# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 7 August 2011 |
| Platform | Quiet Systems |
| Series | DC-Y-2011 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

The 2011 record is one research line on two stages: a surplus target-drone plus open autopilot and XBee telemetry used as a standoff RF payload truck (WASP), briefed at Black Hat USA and again at DEF CON 19.

### Key judgments

1. **[Assessment — High confidence]** Perkins and Tassey’s WASP work is the only verified kinematic class this year. Black Hat Europe 2011 is NIL for UAV / GNSS-vehicle briefings.
2. **[Assessment — High confidence]** The failure class is the airframe as an RF truck, not a disclosed command-link takeover of a third-party UAV. No CVE, advisory, or Exploit-DB ID attaches.
3. **[Inference — Moderate confidence]** ArduPilot plus commodity XBee telemetry, shown in public as an autonomous payload bearer, is an early Control Fabric fact for later Passport work on unsigned hobby links.

## 01. Perkins / Tassey: WASP surplus drone as a standoff RF payload truck

*Event / publication dates: presented 3 August 2011 (Wednesday 16:45 PT), Black Hat USA 2011, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | Black Hat USA |
| Component | hardware |
| Product | WASP (Wireless Aerial Surveillance Platform); surplus target-drone airframe; open autopilot; XBee telemetry |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Richard Perkins and Mike Tassey presented “Aerial Cyber Apocalypse: If we can do it... they can too.” on the Black Hat USA 2011 archive. Wired (August 2011), Dark Reading, and ABC News covered the same WASP build as a surplus Army-target airframe turned into a hacker RF platform. InfoconDB lists Tassey as presenter. No CVE or Exploit-DB ID was found for the talk window.

**Exposure.** Sense and Act: standoff wireless / cellular collection from an autonomous airframe. Move is the delivery path (the truck), not a disclosed victim-vehicle hijack.

**Intelligence assessment.** [Assessment — High confidence] Named-outlet after-record corroborates the briefing object as WASP, not a vendor bug class. [Uncertainty] The Black Hat archive page is the official listing; slide-level product pins sit with the DEF CON after-record. [Inference — Moderate confidence] A surplus airframe plus open autopilot is enough to put RF payloads over a target without a new airframe design.

**Opportunity.** Passport hobby autopilot and XBee-class telemetry as unsigned bearers. Kestrel this truck class against later collector UAVs (2014 Snoopy, 2016 Danger Drone). Watch for a vendor or military statement on surplus-airframe reuse — none is in this record.

**LRRK relevance.** Watch and Control Fabric. Campaign “UAV-as-RF-truck.” Lab the open-autopilot plus commodity telemetry pairing. Sense-Move-Act: the airframe moves a payload that senses.

**Confidence.** High on the briefing and press after-record. Moderate as a reusable case — product versions are not pinned.

## 02. Tassey / Perkins: Wireless Aerial Surveillance Platform on ArduPilot and XBee

*Event / publication dates: presented 7 August 2011 (Sunday 16:00 PT), DEF CON 19, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | hardware |
| Product | WASP; ArduPilot; XBee datalink |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Mike Tassey and Rich Perkins presented “Wireless Aerial Surveillance Platform” at DEF CON 19. The DEF CON 19 archive, media.defcon.org slides, and media.defcon.org video are the primary record. InfoconDB cross-checks the title. The inventory failure class is the same WASP class as the Black Hat USA briefing: an autonomous UAV carrying wireless / cellular payloads over an ArduPilot plus XBee datalink.

**Exposure.** Sense (aerial wireless / cellular payload) and Move (autonomous airframe on an open autopilot). The datalink is the control fabric for the truck, not a disclosed hijack of someone else’s craft.

**Intelligence assessment.** [Assessment — High confidence] Slides plus video make this the A1 technical record of the same research briefed three days earlier at Black Hat USA. [Assessment — High confidence] No CVE, advisory, or Exploit-DB ID attaches. [Inference — Moderate confidence] Naming ArduPilot and XBee on stage is a Watch marker for later unsigned-link work, not evidence of a 2011 catalogued flaw.

**Opportunity.** Lab ArduPilot plus XBee as a pair: who may speak on the telemetry bearer. Passport “open autopilot / commodity radio” as a fabric class. Kestrel against 2012 Paparazzi and later MAVLink-stage gaps (those talks are NIL in this window).

**LRRK relevance.** Control Fabric, Lab, Watch. KAT path is radio and autopilot as payload truck, not victim command injection.

**Confidence.** High on the talk, slides, and video. Moderate on treating ArduPilot / XBee as a standing fabric risk without a contemporaneous advisory.

## Forward indicators

1. A venue talk that treats ArduPilot, XBee, or a GCS datalink as the victim command path.
2. A CVE or vendor advisory on hobby autopilot telemetry.
3. Recurrence of surplus or low-cost airframes as RF trucks at Black Hat or DEF CON.
4. Any Black Hat Europe kinematic briefing (2011 is NIL).

> **Collection integrity.** Searched media.defcon.org DEF CON 19 presentations and video-and-slides; defcon.org DC19 archive; Black Hat USA 2011 archives; Black Hat Europe 2011 archive listings and contemporaneous coverage; InfoconDB; Wired, Dark Reading, ABC News. Two counted talks are the same WASP research at two venues. Black Hat Europe 2011 is NIL. Out-of-venue items (SkyJack, Humphreys / UT Austin civil-GPS UAV capture, HOPE 2012 “Pwn the Drones,” ADS-B / ATC, car CAN) stayed out. No invented talks. No exploit steps. CVE / Exploit-DB / GitHub research repo: none found.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
