United We TransformCreate teamsGrade your agenda
Atlas/Events/DEF CON 33 - Workshops
action-oriented convening agenda analysis

DEF CON 33 - Workshops

This action-oriented convening in Technology / AI / Startup shows 80 visible agenda rows from defcon.org and scores 50/100: a promising public-evidence design, still below the strong-evidence threshold. The clearest public signals sit in Participation Architecture and Learning Transfer; the main limits are Follow Through and Network Design. Visible mechanisms include Participant work, Commitments, Feedback, and Network design. Follow-through or tracking is at least visible enough to inspect, though causal proof... A practical reading: For a reader, this is a useful but still incomplete public example: it reads as an action-oriented convening, with the strongest visible signal in participation architecture and learning transfer and the biggest open question around follow through and network design. The practical test is whether the published agenda connects the room to post-event continuation and evidence. This page is an original public-evidence analysis, not a copy of the source agenda or an endorsement of the event. The score places the visible agenda in the promising but still evidence-limited design band. The strongest visible pillars are Participation Architecture, Learning Transfer, and Future-of-Work Fit; the thinnest visible pillars are Network Design, Follow Through, and Evidence Maturity. Visible mechanisms include Participant work, Commitments, Feedback, Network design, and Learning transfer. The extracted agenda preview includes 115 visible rows. The most common formats are Workshop, Unknown, and Training; the most common inferred purposes are Co Creation, Participant Work, and Unknown.

Primary source evidence: defcon.org ↗ · Archived copy (2026-06-16)

Eight-pillar fingerprint

Hover any pillar to see what it measures and, where it scored low, what the agenda is missing.

Participation Architecture?91
Participation Architecture - 91/100. Participant work, contribution, interaction, and alternatives to passive broadcast.
Follow Through?16
Follow Through - 16/100. Owners, dates, commitments, progress checks, and accountability after the room.Missing: Add named owners, dates, implementation checkpoints, and a visible post-event continuation path.
Problem Specificity?46
Problem Specificity - 46/100. A clear costly problem, objective, decision, or performance target.
Personalization?46
Personalization - 46/100. Role, path, goal, preparation, or connection tailoring for participants.
Network Design?16
Network Design - 16/100. Structured weak ties, bridge-building, mixers, and relationship persistence.Missing: Replace generic networking blocks with designed introductions, ask-offer exchanges, peer groups, or bridge-building rituals.
Learning Transfer?62
Learning Transfer - 62/100. Applied practice, feedback, workplace use, refreshers, and 30-90 day transfer.
Evidence Maturity?35
Evidence Maturity - 35/100. Baseline, comparison, follow-up, isolation, and attribution confidence.Missing: Add baseline measurement, comparison logic, tracking, or post-event impact reporting so effectiveness is not inferred only from format.
Future-of-Work Fit?59
Future-of-Work Fit - 59/100. Value against time, hybrid reality, accessibility, AI, and meeting load.

Fix the gaps

Field-tested exercises matched to this agenda's weakest pillars, from the exercise library.

Agenda Preview

The actual agenda we captured. Every block is classified by format and purpose. Open any block to see how we read it; the colored edge shows whether it is participant work, broadcast, logistics, or a showcase.

Room vs wrapper

82 percent of the 115 classified blocks put participants to work; the rest broadcast, show, or handle logistics. That mix is what drives the participation score.

