\
 , Xeno\n   worked at Apple designing architectural support for firmware se
 curity\;\n   and code auditing firmware security implementations. A lot of
  what he\n   did revolved around adding secure boot support to the main an
 d\n   peripheral processors (e.g. the Broadcom Bluetooth chip.) He led the
 \n   efforts to bring secure boot to Macs\, first with T2-based Macs\, and
 \n   then with the massive architectural change of Apple Silicon Macs. Onc
 e\n   the M1 Macs shipped\, he left Apple to pursue the project he felt wo
 uld\n   be most impactful: creating free deep-technical online training\n 
   material and growing the newly created OpenSecurityTraining 501(c)(3)\n 
   nonprofit.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T003000Z
DTSTART:20260808T233000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:How much of our Bluetooth firmware reverse engineering work can now
  be automated with LLMs?
END:VEVENT
END:VCALENDAR
