← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Def Cuts

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/Def Cuts/years/2017.md
Imported-content SHA-256
f1c9547de900073f19e91ba6dd65f08e5230d783eebe1a66006f8817cba92fdb
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 30 July 2017 |
| Platform | Quiet Systems |
| Series | DC-Y-2017 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

2017 is a C-UAS efficacy year, not a CVE year: Bishop Fox field-tested first-generation drone-defense products against a purpose-built pentest UAV and found them immature, while the only other in-scope record is a R00tz youth-village introduction with no vendor flaw attached.

### Key judgments

1. **[Assessment — High confidence]** First-generation commercial C-UAS (nets, trained birds, RF denial, directed energy) did not reliably stop a custom pentest airframe in the Bishop Fox tests presented at Black Hat USA Arsenal and DEF CON 25.
2. **[Assessment — High confidence]** No CVE, advisory, or Exploit-DB record is attached to either in-scope 2017 talk. The conference record is a product-class failure, not a patched software ID.
3. **[Inference — Moderate confidence]** A Passport that records “C-UAS on site” without a Lab result against a non-commodity airframe will overstate Act (stop) capability.

## 01. First-generation C-UAS products fail a pentest UAV

*Event / publication dates: Black Hat USA Arsenal Theater demo 26–27 July 2017; DEF CON 25 main stage 29 July 2017, 16:00 PT (45 min). Same research; one signal.*

| Field | Value |
| --- | --- |
| Venue | DEF CON / Black Hat USA |
| Component | hardware |
| Product | first-generation commercial C-UAS products, field-tested against Bishop Fox DangerDrone |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Francis Brown and David Latimer (Bishop Fox) presented “Game of Drones: Putting the Emerging ‘Drone Defense’ Market to the Test” as a Black Hat USA 2017 Arsenal Theater demo and as a DEF CON 25 main-stage briefing. Official pages: blackhat.com/us-17/arsenal.html; defcon.org DC25 speakers. After-record: media.defcon.org slides (UPDATED PDF) and video; YouTube jwNrcuYAhj8; Bishop Fox resource page; InfoconDB. Failure class on the record: nets, birds, RF denial, and directed-energy C-UAS products were field-tested against a custom pentest UAV and shown immature or ineffective. DangerDrone v2.0 was announced as a public pentest-quadcopter release; no talk-tied GitHub URL was located. No CVE, advisory, or Exploit-DB ID was found.

**Exposure.** Act (C-UAS stop) and Move (the airframe continues). A defended volume that assumed those products would deny flight remains open to a non-commodity UAV.

**Intelligence assessment.** [Assessment — High confidence] The two venues are one research program, not two findings. [Assessment — High confidence] The object is C-UAS product immaturity, not a named autopilot CVE. [Uncertainty] Which exact commercial SKUs failed is a slide-level detail; this filing does not invent a vendor list. [Inference — Moderate confidence] Commodity C-UAS tuned to consumer command links will keep missing purpose-built airframes.

**Opportunity.** Lab C-UAS claims against a non-Wi-Fi, non-DJI command path. Passport “C-UAS present” only with a named product class and a dated test against the airframe under Campaign. Watch for vendor responses or later advisories; none exist in this window.

**LRRK relevance.** Watch and Lab. Control Fabric on the pentest UAV vs the C-UAS sensor/effector chain. Sense-Move-Act: Sense (detect the airframe) failed to produce Act (stop). Kestrel across first-generation nets / RF-denial / directed-energy SKUs rather than a single brand.

**Confidence.** High on the talk pages, slides, and Bishop Fox after-record. Moderate as a general C-UAS-market case. Low on any unlisted SKU.

## 02. R00tz “Drone Wars” is a youth contest, not a vendor flaw

*Event / publication dates: July 2017, DEF CON 25 R00tz Asylum village program.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | hardware |
| Product | village UAV contest platforms (unnamed) |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | none public |

**Verified record — [Fact — A1]** Erin Owens, Sujeet Bambale, Justin Whitehead, Chris Kiggins, Abby, and Duncan presented “Drone Wars” at R00tz Asylum during DEF CON 25. After-record: media.defcon.org DC25 villages video. Official village tree: media.defcon.org DEF CON 25 villages. Failure class: youth-village introduction to UAV platforms and in-village drone contests. No vendor CVE or catalogued flaw is attached. No GitHub research repo and no Exploit-DB ID were found.

**Exposure.** Hardware familiarity and contest framing. No established Sense, Move, or Act failure on a named product.

**Intelligence assessment.** [Assessment — High confidence] This is the 2017 precursor village record for drone content at DEF CON, not a software-danger signal. [Uncertainty] Platform makes and contest scoring are not independently specified on the village page. [Inference — Low confidence] Treat as Watch context for later DroneWarz, not as a Control Fabric finding.

**Opportunity.** No patch to verify. Watch whether a titled, recorded technical talk appears in a later drone village. Do not Passport a youth contest as a product assessment.

**LRRK relevance.** Watch only. Lab and KAT do not attach. Campaign should not ingest this as a kinematic vulnerability.

**Confidence.** High that the village video exists. High that no CVE is attached. Low as a decision signal.

## Forward indicators

1. Vendor or C-UAS-industry response to the Bishop Fox field tests (none in this window).
2. A talk-tied DangerDrone repository or advisory ID — inventory has the announcement only.
3. Whether DEF CON 26 elevates drone content from R00tz/contest into a titled technical village talk.
4. Any CVE or Exploit-DB record that later cites this C-UAS evaluation (none found through the 2017 cutoff).

> **Collection integrity.** Public sources only. Inventory leftover for 2017: three talks, used as two signals (Game of Drones at DEF CON 25 and Black Hat USA Arsenal is one research program). Collection cutoff is DEF CON 25 Sunday, 30 July 2017. Searched: media.defcon.org DC25 presentations, video-and-slides, and villages; DC25 speakers; Black Hat USA 2017 briefings and Arsenal; Black Hat Europe 2017 briefings (NIL); Black Hat Asia 2017 briefings (NIL); IoT Village 2017 speaker PR (NIL); Wireless / Hardware Village 2017 (NIL kinematic titles). **Village note.** No brand named “Drone Village” in 2017–2021. The DEF CON drone village in this window is DroneWarz (full village DC26–DC27; R00tz youth precursor DC25). Aerospace Village has not started (begins DC28 Safe Mode, 2020). **Excluded (inventory, out of topic or out of window):** Aaron Luo DC24 and Nils Rodday Black Hat Asia 2016 (pre-window); Karit / David Robinson DC25 “Using GPS Spoofing to control time” (NTP / time, not vehicles); Black Hat USA 2017 “Hunting GPS Jammers” (jammer-hunting survey; drones only as an example); Black Hat USA 2017 “Sonic Gun to Smart Devices” (MEMS acoustic injection; DJI Phantom 3 is one of many consumer targets, not a UAS briefing); DroneWarz cage / CTF activities without a titled recorded talk; paid trainings; HOPE / SAINTCON / Nuit du Hack / Codemotion. No invented talks. No CVE, Exploit-DB ID, or GitHub URL invented. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>