94
15
6
Participant workBroadcastShowcaseLogistics
all eventWorkshopsWorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all eventTrainingTrainingSkill building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisParticipant work is implied by the formatInferred from format
all eventDemo LabsWorkshopShowcase+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all event64-bit Intel Assembly Language Programming for HackersPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventAnalyzing and Creating Windows Shellcode for HackersPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventCloud Forensics Workshop: Smart Grid EditionWorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all eventContextualizing alerts with relevant logs and events without queries or LLMsPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventCreating malicious functional app on AndroidPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventDeep-dive into modern network fingerprintingPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventDefeating Malware Evasion: Techniques and CountermeasuresPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
14:00Friday for 4 hours, at LVCC - L2 - N253 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Friday for 4 hours, at LVCC - L2 - N257 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Saturday for 4 hours, at LVCC - L2 - N260 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Friday for 4 hours, at LVCC - L2 - N256 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Sunday for 4 hours, at LVCC - L2 - N256 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Friday for 2 hours, at LVCC - L2 - N252 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Sunday for 4 hours, at LVCC - L2 - N255 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Saturday for 4 hours, at LVCC - L2 - N258 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Sunday for 4 hours, at LVCC - L2 - N257 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Friday for 4 hours, at LVCC - L2 - N258 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all eventDIY Malware Emulation: Build It, Break It, Detect ItBreakPacing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisOutcome inferred from formatInferred from format
09:00Sunday for 4 hours, at LVCC - L2 - N252 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Saturday for 4 hours, at LVCC - L2 - N254 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Sunday for 4 hours, at LVCC - L2 - N260 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Friday for 4 hours, at LVCC - L2 - N260 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all eventFortifying AI: Hands-On Training in Adversarial Attacks and Defense of AI SystemsWorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Saturday for 4 hours, at LVCC - L2 - N252 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Saturday for 4 hours, at LVCC - L2 - N257 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Sunday for 4 hours, at LVCC - L2 - N254 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Saturday for 4 hours, at LVCC - L2 - N256 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Sunday for 4 hours, at LVCC - L2 - N258 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all eventHands-on Kubernetes Attack & Defense MasterclassWorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Friday for 4 hours, at LVCC - L2 - N255 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
09:00Saturday for 4 hours, at LVCC - L2 - N253 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
14:00Saturday for 4 hours, at LVCC - L2 - N255 (Workshops)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all eventWorkshopsWorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventTrainingTrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventDemo LabsDemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all event64-bit Intel Assembly Language Programming for HackersUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventAccelerating Malware Analysis with WinDbg Time Travel DebuggingUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventAdvanced Ghidra Scripting& AutomationUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventAnalyzing and Creating Windows Shellcode for HackersUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventCloud Forensics Workshop: Smart Grid EditionWorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventContextualizing alerts with relevant logs and events without queries or LLMsUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventCreating malicious functional app on AndroidUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventDeep-dive into modern network fingerprintingUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventDefeating Malware Evasion: Techniques and CountermeasuresUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
14:00 Friday for 4 hours, at LVCC - L2 - N253 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
09:00 Friday for 4 hours, at LVCC - L2 - N257 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventMalware analysis and reverse engineering involve intricate execution, obfuscation, and anti-analysis techniques that hinder traditional debugging. This intensive, hands-on workshop introduces WinDbg's powerful Time Travel Debugging (TTD), allowing you to record a complete execution trace and replay it forwards and backwards. Designed for reverse engineers and malware analysts, this workshop provides practical skills to harness TTD, significantly cutting analysis time compared to traditional methods.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventJoshua is an experienced malware analyst and reverse engineer and has a passion for sharing his knowledge with others. He is a reverse engineer with the FLARE team at Google, where he focuses on tackling the latest threats. He is an accomplished trainer, providing training at places such as Ring Zero, Black Hat, DEF CON, ToorCon, Hack In The Box, SuriCon, and other public and private venues. He is also an author on Pluralsight, where he publishes content around malware analysis, reverse engineering, and other security related topics.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventBack to topUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
