# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 7 December 2023 |
| Platform | Quiet Systems |
| Series | DC-Y-2023 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

DEF CON 31 put one kinematic talk on the main stage: frequency-hopping disposable drones that degrade C-UAS jamming, while unprotected DIY command links stay open to RF denial. Black Hat 2023 briefings were NIL.

### Key judgments

1. **[Assessment — High confidence]** The only verified 2023 primary is Melendez and García, DEF CON 31 Track 4, 12 August 2023, with a live speakers page and slides plus demos on `media.defcon.org`.
2. **[Assessment — High confidence]** Aerospace Village DEF CON 31, IoT / Hardware / RF village pages, and Black Hat USA / Europe / Asia 2023 briefing landings added no in-scope title. InfoconDB lists a “Strix Interceptor” C-UAS demo that is not on the live DEF CON 31 speakers page and has no village primary, so it is not a signal.
3. **[Inference — Moderate confidence]** The year’s public conference signal is C-UAS effectiveness against hopping disposable airframes, not a named-product CVE on a flight stack or GCS.

## 01. Frequency-hopping disposable drones degrade C-UAS jamming

*Event / publication dates: Saturday 12 August 2023, 11:00 PT (45 min), DEF CON 31 Track 4.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | firmware |
| Product | Disposable / DIY drones (unnamed); C-UAS jammers (unnamed) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** David Melendez and Gabriela “Gabs” García presented *Spread spectrum techniques in disposable drones for anti drone evasion* on DEF CON 31 Track 4. Official speakers page: `https://www.defcon.org/html/defcon-31/dc-31-speakers.html#Melendez`. Slides and demos sit on the DEF CON 31 `media.defcon.org` presentations directory; video is on the DEF CON channel (`https://www.youtube.com/watch?v=8Ng91UY3D2M`). No CVE, advisory, Exploit-DB ID, or GitHub repo was published with the talk. Failure class on the record: unprotected DIY drone command links stay exposed to RF denial, so frequency-hopping airframes degrade C-UAS jamming.

**Exposure.** Act on C-UAS: hop-capable disposable airframes reduce the effect of RF denial that assumes a fixed command link. Move on the DIY airframe: an unprotected command link can still be denied, which is loss of control and a crash or fly-away, not a new airframe CVE.

**Intelligence assessment.** [Assessment — High confidence] This is the only 2023 conference primary that names both a UAS command-link class and a C-UAS physical consequence. [Uncertainty] The talk does not name a vendor product, CVE, or patched build. [Inference — Moderate confidence] C-UAS claims that treat disposable DIY links as fixed-frequency will overstate jam effectiveness against hopped airframes.

**Opportunity.** Passport whether a given disposable or DIY command link is authenticated, or only hopped. Watch C-UAS product claims that assume a static DIY bearer. Lab hop-versus-jam as a class of outcome (denied versus still-commanded), not as a recipe.

**LRRK relevance.** Control Fabric on the DIY command link. Watch on C-UAS effectiveness claims. Lab and KAT from RF denial to loss of Move. Sense-Move-Act: Act is the C-UAS side; Move is the airframe that stays or falls off the link.

**Confidence.** High on the talk page, slides, and after-record. Moderate as a fleet case: no named product or CVE.

## Forward indicators

1. A vendor or C-UAS advisory that names hop-capable disposable airframes as a jam-effectiveness limit.
2. A CVE or maintainer note on DIY / open command-link authentication that cites this talk or the same failure class.
3. A later DEF CON or Black Hat briefing that names a product C-UAS against hopped disposable drones.
4. Any live primary for the InfoconDB “Strix Interceptor” item, which stays unrecorded until a speakers or village page exists.

> **Collection integrity.** Public sources only. No invented talks. No exploit steps, PoCs, or payloads. Also searched in 2023 with no additional in-scope talk: Aerospace Village DEF CON 31 talk list (`aerospacevillage.org/defcon-31-talks`) — space, ISS, 737, weather-radiosonde, satellite-comms; GPS appears as a satellite service, not a vehicle/UAS briefing. IoT / Hardware / RF village 2023 pages: no in-scope title. InfoconDB “Strix Interceptor” excluded (no live DEF CON 31 or village primary). Black Hat USA / Europe / Asia briefings 2022–2026: NIL. Excluded as not talks or not in filter: paid trainings; Drone Zone or cage/CTF activities without a named talk; manned-aviation datalinks; satellite / space-mission talks without a vehicle GNSS or UAS datalink focus. Last in-scope conference day 2023 is Black Hat Europe, 7 December 2023.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
