DEF CON 34 Recap: Key Talks, Badges, and Takeaways from Vegas 2026
Published: Aug 24, 2026
I made it back from Las Vegas with a pile of notes, way too many stickers, three new badges around my neck, and a list of research rabbit holes long enough to keep me busy until next August. This year's floor leaned hard into AI-assisted red teaming, autonomous attack chains, and some of the most practical social engineering research I've seen at a con.
Here's the rundown from DEF CON 34.
DEF CON 34 Workshops: Malware Development and Windows Instrumentation
I scheduled two 4-hour workshops going in, on Friday and Saturday mornings.
The first was Yoann "OtterHacker" Dequeker's "Malware Development 101, From Zero to Hero, Adapt Your Payload to Your Environment." OtterHacker is a red team operator at Wavestone, and this is his third year running some version of this course at DEF CON. The workshop built a basic process injection payload in C/C++, then layers on evasion one technique at a time: module stomping, DLL injection, threadless injection, and hardware breakpoints for dehooking. Afterwards, we were free to try the same with our EDR of choice to understand what works best for each.
I showed up with a MacBook running a Windows ARM VM. It typically has great battery life, but then I remembered the ARM problems I had while working through MalDevAcedemy. VirtualAllocEx and CreateRemoteThread work fine on Windows ARM, but the course shellcode was compiled for x64, and high-level Win32 calls for ARM, and x64 process injection paths diverge in ways that aren't cosmetic.
I ended up leaning on an LLM to walk through the assembly code with me to get the intended technique running on the hardware I had. It got me through the workshop. It also left a gap I don't like leaving open, so I've got a deep dive planned to go through each technique OtterHacker covered and understand why it broke between architectures instead of just patching around it.
The second workshop was also Dequeker's, "Explore the Windows Instrumentation Callback," and I missed it live. He did share the material ahead of time, so it's become an evening project instead of a conference session. The subject is Nirvana Debugging, an instrumentation callback mechanism that's existed since Windows 7 and can be weaponized to hook syscalls without registering a traditional exception handler. In essence, patchless hooking slips past a lot of usual detection logic. It’s worth doing the slow, at home version of this one.
Malware Village
Malware Village had a piece of hardware on the table that I keep thinking about: a bare metal malware detonation box called Malysis, built on something called SRODisk. It booted a Windows OS, then the presenter removed the NVME SSD, then ran a speed test, 50gbps read/write filesystem all running inRAM. There was no hypervisor, so no VM artifacts for the sample to fingerprint, no sandbox awareness tricks to fight through: just native execution speed on real silicon. A soft reboot keeps your session intact as the RAM stays powered, while a full power cycle wipes it clean. This was a very cool demo. While at the Malware Village, if you ask for free malware, you will get it. I grabbed a sample off their table for their CTF challenge to tinker throughout the conference in between talks.

Maritime Hacking Village
This one’s new territory for me. Maritime Hacking Village brought actual boats and marine electronics to poke at, and the security underneath most of it is worse than I expected. A lot of onboard systems run over an unencrypted CAN bus, so you can sit there with Wireshark, sniff normal operational traffic, and write a script to replay it later. No encryption, no authentication: just raw bus traffic sitting there waiting to be recorded and reused.
Then came the shipping containers. Getting to learn about the tracking and yard placement systems was something I’ve never thought about before. The presenter at the village led me through a CTF challenge involving a crane behind a black curtain, which is something I didn’t get the chance to dig into more. There was a lot of learning left on the table for this session.
Biohacking Village
There was a lighter touch in the biohacking village, composed of more tinkering than deep research. There were patient monitors pulled out of clinical use for kiosk breakout testing, a laparoscopic surgery demo, and even a "SOC in a box" concept built for small and medium sized medical offices that don't have the budget for an enterprise solution. Nothing that kept me up that night, but it's a decent look at how thin the security margin gets once you're outside a large hospital system.
DEF CON 34 Talks Worth Your Time
Patrick Wardle gave the macOS version of DLL sideloading, "Dylib Hijacking on macOS, Dead or Alive," revisiting research he first did over a decade ago against everything Apple has layered on since, up through macOS 26. The most interesting tactic I brought back was malicious dylibs with our in-house C2, built to slot into an app bundle without breaking the code signature. Code signing is exactly the kind of control a client assumes is doing more work than it is, so this one's going in the back pocket for the next macOS engagement.
