






About Our Event
Following the success of previous editions, ScapyCon returns in 2026 with a refined and more integrated format. Bringing together a growing community of cybersecurity professionals, researchers, and engineers, the event continues to focus on practical knowledge sharing and real-world applications of network packet manipulation.
Taking place on September 15–16 at TechBase Regensburg, ScapyCon 2026 combines morning talks and presentations with interactive afternoon sessions, including workshops, demos, and discussions. This structure creates more space for hands-on exchange, collaboration, and deeper technical exploration across domains such as automotive, IoT, aerospace and beyond.
Participants can expect insights into current challenges and developments in cybersecurity, along with hands-on engagement with tools and techniques. The evening event at Degginger Regensburg on September 15 offers a dedicated setting to connect with peers and continue discussions beyond the sessions.
Join ScapyCon 2026 to exchange ideas, explore new approaches, and be part of an evolving, practice-driven cybersecurity ecosystem.
Stay in the loop and never miss a beat! Follow us on LinkedIn for registration details and all the latest updates about the upcoming event.
When:
15.09.26 – 16.09.26, 09:00 AM – 05:00 PM
Where:
Techbase Regensburg, Franz-Mayer-Str. 1, Regensburg
Keynote Speakers:
Dr. Enrico Pozzobon, Reinhard Kugler, Dr. Friedrich Wiemer, Ben Gardiner, Willem Melching and more!
Speakers

Dr. Enrico Pozzobon – Senior Manager @ dissecto
Enrico has worked as an automotive penetration tester since 2016. Together with Dr. Nils Weiss, he built the automotive security research lab at the OTH Regensburg and later founded dissecto. He has worked with several automotive manufacturers and insurance companies to find vulnerabilities and build exploit demonstrations. His special field of expertise is side-channel attacks and voltage glitching.

Dr. Nils Weiss – Scapy Maintainer / Senior Manager @ dissecto
Nils delved into penetration testing during his Bachelor’s and Master’s, exploring vulnerabilities in embedded systems and entire vehicles. Active in developing open-source penetration test frameworks like Scapy, he co-founded dissecto GmbH in 2022, focusing on simplifying security diagnostics and solutions for embedded systems.

Reinhard Kugler – Security Consultant @ SBA Research
Reinhard’s focus relies on security testing of IT and industrial cyber-physical systems. Based on his prior experience in cyber defense, he works with companies to develop security capabilities and secure products. Reinhard is an experienced instructor and develops tailored security trainings. His mission is to apply research methods (combinatorial security testing) to industrial applications, like automotive, embedded or cloud.

Dr. Friedrich Wiemer – Security Researcher @ Robert Bosch
Friedrich Wiemer is a security researcher at Robert Bosch GmbH working on in-vehicle network security. He (co-)drives the CANsec and CAN FD Adaptation Layer specifications in the CiA working groups and contributes to the Automotive MACsec and MKA profiles of Open Alliance TC17.

Ben Gardiner – Sen. Cybersecurity Research Engineer @ NMFTA
Ben is a Senior Cybersecurity Research Engineer contractor at the National Motor Freight Traffic Association, Inc. (NMFTA)™. He specializes in hardware and low-level software security, with over ten years of professional experience in embedded systems design and a master’s degree in Applied Math and Stats from Queen’s University. He has presented his research at numerous global events, including DEF CON, Hack in Paris, and the Cybertruck Challenge.

Antonio Vasquez Blanco – Cybersecurity Researcher @ Tarlogic
Industrial Engineer turned Security Researcher, now part of the Innovation Department at Tarlogic. Passionate about electronics, reverse engineering (especially bare-metal), radio frequency, and everything low-level. Author and contributor to projects like BlueSpy, BSAM, UsbBluetooth and Ghidra Findcrypt, Ghidra SVD, Ghidra DTB…

Willem Melching – Independent Cybersecurity Researcher
Willem Melching is an independent security researcher with over 7 years of experience, specializing in automotive security and reverse engineering. He contributed to openpilot at comma.ai, develops tools like the SecOC Key Extractor, and shares research via his blog “I CAN Hack.” He also offers car hacking training and holds a degree from TU Delft.

Janine Funke – Lead Consultant @ UL
Janine is an advisor, trainer, and lead assessor helping organizations navigate complex security and regulatory challenges. She actively contributes to shaping the industry through her involvement in standards and regulatory initiatives and regularly speaks at international cybersecurity conferences. Janine is also a founding member of CRAIG (Cyber Resilience Act Implementation Group), a non-profit community supporting organizations in the practical implementation of the EU Cyber Resilience Act.

