# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 10 August 2014 |
| Platform | Quiet Systems |
| Series | DC-Y-2014 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

2014 is still UAV-as-sensor: SensePost’s Snoopy airborne device-tracking at Black Hat Asia and DEF CON 22, plus a Wireless Village 3-D RF site survey. No in-scope talk discloses a victim-vehicle command-link failure.

### Key judgments

1. **[Assessment — High confidence]** Three verified talks — Wilkinson at Black Hat Asia, Wilkinson at DEF CON 22, Pack / Rowe at the Wireless Village — are the year’s kinematic record. Black Hat USA 2014 has no dedicated kinematic briefing (paid “Radio Exploitation” training is not inventoried).
2. **[Assessment — High confidence]** Snoopy-ng is a named collector framework (GitHub record only, not a vuln PoC). No CVE, advisory, or Exploit-DB ID attaches to any of the three talks.
3. **[Inference — Moderate confidence]** Black Hat Europe 2014 is later on the calendar but NIL for kinematic-system talks. Shamir’s Scangate keynote used a DJI Phantom 2 Vision only as a camera on a printer side-channel and stays out. Cutoff remains DEF CON Sunday.

## 01. Wilkinson: Snoopy airborne device-tracking with GCS and flight-controller methodology

*Event / publication dates: presented 8 August 2014 (Friday 16:00 PT), DEF CON 22, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | software |
| Product | SensePost Snoopy / snoopy-ng on a UAV; GCS / flight-controller / UAV payload methodology |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Glenn Wilkinson (SensePost) presented “Practical Aerial Hacking & Surveillance” at DEF CON 22. The DC22 archive, media.defcon.org slides (original and updated), the DEF CON white paper, media.defcon.org video, and InfoconDB are the primary record. The inventory names https://github.com/sensepost/snoopy-ng. Failure class is the same Snoopy collector class as the Asia briefing, with explicit GCS / flight-controller / UAV payload methodology. No CVE or Exploit-DB ID was found.

**Exposure.** Sense: beyond-line-of-sight wireless fingerprinting from the air. Move is the UAV and GCS as delivery and control of the collector, not a disclosed hijack of a third-party airframe.

**Intelligence assessment.** [Assessment — High confidence] This is the most complete A1 record of airborne Snoopy in 2014 because it names GCS and flight-controller methodology. [Assessment — High confidence] Exploit status is public writeup of a collector framework, not a catalogued airframe vuln. [Inference — Moderate confidence] A GCS that can fly a fingerprinting payload is a Control Fabric object for the truck, not evidence the victim devices’ own kinematics were taken.

**Opportunity.** Passport Snoopy-ng as a named collector payload, not as a UAV CVE. Lab whether a given GCS/FC pair is being used as a sensor truck. Kestrel against 2011 WASP and 2016 Danger Drone.

**LRRK relevance.** Watch, Lab, Campaign “UAV-as-collector.” Control Fabric on the GCS–airframe path that carries the payload. Sense-Move-Act: Move delivers Sense.

**Confidence.** High on the talk, slides, video, and named repo. Moderate as a product case — airframe SKU is not pinned.

## 02. Wilkinson: UAV-mounted Snoopy for beyond-line-of-sight device tracking

*Event / publication dates: presented during Black Hat Asia 2014 (week of 24 March 2014, Singapore); contemporaneous BBC piece dated 28 March 2014.*

| Field | Value |
| --- | --- |
| Venue | Black Hat Asia |
| Component | software |
| Product | SensePost Snoopy / snoopy-ng; DIY drone used as a distributed wireless-fingerprint collector |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Glenn Wilkinson (SensePost) presented “The Machines That Betrayed Their Masters” at Black Hat Asia 2014. The briefing page, Black Hat slides, and Asia 2014 archives are the official record. BBC (28 March 2014) and Ars Technica covered Snoopy as a DIY drone that tracks devices. InfoconDB cross-checks the title. Later DEF CON 22 slides name https://github.com/sensepost/snoopy-ng as the airborne payload. No CVE or Exploit-DB ID was found.

