BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Be like a BRAT(BLE Recon and Attack Toolkit): Skip t
 he\n   Handshake\, Own the Device\n   Tags: Intro/Beginner | DEF CON Demo 
 Labs | AppSec | Hardware/IoT |\n   Mobile | Offense/Red Team | Wireless/RF
  | DEF CON Demo Labs\n   When: Saturday\, Aug 8\, 15:00 - 15:45 PDT\n   Wh
 ere: LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3) - [1]Map\n\n   Descript
 ion:\n\n   What happens when you buy a popular medical device and realize 
 it\n   blindly trusts any BLE connection within 30 meters?\n\n   BRAT (BLE
  Recon and Attack Toolkit) is the open-source Python arsenal\n   we built 
 to systematically take over an FDA-listed consumer hormone\n   analyzer an
 d generalize the attack to the class of devices behind it.\n   Relying on 
 the Nordic UART Service (NUS)\, the target blindly trusts\n   any connecti
 on within 30 meters. BRAT automates the exact attack chain\n   we used to 
 compromise it: passive BLE discovery\, protocol reverse\n   engineering\, 
 unauthenticated command injection\, full bind takeover\,\n   and rogue per
 ipheral impersonation to hijack live API session tokens.\n\n   Every scrip
 t is built on the ā bleakā  async BLE library and\n   deliberately kept 
 small so you can read the code and understand the\n   exploit in minutes. 
 Our Demo Lab features live\, end-to-end attacks\n   against a consumer med
 ical device. Weāll demonstrate unauthenticated\n   command injection\, r
 ogue peripheral spoofing that intercepts companion\n   app handshakes\, an
 d how we injected spoofed hormone sensor data\n   without ever pairing.\n\
 n   Speakers:Gigi Xiaoqing Liu\,Muzzammil Mohammed\,Narmina Karimova\n\n  
  SpeakerBio:  Gigi Xiaoqing Liu\n\n   Gigi Liu is a graduate security rese
 archer at Northeastern's Security\n   And Privacy Research (SPQR) Group un
 der Professor Kevin Fu\, where her\n   work covers embedded systems securi
 ty\, medical device attack surfaces\,\n   and AI-generated media detection
 . She interns at Lila Sciences as a\n   Security and Cloud Engineer\, buil
 ding enterprise-wide agentic AI\n   security infrastructure and detection 
 capabilities for unauthorized AI\n   activity across cloud and SaaS enviro
 nments.\n\n   Her technical work spans wireless protocol reverse engineeri
 ng\, binary\n   exploitation\, web and mobile reverse engineering\, cloud 
 and AI\n   security. She has applied these skills across medical hardware\
 ,\n   automotive platforms\, and enterprise cloud environments ā from BL
 E\n   command injection on FDA-listed devices to CarPlay API exploitation 
 to\n   building agentic AI detection controls at scale. As a UCLA\n   psyc
 hobiology alum with a consulting background\, she brings a\n   multidiscip
 linary lens to every system: understand what it's designed\n   to do first
 \, then find where it breaks.\n\n   SpeakerBio:  Muzzammil Mohammed\n\n   
 Muzzammil Mohammed is an offensive security researcher\, penetration\n   t
 ester at Maltek Solutions\, and MS in Cybersecurity at Northeastern\n   Un
 iversity. Operating out of the SPQR Lab under Professor Kevin Fu\,\n   and
  serving as a Teaching Assistant Network Security\, his work bridges\n   a
 cademic vulnerability research with real-world red team execution. As\n   
 a core developer of WandKit an open-source BLE attack toolkit built to\n  
  audit medical devices. Muzzammil led the cloud API exploitation phase\,\n
    successfully confirming a complete authentication bypass and\n   engine
 ering the rogue peripheral session hijack chain. Beyond hardware\n   and A
 PI hacking\, he is actively developing autonomous multi-agent AI\n   frame
 works designed to orchestrate local LLMs for automated security\n   auditi
 ng and vulnerability analysis.\n\n   SpeakerBio:  Narmina Karimova\n\n   N
 armina Karimova is a cybersecurity graduate researcher at\n   Northeastern
  University with a background in enterprise technology\n   across financia
 l institutions and the United Nations. She came to\n   security research f
 rom the infrastructure side\, which shaped how she\n   approached tearing 
 apart a consumer fertility monitor. For BRAT\, she\n   wrote the core BLE 
 attack suite in Python: replay modules\, rogue\n   peripheral session capt
 ure\, unauthenticated hormone data extraction\,\n   and the bind takeover 
 chain that captures device ownership in under 15\n   seconds. She also rev
 erse-engineered the APK with JADX\, found\n   hardcoded credentials\, and 
 confirmed a CVSS 9.1 IDOR in the\n   third-party integration. Her interest
  is in the gap between how\n   consumer health devices are marketed and ho
 w they actually handle\n   sensitive data.\n\n   '\n\n   1. #LVCCW_Level1_
 Hall3\n\n\n
DTEND:20260808T224500Z
DTSTART:20260808T220000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1003 (Demo Labs Track 3)
SUMMARY:Be like a BRAT(BLE Recon and Attack Toolkit): Skip the Handshake\, 
 Own the Device
END:VEVENT
END:VCALENDAR