Charan Krishnamurthy – Software Engineer @ UL
Charan is a cybersecurity engineer specializing in automotive and embedded systems, with experience in threat modelling, secure software development, and security architecture for connected and autonomous platforms. He focuses on translating cybersecurity and Cyber Resilience Act (CRA) requirements into practical engineering solutions that enable secure, compliant, and scalable products.

Dr. Natasha Alkhatib – Governance Project Manager @ Renault
Natasha is an AI and automotive cybersecurity expert specializing in connected and autonomous vehicle security. She holds a PhD from the Polytechnic Institute of Paris, where her research focused on AI-based intrusion detection for automotive networks. As Cybersecurity and Software Update Project Manager at Renault, she leads the deployment of Cybersecurity Management Systems in compliance with UNR155. Dr. Alkhatib is a published researcher and frequent speaker on AI-driven automotive cybersecurity and cyber resilience.

Damien Cauquil – Security Engineer @ Quarkslab
Damien is a security engineer at Quarkslab, France. He loves electronics, embedded devices, wireless protocols and to hack all of these not especially in that order. He authored several Bluetooth Low Energy tools like Btlejuice and Btlejack, discovered a way to hack into an existing Bluetooth Low Energy connection and other tools on a lot of different topics that tickle his mind but not always related to security or wireless protocols.

Romain Cayre – Assistant Professor @ INSA Toulouse
Romain is an Assistant Professor at INSA Toulouse and LAAS-CNRS, France, specializing in wireless, IoT, and embedded systems security. His research focuses on hacking embedded wireless stacks and developing offensive and defensive techniques for protocols such as Bluetooth Low Energy and IEEE 802.15.4. He has led projects including WazaBee, InjectaBLE, and OASIS, and is the main developer of Mirage, a widely used offensive framework for wireless communication protocols, as well as its successor, WHAD.

Dieter Schuster – Senior Engineer Pentesting @ Fraunhofer AISEC
Dieter Schuster has worked in embedded security at Fraunhofer AISEC for more than 15 years, specializing in automotive security and vehicle penetration testing over the last decade. As part of the Fraunhofer AISEC Automotive Security Lab, he delivers hands-on training that combines realistic workshop environments with current attack techniques and practical exercises.

Nikolai Puch – Research Associate @ Fraunhofer AISEC
Nikolai Puch is a research associate and penetration tester at Fraunhofer AISEC, as well as a PhD candidate at the Technical University of Munich, focusing on secure and usable solutions for tooling machines. As a penetration tester, he specializes in the various wireless interfaces of vehicles.

Jonas Horreis – Sen. Penetration Tester @ dissecto
Jonas Horreis is a senior penetration tester at dissecto with a focus on automotive security. He started by automating ECU security tests for his bachelor’s thesis, expanded into securing EV-charging infrastructure and electric-vehicle architectures during his master’s research, and later investigated advanced fuzzing techniques as a university research assistant. Now he applies this knowledge to secure the ECUs of the future.