09:00 Saturday for 4 hours, at LVCC - L2 - N260 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventWhen you are reverse engineering a file and have to repeatedly perform the same mundane task, you start to wonder how to perform the action automatically. This workshop provides the basis for automating tasks with Ghidra. We will look at a wiper used to target Ukrainian victims in late February 2022.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis four-hour workshop primarily focuses on how to automate repeated activities and how to think in a way that is supported by the analysis framework’s API. You can transfer this knowledge to other reverse engineering suites, although the specific API calls will differ. This class is perfect for aspiring and beginning analysts, while also providing background information and additional techniques for intermediate analysts.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThe workshop’s materials consist of multiple malware samples, the precautions for which will be explained in-detail during the workshop, ensuring the safety and integrity of the systems of the attendees. An x8664 laptop with Ubuntu 22.04 or later, along with Ghidra, Eclipse, and OpenJDK 21 is required. Its mandatory to be able to understand the basics of assembly language and decompiled code, and to be able to read and write Java. Python 2 can be used as a substitute if desired, but is not fully supported.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventMax Kersten is a malware analyst, blogger, and speaker who aims to make malware analysis more approachable for those who are starting. In 2019, Max graduated cum laude with a bachelor's in IT & Cyber Security, during which Max also worked as an Android malware analyst. Currently, Max works as a senior malware analyst at Trellix, where he analyses APT malware and creates open-source tooling to aid such research. Over the past few years, Max spoke at international conferences, such as DEFCON, Black Hat (USA, EU, MEA, Asia), Botconf, Confidence-Conference, HackYeahPL, and HackFestCA. Additionally, he gave guest lectures and workshops for DEFCON, Botconf, several universities, and private entities.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
14:00 Friday for 4 hours, at LVCC - L2 - N256 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
09:00 Sunday for 4 hours, at LVCC - L2 - N256 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventSince 2017, the Cloud Forensics Workshop has introduced security professionals to core Cloud forensics concepts. The latest Smart Grid Edition explores the relationship between smart grids, Cloud computing, and digital forensics. Participants will engage in hands-on labs using open-source tools to identify indicators of compromise (IoCs), acquire forensically sound artifacts, and apply AI and automation in investigations. Registered students will download sample data before the workshop and apply their skills in a live tabletop exercise.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventEver the security enthusiast and a sucker for movie references, combined with a deep passion for teaching and mentoring; Mr. Hazelton created the Cloud Forensics Workshop and CTF Challenge in 2017, which is a technical workshop that focuses on learning about the science of Cloud forensics and its real-world applications, followed by a Capture-the-Flag competition to gauge his students’ comprehension and critical-thinking skills by solving multiple forensic puzzles in a race against each other within the allotted amount of time.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
14:00 Friday for 2 hours, at LVCC - L2 - N252 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis workshop is for SOC analysts, threat hunters, and defenders dealing with alert fatigue, fragmented telemetry, and the challenge of spotting coordinated attacks. Instead of large language models or costly vendor tools, we’ll use open-source, explainable ML to map alerts, logs, and events into contextualized attack stories.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
09:00 Sunday for 4 hours, at LVCC - L2 - N255 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis workshop provides an in-depth, hands-on experience in the creation and analysis of malicious applications, focusing on the techniques used by attackers to compromise mobile devices. Participants will learn how to manipulate Android applications using tools such as Android Studio, APKTool, Burp Suite, and Metasploit to inject payloads, bypass security mechanisms, and establish remote access. Through step-by-step demonstrations, they will explore methods for obfuscation, privilege escalation, and persistence, gaining a clear understanding of how adversaries exploit vulnerabilities in mobile environments.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventBeyond offensive techniques, the workshop emphasizes defensive strategies, equipping attendees with skills to detect, analyze, and mitigate mobile threats. Using malware analysis and reverse engineering, students will learn how security professionals track, neutralize, and prevent attacks. Real-time lab exercises will reinforce these concepts, ensuring that participants leave with practical expertise applicable to ethical hacking, penetration testing, and security research. This session is ideal for cybersecurity professionals, developers, and researchers looking to deepen their knowledge of mobile security and ethical hacking methodologies.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventHackeMate is the YouTube channel where Gianpaul Custodio, a Offensive Cybersecurity Engineer, shares his expertise in ethical hacking, as well as offensive and defensive security. With over 28,000 subscribers engaged in the world of cybersecurity, he has established himself as a key figure in the community through challenges, technical analyses, and hands-on demonstrations.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventIn this hands-on workshop you’ll move beyond the theory of network fingerprinting and actually use them in practice at both the TCP and TLS layers. Working in live lab environments, you will:WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventVlad is the co-founder and cybersecurity expert at ELLIO and President of the Anti-Malware Testing Standards Organization (AMTSO).A true cybersecurity enthusiast, Vlad’s passionate about network security, IoT, and cyber deception. Before ELLIO, he founded and led the Avast IoT Lab (now Gen Digital), developing security features and researching IoT threats. He has spoken at many conferences, including Web Summit and South by Southwest (SXSW), where he demonstrated IoT vulnerabilities.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
