# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 30 July 2017 |
| Platform | Quiet Systems |
| Series | DC-S-04 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

Bishop Fox’s *Game of Drones* — Black Hat USA 2017 Arsenal plus DEF CON 25 main stage — is one research program: first-generation C-UAS products (nets, birds, RF denial, directed energy) were field-tested against a custom pentest UAV and shown to be immature or ineffective.

### Key judgments

1. **[Assessment — High confidence]** Inventory 2017-01 (DEF CON 25, 29 July 2017) and 2017-02 (Black Hat USA 2017 Arsenal Theater, 26–27 July 2017) are the same Francis Brown / David Latimer research, not two disclosures.
2. **[Assessment — High confidence]** The failure class is C-UAS product effectiveness against a pentest airframe (DangerDrone), not a vendor CVE on a flight stack. No CVE, Exploit-DB ID, or talk-tied GitHub URL was found.
3. **[Inference — Moderate confidence]** A Passport that records “C-UAS present” without a field result against a non-cooperative airframe over-claims Act on the defended site.

## 01. First-generation C-UAS products fail a field test against a pentest UAV

*Event / publication dates: Black Hat USA 2017 Arsenal Theater demo, 26–27 July 2017; DEF CON 25 main stage, 29 July 2017 (16:00 PT, 45 min). Collection cutoff is DEF CON 25 Sunday, 30 July 2017.*

| Field | Value |
| --- | --- |
| Venue | DEF CON; Black Hat USA |
| Component | hardware |
| Product | first-generation C-UAS (nets, birds, RF denial, directed energy) vs Bishop Fox DangerDrone |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Speakers Francis Brown and David Latimer (Bishop Fox). DEF CON 25 title *Game of Drones: Putting the Emerging "Drone Defense" Market to the Test*; official speaker page https://www.defcon.org/html/defcon-25/dc-25-speakers.html; media.defcon.org updated slides (`DEF CON 25 - Brown-and-Latimer-Game-of-Drones-Drone-Defense-Market-UPDATED.pdf`) and video (`DEF CON 25 - Francis Brown, David Latimer - Game of Drones - Putting the Emerging Drone Defense Market to the Test.mp4`); YouTube after-record `jwNrcuYAhj8`; speaker-firm page https://bishopfox.com/resources/def-con-25-2017-game-of-drones. Black Hat USA 2017 Arsenal title *Game of Drones: Putting the Emerging 'Drone Defense' Market to the Test - Arsenal Theater Demo*; official Arsenal listing https://www.blackhat.com/us-17/arsenal.html. InfoconDB is a cross-check only. **[Fact — A1]** CVE / advisory: none found. Exploit-DB ID: none found. GitHub research repo: none found (DangerDrone v2.0 announced as a public pentest-quadcopter release; no talk-tied GitHub URL located). Exploit-status on both venue records: public writeup.

**Exposure.** Adjacent C-UAS: the defended site’s Act against an incoming UAV. The test article (DangerDrone) is itself a kinematic platform; the finding is that nets, birds, RF denial, and directed energy then on the market did not reliably stop it. Sense on the C-UAS side is implied by missed or ineffective engagements, not by a new UAV CVE.

**Intelligence assessment.** **[Assessment — High confidence]** Main stage plus Arsenal is one research program; double-counting would invent a second talk. **[Assessment — High confidence]** Physical consequence is an airframe that still arrives — the C-UAS layer fails to deny Move into the defended volume. **[Uncertainty]** Individual product SKUs are not Passport-named in the inventory; “first-generation C-UAS” stays a class. **[Inference — Moderate confidence]** Later evasion talks (Interceptor 2018, spread-spectrum disposable drones 2023) assume this market-immaturity baseline.

**Opportunity.** Passport a C-UAS claim only with a field result against a non-cooperative, non-DJI-default airframe. Campaign “C-UAS installed” as unevidenced Act. Lab effectiveness as a product question, not as a flight-stack CVE. Watch for vendor responses this 2017 record did not produce as advisories.

**LRRK relevance.** Adjacent C-UAS on the kinematic trust path. Watch and Campaign for over-claimed defenses. Lab / Kestrel across C-UAS classes (kinetic net, animal, RF denial, directed energy). DangerDrone is a test article, not the Campaign target.

**Confidence.** High on the two official venue records, media.defcon.org after-record, and the single-research merge. Moderate on unnamed product SKUs. Nil on CVE, EDB, and a talk-tied repo.

## Forward indicators

1. A C-UAS vendor advisory or third-party retest answers the 2017 field-test class with named products and dates.
2. A later BH/DC talk treats C-UAS effectiveness as a Passport item rather than a market demo.
3. A talk-tied DangerDrone v2.0 repo or catalog ID appears and can be cited as a named record only.

> **Collection integrity.** Built from leftover inventory 2017-01 and 2017-02 only (same research: DEF CON 25 main + Black Hat USA Arsenal). Official sources: defcon.org DC25 speakers; media.defcon.org DC25 presentations and video-and-slides; blackhat.com US-17 Arsenal; Bishop Fox after-record page. InfoconDB cross-check only. Black Hat USA 2017 dedicated kinematic briefings remain NIL (jammer-hunting survey excluded). Black Hat Europe / Asia 2017 remain NIL. R00tz *Drone Wars* (2017-03) is a separate youth-village item and is not merged here. Slides and video treated as metadata; pentest-UAV build steps, SD images, and engagement procedures excluded. No invented talks. CVE / EDB / GitHub / exploit-status copied from the inventory: none found / none found / none found / public writeup.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