**Exposure.** Sense: distributed wireless-fingerprint collection beyond line of sight. The UAV is the collector. Physical consequence is device tracking from the air, not unauthorized maneuver of the tracked party’s vehicle.

**Intelligence assessment.** [Assessment — High confidence] First 2014 venue appearance of airborne Snoopy, corroborated by A1 slides and B1 outlets. [Assessment — High confidence] This is not a UAV command-link disclosure. [Uncertainty] Airframe vendor/SKU is not a CVE object in this record.

**Opportunity.** Watch the Asia briefing as the start of the 2014 collector pair. Passport device-identity leakage as a Sense problem adjacent to kinematic delivery. Do not file Shamir / Scangate here.

**LRRK relevance.** Watch and Campaign with signal 01. Sense-Move-Act on a UAV used to Sense other people’s devices. Kestrel Asia vs Las Vegas records of the same framework.

**Confidence.** High on the briefing, slides, and named-outlet after-record. Moderate on airframe identity.

## 03. Pack / Rowe: open-source quadcopter as a 3-D RF site-survey sensor

*Event / publication dates: DEF CON 22 Wireless Village program, August 2014, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | village |
| Component | hardware |
| Product | Open-source quadcopter used as a 3-D RF site-survey sensor (coverage / rogue-AP location) |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | none public |

**Verified record — [Fact — A1]** Scott Pack and Dale Rowe presented “UAV-Assisted Three-Dimensional Wireless Assessments” in the DEF CON 22 WiFi Hacking Village. media.defcon.org holds the village video. An Irongeek village mirror exists as a secondary copy. No CVE, Exploit-DB ID, or GitHub research repo was found. Failure class: an open-source quadcopter used as a 3-D RF site-survey sensor, not a command-link takeover.

**Exposure.** Sense: coverage and rogue-AP location in three dimensions. Move is the quadcopter as a measurement perch. No Act-against-another-airframe disclosure.

**Intelligence assessment.** [Assessment — High confidence] Village A1 video establishes the talk. [Assessment — High confidence] Exploit status is none public — this is a survey method, not a vuln writeup. [Inference — Moderate confidence] RF site survey from a quadcopter is the same collector pattern as Snoopy, aimed at infrastructure mapping rather than device tracking.

**Opportunity.** Lab UAV-assisted survey as a Watch class for plant and airfield RF maps. Passport “open quadcopter as sensor” separately from victim-vehicle hijack. Kestrel against Melrose 2016 (UAV toward industrial wireless).

**LRRK relevance.** Watch, Lab, Sense-Move-Act. Campaign with other collector-UAV talks. KAT is airframe → RF sensor, not airframe → unauthorized command.

**Confidence.** High on the village video. Moderate on product pin — “open-source quadcopter” only.

## Forward indicators

1. A venue talk that hijacks Move on a named airframe (command link, GNSS, or host services).
2. A CVE or advisory on Snoopy, a GCS, or a consumer UAV Wi-Fi / datalink.
3. Whether Black Hat USA ever carries the Snoopy briefing (2014 USA is NIL for a dedicated kinematic talk).
4. Black Hat Europe kinematic talks after this cutoff — Shamir / Scangate remains out of scope.

> **Collection integrity.** Searched media.defcon.org DEF CON 22 presentations, video-and-slides, and wifi-village talks; defcon.org DC22 archive; Black Hat Asia 2014 briefings and archives; Black Hat USA 2014 briefings; Black Hat Europe 2014 briefings; InfoconDB; BBC, Ars Technica, Irongeek village mirror. Three counted talks. Black Hat USA 2014 “Radio Exploitation” training mentioned a drone exercise in the syllabus; it is paid training, not a public talk, and is not inventoried. Adi Shamir’s 16 October 2014 Black Hat Europe keynote (Scangate) used a DJI Phantom 2 Vision only as a camera for a printer side-channel and stayed out. SkyJack, Humphreys, HOPE 2012, Nullcon, ADS-B / ATC, and car CAN talks stayed out. No invented talks. No exploit steps. CVE / Exploit-DB: none found. snoopy-ng repo copied from the inventory.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