14:00 Saturday for 4 hours, at LVCC - L2 - N258 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis workshop is designed to give students the skills they need to identify and defeat common evasion techniques used by malware. It’s broken up into three hands-on modules where students will work with a range of open-source (or otherwise free) tools to dig into malicious code, examine different evasion techniques, and learn how to circumvent them to better understand how the malware operates. We’ll be using a mix of instructor-created malware samples - with full source code provided so students can analyze both the binary and the code side-by-side - and real-world samples found in the wild. By the end of the workshop, students will walk away with several malware samples, pages of code to keep digging into on their own, and a solid toolkit of techniques for breaking through typical anti-analysis and evasion tricks used in modern malware.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventRandy leads threat detection and engineering teams at Proofpoint, using custom dynamic sandbox systems to detect evasive malware and phishing threats that target customers around the world. He previously led threat hunting and endpoint detection engineering at Binary Defense, and investigated botnets and other cyber criminal activities as a member of the FBI Cyber Action Team and Seattle Cyber Task Force. Randy currently volunteers as a digital forensic analyst with The DFIR Report, and organizes DEATHCon, a global conference for Detection Engineering and Threat Hunting workshops.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
09:00 Sunday for 4 hours, at LVCC - L2 - N257 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventPreston Zen is a OSCE3 Cybersecurity Certified maker and breaker of all things technology from custom electronics to bespoke software. Humanitarian volunteer in Ukraine since 2022 in logistics and engineering as well as one of the leading innovators of field implemented technology use casesBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
14:00 Friday for 4 hours, at LVCC - L2 - N258 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventHis research leads him to present his results on several conferences such as LeHack (Paris), Insomni'hack, BlackAlps (Swiss) or even through a 4-hour malware workshop at Defcon31 and Defcon32 (Las Vegas). All along the year, he publishes several white papers on the techniques he discovered or upgraded and the vulnerabilities he found on public products.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventDIY Malware Emulation: Build It, Break It, Detect ItBreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
09:00 Sunday for 4 hours, at LVCC - L2 - N252 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventReal threats leave behind real artifacts - and in this hands-on workshop, we’ll combine malware development and analysis by safely recreating and dissecting a custom malware based on Lumma Stealer, one of today’s most active malware families. This approach is designed to support adversary emulation efforts by replicating real-world TTPs in a controlled environment, while also teaching participants how to detect and analyze each technique. Whether you're on a red or purple team looking to simulate attacker behavior, or on a blue team aiming to strengthen detection capabilities, this workshop delivers practical skills grounded in real-world threats.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventSebastian breaks things to understand them - and sometimes to teach others how to do it better. He’s spent years in red teaming, malware reversing, and purple team exercises - learning how attackers think, and how defenders can think better. These days, he builds labs, breaks code, and shares what he learns so others can level up, too.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
09:00 Saturday for 4 hours, at LVCC - L2 - N254 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
09:00 Sunday for 4 hours, at LVCC - L2 - N260 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
14:00 Friday for 4 hours, at LVCC - L2 - N260 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventIn today’s landscape, generative AI coding tools are powerful but often insecure, raising concerns for developers and organizations alike. This hands-on workshop will guide participants in building a secure coding assistant tailored to their specific security needs.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventYariv Tal is a senior developer & security researcher, and the cofounder of Secure From Scratch - a venture dedicated to teaching developers secure coding from the very first line of code. A summa cum laude graduate from the Technion, leveraging four decades of programming expertise and years of experience in university lecturing and bootcamp mentoring, he brings a developer's perspective to the field of security. Currently, he lectures on secure coding at several colleges and the private sector, he is the leader of the owasp-untrust project and is currently pursuing a master's degree in computer science and lectures in several colleges.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventFortifying AI: Hands-On Training in Adversarial Attacks and Defense of AI SystemsWorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
