Dark Wolf Hack Our Drone Workshop - Ronald Broberg & Rudy Mendoza - DCTLV2026
Name of Training: Dark Wolf Hack Our Drone Workshop
Trainer(s): Ronald Broberg and Rudy Mendoza
Dates: August 10-11, 2026
Time: 8:30 am to 5:30 pm
Venue: Las Vegas Convention Center
Cost: $2,250 (USD)
Short Summary:
The Dark Wolf Hack Our Drone Workshop provides students with hands-on cyber testing of Unmanned Aerial Vehicle (UAV), Ground Control Station (GCS), Android controller, and Radio Frequency (RF) Communications. Students will learn the tools, techniques, and procedures used in cybersecurity testing of Unmanned Autonomous Systems (UAS).
Course Description:
The recent expansion of Uncrewed Autonomous Systems (UAS) across various sectors presents significant security challenges, as rapid adoption often outpaces critical cybersecurity security engineering, leaving many of these systems vulnerable. The Dark Wolf Hacking Our Drone Workshop provides participants a comprehensive, hands-on understanding of drone security vulnerabilities and the techniques to assess and mitigate them. This intensive two-day program offers a deep dive into drone hacking, equipping cyber professionals with the practical skills and theoretical knowledge necessary to evaluate and secure autonomous systems.
The curriculum spans the UAS architecture and includes an Unmanned Aerial Vehicle (UAV), a Ground Control Station (GCS) system, RF communication protocols, payloads, and log analysis. Through a combination of expert-led instruction and extensive practical lab exercises, participants will gain proficiency in identifying, exploiting, and reporting vulnerabilities across these diverse components. The workshop concludes with a focus on risk assessment, mitigation strategies, and industry best practices for securing drone operations, ensuring attendees leave equipped to proactively identify and secure autonomous systems against evolving cyber threats.
Course Outline:
-
UAV - Drone
-
UAS Cybersecurity (presentation)
- Attack Surface (activity)
-
UAV Hardware, Software, Cybersecurity (presentation)
- UAV Firmware Analysis (lab)
-
UAV Flight Controllers (presentation)
- QGround Control and Mission Planning (lab)
-
UAS Cybersecurity (presentation)
-
Ground Control
-
Introduction to Android Cybersecurity (presentation)
- Android GCS Application Analysis (lab)
-
GCS Hardware, Software, Cybersecurity (presentation)
- GCS Exploitation (lab)
-
Introduction to Android Cybersecurity (presentation)
-
Radio Frequency Communications
-
UAS RF Communications - Telemetry, Video, GPS, ADS-B (presentation)
- Cracking Wireless Communications (lab)
-
DroneID (presentation)
- RemoteID (lab)
-
SiK Telemetry Radios (presentation)
- SiK Radio Hacks (lab)
-
MAVLink Telemetry for Command and Control
- MAVLink Sniffing and Spoofing (lab)
-
UAS RF Communications - Telemetry, Video, GPS, ADS-B (presentation)
-
Payloads and Logging
-
UAV Cameras - Digital and Analog (presentation)
- Analog Video Transmission Sniffing (lab)
-
UAS Logging (presentation)
- Adversarial Forensics on UAS Logs (lab)
- UAS Cybersecurity Review (presentation)
-
UAV Cameras - Digital and Analog (presentation)
Difficulty Level:
Beginner - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.
Students should be comfortable with the Linux command line.
While the skills and techniques are not particularly advanced, few individuals are comfortable taking cybersecurity and pentesting skills and applying them to drones. That is why our course emphasizes hands-on labs and encourages our students to physically access UAS devices and payloads.
A foundational understanding of drones, network security, or embedded systems will enhance a student's engagement with the course content. To facilitate learning for all attendees, thorough lab manuals will be supplied, effectively addressing any prerequisite knowledge differentials.
Suggested Prerequisites:
Students should be comfortable with the Linux command line. Lab documents will be provided to help guide students through the command line exercises.