Enno Rey – Founder @ ERNW, TROOPERS
Enno Rey has been working in information security since the late 1990s, in both offense and defense, and in a variety of roles: as a researcher, as the founder of a security company celebrating its 25th anniversary this year, and as the initiator of TROOPERS, an international gathering of security folks. Enno will present the Scapy keynote.
Keynotes &Talks
1. From Garage Testing to CI Pipelines: Towards automated Security Testing of Automotive Containers – Reinhard Kugler
Linux and containers are now a common deployment technique in modern automotive ECUs, including Infotainment systems and HPCs. The security testing and prototyping still remain a challenge and companies still are adapting to modern software development and building practices like CI/CD. The main goal to moving from ad-hoc testing approaches to fully automated Dynamic Application Security Testing (DAST) is accompanied by several challenges:
- Support for automotive environments such as CAN in IT build environments (CI)
- Integration of testing tools with the system under test (SUT)
- Automation of test cases to provide repeatable and cost effective testing
This talk outlines the integration of automotive applications into automated build systems for automotive software and explores practical testing approaches such as smart fuzzing, automation with Scapy and combinatorial testing.
2. Foundational Security from Ethernet to CAN: Prototyping CANsec and FDAL with Scapy – Dr. Friedrich Wiemer
MACsec has become the foundational link-layer security for automotive Ethernet. CAN and CAN FD, which still carry most safety-critical in-vehicle traffic, have no comparable foundation. We close this gap by extending MACsec downward: reuse MACsec for CANsec — the Layer 2 security protocol for CAN XL under specification in CiA 613-2. To make CANsec available on CAN FD as well, we additionally developed the CAN FD Adaptation Layer (FDAL). It extends the same Layer 2 trust foundation to the billions of CAN FD nodes already deployed today.
Scapy accompanied this work end-to-end. Building on the existing CAN XL functionality in the Linux kernel, we integrated it in Scapy, and implemented CANsec and FDAL as additional layers, developed alongside our specification work to validate real-world functionality. The same code base produced CANsec test vectors shared with silicon and stack vendors, and powered a proof-of-concept Ethernet application over CANsec protected CAN FD.
3. Autopsy of Modern Connected Cars – Dr. Enrico Pozzobon
While automotive security has moved forward, the forensic reality of these systems remains a “black box.” Based on a FIA study, this talk presents the technical challenges found in performing independent audits on three modern electric vehicles to extract the ground truth behind their data-handling practices.
We will detail the specific methodologies and hardware/software toolkit required to achieve:
- Network Interception: Building Man-in-the-Middle (MITM) setups for Automotive Ethernet and USB links. We will discuss intercepting telemetry and mapping hidden endpoints in environments protected by TLS and mTLS.
- Storage Forensics: A deep dive into extraction strategies, ranging from “in-situ” eMMC dumping to the invasive desoldering and reballing required for UFS memories. We also cover the recovery of forensic artifacts from encrypted NVMe storage and gateway-managed SD logs.
- Software Reversing: Practical analysis of the infotainment stack, including decompiling Android Automotive (GAS) applications and reverse engineering native QNX and Linux binaries to trace how sensor data is repackaged for the cloud.
4. Unlocking Hidden Bluetooth Capabilities with Scapy – Antonio Vasquez Blanco
Bluetooth security research lacks support for advanced capabilities comparable to monitor mode in WiFi adapters. Beyond the standardized interfaces of Bluetooth controllers lies a layer of vendor-specific functionality where powerful features exist but are typically inaccessible through conventional tooling.
Starting from real-world Bluetooth security research and existing tooling gaps, this talk explores direct controller interaction over USB, the discovery of vendor specific HCI commands, and how reverse engineering efforts can be turned into practical tooling by extending Scapy. Along the way, we unlock capabilities such as MAC spoofing and low level protocol access, features that are normally hidden from the operating system and standard Bluetooth stacks.
5. EU Cyber Resilience Act: Myths, Expectations and Practical Implementation – Janine Funke and Charan Krishnawurthy
The EU Cyber Resilience Act (CRA) is one of the most significant new cybersecurity regulations for digital products, yet many organizations still struggle to understand what it really means in practice. This session separates fact from fiction by addressing common myths around CRA compliance, discussing what conformity assessment and future Notified Bodies are expected to focus on, and sharing practical lessons learned from early implementation activities. Attendees will gain a clear understanding of how organizations can approach CRA readiness pragmatically, avoid common pitfalls, and build on existing cybersecurity practices rather than starting from scratch.
6. Beyond Blind Fuzzing: AI for Automotive Cybersecurity Testing – Dr. Natasha Alkhatib
Modern vehicles rely on dozens of networked electronic control units, creating an expanding attack surface for cyber threats. Yet identifying vulnerabilities before attackers exploit them remains slow and resource-intensive, as conventional fuzzing and penetration testing waste valuable effort on invalid inputs without understanding how vehicle systems actually behave.
In this talk, Dr. Natasha Alkhatib will demonstrate how artificial intelligence can transform automotive security testing. Using a local AI model, the system learns how a vehicle’s electronics respond, identifies high-risk areas, and focuses testing on the most security-critical functions instead of probing blindly. This intelligent approach uncovers exploitable vulnerabilities significantly faster than traditional methods.