09:00 Saturday for 4 hours, at LVCC - L2 - N252 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventAs AI becomes integral to critical systems, its vulnerabilities to adversarial attacks and data-related weaknesses pose serious risks. This interactive, one-day training is designed for AI practitioners, researchers, and security professionals to understand and mitigate these challenges. Participants will gain a comprehensive foundation in AI security, exploring adversarial attack techniques, defense mechanisms, and best practices for building robust datasets.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventHe has shared his research and insights at prominent international conferences, including BlackHat, DEFCON, FIRST, and the SANS DFIR Summit, where his sessions have been highly regarded for their depth and practical relevance. Additionally, Vishal has delivered training and workshops at BlackHat and the FIRST Conference, equipping participants with cutting-edge skills and techniques. Vishal currently leads the Incident Response function for APAC region at Atlassian.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis hands-on workshop explores the offensive and defensive security challenges of Generative AI (GenAI). In the first half, participants will use structured frameworks and rapid threat prototyping to map out real-world GenAI risks such as - prompt injection, data poisoning, and model leakage. Working in teams, you'll threat model a GenAI system using simplified STRIDE and Rapid threat prototyping techniques and visual diagrams.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis workshop is ideal for red teamers, security engineers, and curious builders. Just bring basic Python familiarity and a laptop - we’ll supply the rest.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventYou’ll walk away with real-world threat models, working tool prototypes, and a clear framework for breaking and securing AI systems in your org.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
all eventAshwin is an EC-Council CodeRed instructor (Session Hijacking & Prevention), a reviewer for Hands-On Red Team Tactics (Packt), and a contributor to PCI SSC’s segmentation guidance for modern networks. He has delivered hands-on workshops at BSidesSF, HackGDL, and Pacific Hackers on topics like GenAI threat modeling, Practical Threat Modeling for Agile.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
14:00 Saturday for 4 hours, at LVCC - L2 - N257 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventIn this workshop we'll create a Hacker VPN that combines the best of VPNs, Tor, and E2EE secure comms apps. We'll use modern-day PQC encryption to implement a secure protocol. We'll use both TCP/UDP as our network protocols to demonstrate flexibility in design. We'll support packet sharding, random noise injection, multi-hop routing, and 100% anonymity between network endpoints. We'll do all this on Linux with standard C++, CMake & OpenSSL. At the end of this workshop you'll have all the tools you need to take the Hacker VPN to the next level. Why trust outdated software from shady companies when you can build your own modern day, kick-ass implementation?WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventEijah is the founder of Code Siren, LLC and has 25+ years of experience in software development. He is the creator of Polynom, the world's first CNSA Suite 2.0 PQC collaboration app. He is also the developer of Demonsaw, an encrypted communications platform that allows you to share information without fear of data collection or surveillance. Before that Eijah was a Lead Programmer at Rockstar Games where he created Grand Theft Auto V and Red Dead Redemption 2. In 2007, Eijah hacked multiple implementations of the Advanced Access Content System (AACS) protocol and released the first Blu-ray device keys under the pseudonym, ATARI Vampire. He has been a faculty member at multiple colleges, has spoken at DEF CON and other security conferences, and holds a master’s degree in Computer Science. Eijah is an active member of the hacking community and is an avid proponent of Internet freedom.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
09:00 Sunday for 4 hours, at LVCC - L2 - N254 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventTired of legacy ICS systems? Attend this workshop to hack the next generation of Industrial Control Systems,! No more Modbus, no more standard PLC, no more Purdue model! This workshop is designed to show what the future might look like for Industrial Control Systems, with a focus on ML & AI!WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventArnaud Soullié is a Senior Manager at Wavestone, a global consulting company. For 15 years, he has been performing security assessments and pentests on all types of targets. He started specializing in ICS cybersecurity 10 years ago. He has spoken at numerous security conferences on ICS topics, including: BlackHat Europe, BruCon, 4SICS, BSides Las Vegas, and DEFCON. He is also the creator of the DYODE project, an open source data diode aimed at ICS. He has taught ICS cybersecurity trainings since 2015.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventAlexandrine Torrents is a Senior Manager at Wavestone. She started as a penetration tester, and performed several cybersecurity assessments on ICS. She worked on a few ICS models to demonstrate attacks on PLCs and developed a particular tool to request Siemens PLCs. Then, she started working at securing ICS, especially in the scope of the French military law, helping companies offering a vital service to the nation to comply with security rules. Now, Alexandrine works with different industrial CISOs on their cybersecurity projects: defining secure architectures, hardening systems, implementing detection mechanisms. She is also IEC 62443 certified and still performs assessments on multiple environments.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
14:00 Saturday for 4 hours, at LVCC - L2 - N256 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
