← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Def Cuts

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/Def Cuts/years/2018.md
Imported-content SHA-256
f5014fd17f936cece0fde54d2de21aafbaec40e0ff1ae965308067de68c6f9d7
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 12 August 2018 |
| Platform | Quiet Systems |
| Series | DC-Y-2018 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

2018 is the year the conference record shows commodity C-UAS failing because they assume an open, deauth-able command link: David Melendez Cano’s Project Interceptor (Black Hat USA Arsenal + DEF CON 26) and the Hardware Village build talk both turn on a small airframe whose control path is not on the bands those products expect.

### Key judgments

1. **[Assessment — High confidence]** C-UAS products that assume open Wi-Fi or a deauth-able command link do not stop a nanodrone that uses a hidden, replay-resistant side channel and an SDR fallback. That is the Interceptor finding, shown twice as one research program.
2. **[Assessment — High confidence]** No CVE, advisory, or Exploit-DB record is attached to the three 2018 talks. The failure is a detection/control-path assumption, not a patched ID.
3. **[Inference — Moderate confidence]** A Passport that scores C-UAS by “Wi-Fi deauth works on consumer drones” will miss airframes whose Control Fabric was built off those bands.

## 01. Commodity C-UAS miss a nanodrone with a hidden command path

*Event / publication dates: Black Hat USA 2018 Arsenal Theater demo 8–9 August 2018; DEF CON 26 main stage (101 Track) 11 August 2018, 15:00 PT (45 min). Same research; one signal.*

| Field | Value |
| --- | --- |
| Venue | DEF CON / Black Hat USA |
| Component | software |
| Product | commodity C-UAS products vs Project Interceptor nanodrone (David Melendez Cano) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** David Melendez Cano presented “Project Interceptor: Owning Anti-Drone Systems with Nanodrones” as a Black Hat USA 2018 Arsenal Theater demo and “Project Interceptor: avoiding counter-drone systems with nanodrones” on the DEF CON 26 main stage. Official pages: blackhat.com/us-18/arsenal.html (named Arsenal entry); defcon.org DC26 speakers. After-record: media.defcon.org DC26 video-and-slides; YouTube pVmFxJPOu9I; InfoconDB; TIB AV-Portal 39681. Slides were not in the DC26 presentations listing; the official after-record is the video-and-slides file. Failure class: commodity C-UAS that assume open Wi-Fi / deauth-able command links fail against a small airframe with a hidden replay-resistant side channel and SDR fallback control. No CVE, Exploit-DB ID, or talk-tied GitHub repository was found.

**Exposure.** Move (the airframe continues) and Act (C-UAS stop does not occur). The trust failure is on the C-UAS side: Sense is tuned to a command-link class the target is not using.

**Intelligence assessment.** [Assessment — High confidence] Arsenal and the main stage are one finding. [Assessment — High confidence] The physical consequence is an unstopped UAV in a volume operators believed was covered. [Uncertainty] No named C-UAS SKU or Interceptor repo is on the talk pages. [Inference — Moderate confidence] Any C-UAS Campaign that only Labs consumer Wi-Fi links will keep reporting false Act capability.

**Opportunity.** Passport C-UAS by command-link class covered (open Wi-Fi vs hidden / SDR), not by marketing category. Lab against a non-standard datalink. Watch for a later Interceptor repository or vendor advisory — none in this window.

**LRRK relevance.** Control Fabric (the hidden command path) vs C-UAS Sense-to-Act. Watch and Lab. Kestrel across C-UAS products that advertise Wi-Fi denial as the stop. KAT: radio assumption → missed Move.

**Confidence.** High on the official pages and video after-record. Moderate as a case against the whole C-UAS class. Low on unlisted product names.

## 02. Custom flight controllers keep the command path off expected bands

*Event / publication dates: August 2018, DEF CON 26 Hardware Hacking Village program.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | hardware |
| Product | custom Linux-router flight controllers and non-standard datalinks (Melendez Cano) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** David Melendez Cano presented “Building Drones the Hard Way” at the DEF CON 26 Hardware Hacking Village. Official village page: defcon.org DC26 villages. After-record: media.defcon.org DC26 villages video. Failure class: custom Linux-router flight controllers and non-standard datalinks are used to keep a UAV command path off the bands C-UAS products expect. No CVE, Exploit-DB ID, or GitHub research repo was found. This is a distinct titled village talk from Interceptor, not a second Arsenal slot.

**Exposure.** Control path / peripheral radio. Move continues when C-UAS Sense is looking at the wrong band. Hardware and datalink choices are the assurance question.

**Intelligence assessment.** [Assessment — High confidence] The village talk exists and states the build-side of off-band control. [Assessment — Moderate confidence] It is adjacent to Interceptor (same speaker, same year) but is a separate titled record. [Uncertainty] Controller board and radio part numbers are not independently listed on the village page. [Inference — Moderate confidence] Passport fields for flight-controller class and datalink band matter as much as airframe vendor.

**Opportunity.** Lab C-UAS against a Linux-router controller on a non-standard datalink. Passport “stock FC + stock radio” vs “custom controller / off-band link.” Do not treat a Hardware Village build talk as a CVE.

**LRRK relevance.** Control Fabric and Lab. Hardware on the kinematic path. Watch for later talks that name the radio. Campaign should group custom-controller airframes separately from consumer Wi-Fi quads.

**Confidence.** High on the village video. Moderate on how far the build generalizes beyond this speaker’s airframe.

## Forward indicators

1. A talk-tied Interceptor or custom-FC repository (none located).
2. C-UAS vendor claims that coverage extends past open Wi-Fi / deauth — those claims are now the thing to Lab.
3. Whether DroneWarz (now a full village at DC26) produces a titled, recorded technical talk next year; this year the arena had no additional titled after-record.
4. Any CVE or Exploit-DB ID that later cites Interceptor (none through the 2018 cutoff).

> **Collection integrity.** Public sources only. Inventory leftover for 2018: three talks, used as two signals (Interceptor at DEF CON 26 and Black Hat USA Arsenal is one research program; Hardware Village remains its own titled talk). Collection cutoff is DEF CON 26 Sunday, 12 August 2018. Searched: media.defcon.org DC26 presentations (Interceptor is the only kinematic main-stage title), video-and-slides, and villages; DC26 speakers and villages pages; Black Hat USA 2018 briefings (NIL; InfoconDB full title list) and Arsenal; Black Hat Europe 2018 briefings (NIL); Black Hat Asia 2018 briefings (NIL); IoT Village / Wireless Village 2018 (NIL). “Applied Self-Driving Car Security” (BH USA) excluded as vehicle cybersecurity, not GNSS-of-vehicle. **Village note.** No brand named “Drone Village” in 2017–2021. DroneWarz existed at DC26 as a contest / arena (defcon.org DC26 villages); no additional titled recorded talk was found on media.defcon.org beyond the Hardware Village item. Aerospace Village has not started (begins DC28 Safe Mode, 2020). **Excluded:** DroneWarz cage / CTF without a titled recorded talk; paid trainings; pre-window Luo / Rodday; HOPE / SAINTCON / Nuit du Hack / Codemotion. No invented talks. No CVE, Exploit-DB ID, or GitHub URL invented. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>