Dr. Megan Squire gave a talk on "What Scammers Know That Social Engineers Don't, Three Techniques for Tough Cases." Squire studies AI safety, scams, and fraud as a Principal Threat Intel Researcher at F-Secure, and before that spent years on online recruitment and extremist network research. She's coming at social engineering from the criminal side, not the assessment side, which changes the talk.
Most SE training leans on urgency, fear, flattery, and the stuff that stops working once a target's already primed to expect it. Dr. Squire’s three techniques were built for exactly that scenario: targets who've been trained against the obvious plays. “Awareness Hijacking” uses the target's knowledge of one scam to walk them straight into a different one. Another technique, “Complexity-as-Crucible" engineers a situation complicated enough that the operator gets to become the target's trusted guide through it: the "just trust me, I know how this works" move.
Lastly, “First Win” lets the target think they've beaten the scam, so they relax right as they've locked themselves into it. All three are aimed at red team engagements where the target is already on high alert, which is most engagements worth running at this point. After the demo she pointed the room to the FBI's own elicitation techniques reference, which is a good primer on the classic version of this before you get into the tougher cases she was covering. This is another outstanding talk for a team who regularly performs voice-based social engineering engagements.
Google's Daniel Fabian talked through scaling adversary emulation with autonomous agents, and it lined up with a theme running through most of the AI Village and Adversary Village programming this year: industrialized spear phishing, automated chains handling triage and lateral movement, and supply chain compromise getting cheaper (an agent can find and chain overprivileged ACLs faster than any operator I've worked with). An interesting demonstration of the blue team needs the same volume and speed to train filters, which hand tuned tabletop scenarios can't produce.
Adversary Village also ran "The Agents of Chaos, AI Driven Malware Generation," a hands-on workshop on using local agents for personal security work. Good complement to Fabian's talk, less about attacking with agents, and more about what a local model can do for you defensively without sending your data anywhere.
Hallway Track: The Moments That Don't Make the Schedule
A kid from DC NextGen came up to admire my Gothcon badge, featuring a little bat shaped circuit board that he was amazed by.
I ended up giving it to him because of course, it’s DEF CON, he’ll love it more than I will having it hang on my office door. He showed it off to everyone in earshot, gave me a hug, and ran off. The Gothcon organizer heard the story and insisted on handing me a replacement before I left. Easily the most wholesome Defcon experience I’ve had.

The best conversation of the week happened after hours at the Social Engineering Village, where I ran into someone who turned out to be a current Schellman client. We talked off the record about their experience with our team, found a couple of real gaps, and had a plan in place to close them before we split up. Not bad for a chance encounter in a dark conference break out room.
And that was a wrap on DEF CON 34. Now I've got an ARM process injection deep dive to write, a Nirvana Debugging session to run at home, and C2 ideas that need to be implemented ASAP.
About Philip Holbrook
Philip Holbrook is a Lead Penetration Tester with Schellman & Company, LLC based in Pittsburgh, PA, where he leads red team engagements and performs external and internal penetration tests, advanced phishing campaigns, and web application testing. Philip is actively expanding Schellman's red team practice through researching novel initial access vectors, developing custom internal tooling, and supporting the team's penetration testing infrastructure. Philip brings in-depth knowledge of enumerating macOS and Windows environments for vulnerabilities and privilege escalation opportunities, with specialized expertise in SIEM and EDR evasion techniques. In his leadership role, he mentors junior penetration testers, contributes to methodology development, and drives innovation in adversary simulation techniques. Philip has over 10 years of experience in IT and security, serving clients across various industries with a primary focus on Cloud, SaaS, and Service Provider environments. He has presented at the Pittsburgh BSides Conference on advanced phishing techniques utilizing calendar injection, user scripting, and dockerized phishing infrastructure to bypass MFA restrictions. Philip recently obtained his Certified Red Team Lead certification to complement his expertise in red team operations. Prior to joining Schellman in 2020, Philip worked as a Security Engineer handling SOC integration projects and Incident Response in MSP environments supporting small to medium businesses. He performed malware and root cause analysis to identify attack kill chains and provide accurate remediation steps. He obtained his OSCP in 2018 and leverages his defensive security background to emulate realistic adversary tactics, techniques, and procedures (TTPs) in red team.