09:00 Sunday for 4 hours, at LVCC - L2 - N258 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventHands-on Kubernetes Attack & Defense MasterclassWorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
14:00 Friday for 4 hours, at LVCC - L2 - N255 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventMadhu frequently speaks and runs training sessions at security events and conferences around the world including DEFCON 24, 26, 27, 28, 29 & 30, BlackHat 2018, 19, 21 & 22, USENIX LISA 2018, 19 & 21, SANS Cloud Security Summit 2021 & 2022, O’Reilly Velocity EU 2019, Github Satellite 2020, Appsec EU (2018, 19 & 22), All Day DevOps (2016, 17, 18, 19, 20 & 21), DevSecCon (London, Singapore, Boston), DevOpsDays India, c0c0n(2017, 18), Nullcon 2018, 19, 21 & 22, SACON, Serverless Summit, null and multiple others.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
09:00 Saturday for 4 hours, at LVCC - L2 - N253 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventChris is a Packet Analyst at Packet Pioneer, specializing in network performance analysis and forensics using Wireshark. Whether he's investigating complex issues at the packet level or leading hands-on training sessions, Chris is passionate about helping others master the art of packet analysis.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis hands-on workshop takes a deep dive into how browser extensions operate under the hood and exposes how easily legitimate APIs can be weaponized to exfiltrate credentials, hijack sessions, monitor user behavior, and leak sensitive corporate information. By reverse-engineering real-world extension behavior and building functioning proof-of-concept (PoC) malicious extensions, participants will gain a direct understanding of the risks these extensions pose.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventUsing cryptography is often a subtle practice and mistakes can result in significant vulnerabilities. This workshop will cover many of these vulnerabilities which have shown up in the real world, including CVE-2020-0601. This will be a hands-on workshop where you will implement the attacks after each one is explained. I will provide a VM with a tool written in Python to execute the attacks. A good way to determine if this workshop is for you is to look at the challenges at cryptopals.com and see if those look interesting, but you could use in person help understanding the attacks. While not a strict subset of those challenges, there is significant overlap. The exercises will range from decrypting ciphertext to recovering private keys from public key attacks allowing us to create TLS cert private key and ssh private key files.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventMatt Cheung started developing his interest in cryptography during an internship in 2011. He worked on implementation of a secure multi-party protocol by adding elliptic curve support to an existing secure text pattern matching protocol. Implementation weaknesses were not a priority and this concerned Matt. This concern prompted him to learn about cryptographic attacks from Dan Boneh's crypto 1 course offered on Coursera and the Matasano/cryptopals challenges. From this experience he has given workshops at the Boston Application Security Conference, BSidesLV, DEF CON, and the Crypto and Privacy VillageHe now serves on the programming committee of the Crypto and Privacy Village. He now serves on the programming committee of the Crypto and Privacy Village.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
14:00 Saturday for 4 hours, at LVCC - L2 - N255 (Workshops)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventKubernetes is now at the heart of modern infrastructure, yet offensive security content targeting real-world K8s exploitation is still underrepresented - even at DEF CON. K8sploitation: Hacking Kubernetes the Fun Way fills that gap by diving deep into hands‑on Kubernetes hacking techniques including privilege escalation, lateral movement, and control plane compromise. In this workshop, we set aside the buzzwords and focus on practical attacks and defenses drawn from real adversary tradecraft. Whether you’re a red teamer looking to understand how attackers think or a defender seeking to shore up your cluster’s security, you’ll gain invaluable insights through live demos, guided labs, and lessons learned from enterprise and government security operations. This session bridges cloud‑native technology with hands‑on offensive security training in a way that’s rare, relevant, and overdue.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventOver the past few years, BLE CTF has expanded to support multiple platforms and skill levels. Various books, workshops, training, and conferences have utilized it as an educational platform and CTF. As an open source, low-cost of entry, and expandable education solution, BLE CTF has helped progress Bluetooth security research.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventThis workshop will teach the fundamentals of interacting with and hacking Bluetooth Low Energy services. Each exercise, or flag, aims to interactively introduce a new concept to the user. For this workshop, we will undergo a series of exercises to teach beginner students new concepts and allow more seasoned users to try new tools and techniques. After completing this workshop, you should have a good solid understanding of how to interact with and hack on BLE devices in the wild.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventA seasoned medical device red team hacker with nearly a decade in the trenches, Alex Delifer (cheet) breaks stuff so others can sleep at night. He operates out of an unnamed medtech company, where he regularly tears through embedded systems, surgical robots, industrial controllers, APIs, and BIOS firmware like it’s target practice. A Biohacking Village Capture the Flag Champion at DEF CON, he’s known in some circles as the medical device testing sledgehammer - swinging hard, finding the flaws others miss, and leaving no UART unturned.BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source