What Students Should Bring:
Students should bring a laptop with the following installed:
- Docker
- VirtualBox
What the Trainer Will Provide:
The Dark Wolf Drone Hacking Workshop will provide:
-
A UAS Lab Kit to include:
-
UAV with flight computer and firmware
-
UAV Payload
-
GCS hand controller with firmware
-
Android phone with GCS Application
-
HackRF One Software Defined Radio (SDR)
-
USB Wifi Dongle
-
USB Bluetooth Dongle
-
Toolkit
-
Cable Kit
-
Preconfigured Virtual Machine images for installation on student computer
This UAV kit uses benchtop power and does not provide or require lithium batteries.
Trainer(s) Bio:
Ronald Broberg is a cybersecurity principal at Dark Wolf where he tests Drones, Phones, and Radios. Previously, he worked as a cybersecurity engineer with Lockheed Martin in the Space and C2 domains.
Rudy Mendoza is a cybersecurity principal at Dark Wolf where he performs penetration testing against various networks and targets including UAS. He is the primary author of the Dark Wolf Drone Security Testing Playbook and is co-authoring a book on UAS cybersecurity testing.
Proficiency Exam Option:
This course has the option for a proficiency certificate add-on. To earn the proficiency certificate, students will complete testing against a completely virtualized drone, using the TTPs demonstrated in this course.
Please reach out to training@defcon.org for any questions related to the proficiency exam and certificate option.
Registration Terms and Conditions:
Trainings are refundable before July 11, 2026, minus a non-refundable processing fee of $250.
Between July 11, 2026 and August 5, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of $250.
All trainings are non-refundable after August 5, 2026.
Training tickets may be transferred to another student. Please email us at training@defcon.org for specifics.
If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).
Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.
DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.
By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.
Several breaks will be included throughout the day. Please note that food is not included.
All courses come with a certificate of completion, contingent upon attendance at all course sessions. Some courses offer an option to upgrade to a certificate of proficiency, which requires an additional purchase and sufficient performance on an end-of-course evaluation.
Training Justification Request – DEF CON Training
To: [Manager Name]
From: [Employee Name]
Date: [Date]
Subject: Business Justification for Attendance at DEF CON Training
Dear [manager’s name],
I am requesting approval to attend DEF CON Training, one of the cybersecurity industry's most recognized technical training programs. I’ve reviewed the options and selected a course to expand my skills with [1-2 key skills focus areas for the course].
DEF CON has been one of the world’s leading cybersecurity communities for more than three decades, known for convening industry, government, and independent experts to exchange advanced knowledge and practical skills. Building on this tradition, DEF CON Training delivers intensive courses taught by recognized global instructors. DEF CON Training courses offer hands-on instruction in a challenging, fast-paced environment. Many of the courses offered by DEF CON Training align with the National Institute of Standards and Technology (NIST) NICE Framework and Department of Defense Cyber Workforce Framework (DCWF), and attending this course will help me build and sharpen the skills required for my role.
Training: [Name of DEF CON Training Course]
Instructor/Provider: [Trainer Name(s)]
Dates: [Training Dates]
Location: Las Vegas, NV
Cost: [Course Fee]
Travel Expenses: [estimated travel & accommodations costs]
Course Description: [Copy short description of the selected class from the website here]
Trainer Bio: [Copy bio of the trainers of the selected class from the website here]
Once I’ve completed the course, I’ll be able to:
[copy student outcomes from course page where available or choose 3-4 skills or topic areas from the outline that are applicable to your current role, will help you fill a skill gap, etc.]
Business Need
As cyber threats continue to evolve, it is critical that our organization maintains current knowledge of emerging techniques and industry best practices. The selected DEF CON training aligns directly with my responsibilities in [your role/field here - for example, security operations, incident response, threat detection and hunting, application security, cloud security, risk management, security engineering].
The course will provide practical, hands-on experience that can be immediately applied to our environment and security initiatives. DEF CON training emphasizes real-world attack and defense scenarios, enabling participants to develop skills that extend beyond traditional classroom learning.
Request for Approval
I respectfully request approval and funding to attend DEF CON Training this August in Las Vegas. The knowledge, hands-on experience, and industry insights gained will directly support our cybersecurity objectives and contribute to strengthening our organization's security capabilities.
Thank you for your consideration. Please let me know if you have questions or need additional information to support this request.
Sincerely,
[Employee name]