Drawing on real evaluation results across targets with different security postures, Dr. Alkhatib will discuss the potential of AI-driven security testing and what it means for the future of automotive cyber resilience and the growing role of AI in protecting connected vehicles.
7. WHAD: We have a demo! – Damien Cauquil and Romain Cayre
Wireless protocols like Bluetooth Low Energy, ZigBee or LoRaWAN seem pretty complex and you may think you need a lot of different hardware and libraries to play with those. WHAD solves this by providing a unified Python library that supports multiple wireless protocols, heavily using Scapy for packet abstraction and providing its own customizable/hackable protocol stacks. WHAD makes development of proof-of-concepts, tools and wireless attacks simple, also making them compatible with any supported hardware interface.
In this talk, we will explain how this framework works and show how it can be used to create powerful tools, manipulate wireless packets on-the-fly by combining some of the framework’s basic tools or spawn fake devices that mimic legitimate ones.
8. V2X Wardriving – They Drive, We Listen – Dieter Schuster and Nikolai Puch
Vehicle-to-Everything (V2X) communication has quietly become a reality. Many modern vehicles now support Cooperative Intelligent Transport Systems (C-ITS), enabling Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication. But how widespread is this technology? What infrastructure is already deployed? Which messages are exchanged, and what are the associated privacy and security implications?
In this talk, we provide an overview of the European C-ITS ecosystem, explain the underlying standards, and demonstrate how off-the-shelf hardware can be used to research V2X protocols. We present the tooling we developed to analyze real-world deployments, share our findings on current implementations and communication patterns, and discuss potential attack surfaces, privacy concerns, and open research questions. Attendees will gain practical insights into the current state of V2X security and the opportunities for further exploration.
Interactive Sessions
1. Truck Hacking Workshop – Ben Gardiner
This four-hour TCAT training course introduces you to the TCAT platform and its role in vehicle cybersecurity workflows. Through a fast-paced combination of instruction and integrated hands-on labs, participants complete practical exercises in UDS and J1939 diagnostics, controller application enumeration, and vehicle data-flow analysis using simulators.
Requirements: Windows or Linux PC, no admin/root required, but must support Standard USB serial driver allowed (ACM) and standard USB ethernet driver allowed (CDC). Must have a terminal emulator (e.g. putty, teraterm, screen, or picocom) and an ssh client installed. PC must have a modern web browser.
2. Tool Assisted Reverse Engineering – Willem Melching
This four hour workshop introduces the participants to “Tool Assisted Reverse Engineering”. How can you leverage AI tooling to speed up reverse engineering of automotive firmware binaries? Suited for both beginner and advanced Ghidra users. The workshop will start with a short introduction by the instructor, but will be be mostly hands-on. You can pick any of the following subjects you’d like to experience.
- Using Ghidra MCP to fully automate reverse engineering
- Writing Ghidra plugins for tasks such as automatically recognizing AUTOSAR functions
- Writing loaders for custom formats, easily load automotive update files
- Using emulation to assist in reverse engineering
Requirements: Laptop with Ghidra installed, preferably in a VM. Bring your own Claude/Codex subscription or API token. You’re also welcome to bring your own firmware files to analyze.
3. Hacking ZigBee and ANT devices with WHAD – Damien Cauquil, Romain Cayre
This workshop will give attendees a good understanding of WHAD through the use of command-line tools and its Python API. Attendees will practice sniffing, packet injection and tool development with this framework to take control of various devices, such as a ZigBee lightbulb or IoT devices using proprietary protocols like ANT or Enhanced ShockBurst.
Requirements: A Linux computer is required for this workshop, although a virtual machine will be available for download (VMWare/VirtualBox) and some hands-on exercises will be also available in our new emulated lab environment.
4. AI-Assisted Penetration Testing of Embedded Systems – Jonas Horreis
Discover how AI can enhance penetration testing of embedded systems in this hands-on workshop. Participants will combine established security tools such as Scapy, Wireshark, tcpdump, and nmap with AI-assisted workflows for reconnaissance, protocol analysis, vulnerability assessment, and automated test orchestration.
The AI dynamically adapts test workflows, recommends follow-up tests based on previous results, assists with troubleshooting, and supports report generation and severity ranking. Through practical exercises on Ethernet, CAN, diagnostics, and serial interfaces, participants will learn how to build efficient, repeatable, and adaptive security assessments for modern embedded systems.
About Scapy
Scapy, a Python program, revolutionizes network packet manipulation by offering extensive capabilities including packet sending, sniffing, dissecting, and forging. This multifaceted tool empowers users to construct bespoke solutions for network probing, scanning, and security testing. Unlike conventional networking tools, Scapy boasts an interactive interface enabling users to craft, decode, and interpret packets with unparalleled flexibility. Its domain-specific language simplifies packet description and manipulation, epitomized by its ability to describe packets in just a few lines of code. Scapy’s unique approach diverges from traditional tools by providing raw, uninterpreted data, facilitating nuanced analysis and eliminating biases inherent in interpreted results.