The Full Reading

Why It Ranks This Way +

Calibrated from GES design 47/100 and verified 46/100 with no fourth-loop cap.

Reader Takeaway. For a reader, this is a useful but still incomplete public example: it reads as an action-oriented convening, with the strongest visible signal in participation architecture and learning transfer and the biggest open question around follow through and network design. The practical test is whether the published agenda connects the room to post-event continuation and evidence.

Strongest signals: Participation Architecture, Learning Transfer, and Future-of-Work Fit. Weakest signals: Network Design, Follow Through, and Evidence Maturity.

How This Agenda Could Improve +
  • Replace generic networking blocks with designed introductions, ask-offer exchanges, peer groups, or bridge-building rituals.
  • Add named owners, dates, implementation checkpoints, and a visible post-event continuation path.
  • Add baseline measurement, comparison logic, tracking, or post-event impact reporting so effectiveness is not inferred only from format.

Fastest next move: Add named owners, dated next steps, and a visible continuation path before treating the event as outcome-ready.

Role-Specific Reading +

Event owner lens

Use this record to benchmark whether a comparable event makes the work after the room visible. The score is 50/100, so the next move is to benchmark the weakest pillars before repeating the format.

Sponsor lens

Look beyond exposure. Strong sponsor value would show qualified interaction, problem work, buyer learning, customer evidence, or follow-up. The practical sponsor move is to look for structured introductions, buyer-seller fit, and relationship persistence.

Designer lens

The agenda is useful as a pattern sample from defcon.org. Redesign attention should go first to the lowest-scoring pillars; in practice, turn the thinnest agenda blocks into participant work.

Executive lens

Treat the visible agenda as an operating plan. The executive move is to require owners, dates, and evidence before treating the event as strategic. If owners, proof, and follow-through are not visible, the public record does not yet prove strategic movement.

Aggregator lens

Treat the source URL as evidence, not decoration. The data-product move is to label the source boundary clearly before ranking the record before ranking or syndicating the record.

What GES Means Here +

The Gathering Effectiveness Score is a strict 0-100 public-evidence reading of the agenda across eight pillars. It rewards visible participant work, follow-through, transfer, network design, and proof mechanisms more than polish, speaker fame, attendance, or satisfaction.

Visible mechanisms: Participant work, Commitments, Feedback, Network design, Learning transfer, Personalization.

Evidence boundary: Scores reflect visible agenda/source evidence and should not be read as proof of causal event impact.

Limitations, Score Caps, and Review Flags +

Limitations

  • No baseline measurement is visible.

Score caps

  • No fourth-loop score cap applied.

Review flags

  • Satisfaction/NPS signal found, but it is excluded from effectiveness scoring.
  • No tracking, validation, feedback, or impact measurement found in the visible source text.
  • High cleanup rate: many extracted rows were hidden or merged as fragments.
  • Original category was unknown; publication category is inferred.
Is this proof the event worked? +

No. This is a strict public-evidence reading of the agenda. Proof would require baseline, comparison, follow-up, attribution, and impact evidence beyond the listing.

What should a reader inspect first? +

Start with the source URL, then compare the eight pillar scores against the agenda rows. The biggest opportunities usually sit in follow-through, evidence maturity, and participant work.

Why publish weak records? +

Weak records are part of the map. They show where public agendas still describe sessions and speakers more often than outcomes, commitments, transfer, or proof.

How should I use the rows? +

Read the agenda rows as the visible design trace: formats, purposes, and evidence labels show what the public source made inspectable, not everything that happened in the room. This is a source-grounded interpretation of the public agenda record, not a copy of the source, and not an endorsement of the event.

Embed the verified badge +

This record is in the hand-verified gold set. Copy the snippet below to embed the verified badge on your own site.

<a href="https://unitedwetransform.com/events/evt_2025_def_con_33_workshops_defcon_org"><img src="https://unitedwetransform.com/badge/ges-verified.svg" alt="GES verified by United We Transform" height="40"></a>

Where To Go Next

Compare this agenda against other Technology / AI / Startup events scored on the same eight pillars.