ScapyCon Automotive 2026
The third annual ScapyCon 2026 will introduce a more integrated format with talks and presentations in the morning and interactive sessions in the afternoon, focusing on hands-on exchange, demos, and discussion — and a more collaborative approach to cybersecurity.
15.09.2026 – 16.09.2026
Techbase, Regensburg
Interested in becoming part of ScapyCon?
ABOUT
ScapyCon 2026 continues to evolve with a more integrated format, combining morning talks and presentations with interactive afternoon sessions focused on demos, workshops, and roundtables. Taking place on September 15–16 at TechBase Regensburg, the event emphasizes hands-on exchange and closer collaboration within the cybersecurity community. Speakers include Reinhard Kugler (SBA Research) and Dr. Friedrich Wiemer (Bosch), contributing expertise from both research and industry. The evening event at Degginger Regensburg on September 15 offers a dedicated setting to connect with peers and continue discussions beyond the sessions.
Speakers

Dr. Enrico Pozzobon
Enrico has worked as an automotive penetration tester since 2016. Together with Dr. Nils Weiss, he built the automotive security research lab at the OTH Regensburg and later founded dissecto. He has worked with several automotive manufacturers and insurance companies to find vulnerabilities and build exploit demonstrations.
Autopsy of Modern Connected Cars
Based on a study directed by the FIA, this talk presents the technical challenges encountered while performing independent audits on three modern electric vehicles to uncover the reality behind their data-handling practices.
Enrico will discuss the methodologies and hardware/software toolchains required for network interception, including Man-in-the-Middle (MITM) setups for Automotive Ethernet and USB links, as well as techniques for intercepting telemetry and mapping hidden endpoints in TLS- and mTLS-protected environments.
The talk further explores storage forensics, ranging from in-situ eMMC extraction to invasive desoldering and reballing procedures for UFS memories, alongside artifact recovery from encrypted NVMe storage and gateway-managed SD logs.
Finally, we cover practical reverse engineering approaches for infotainment systems, including Android Automotive applications and native QNX/Linux binaries, to trace how vehicle and sensor data is processed and transmitted to cloud backends.

Dr. Nils Weiss
Dr. Weiss delved into penetration testing during his Bachelor’s and Master’s, exploring vulnerabilities in embedded systems and entire vehicles. Active in developing open-source penetration test frameworks like Scapy, he co-founded dissecto GmbH in 2022, focusing on simplifying security diagnostics and solutions for embedded systems.
Conference Opening
Dissecto founder and Senior Manager Dr. Nils Weiß will host ScapyCon Automotive 2026 and guides participants through the conference day, setting the stage for discussions on Scapy’s evolution, community growth, and its expanding role in cybersecurity development.

Reinhard Kugler
Reinhard’s focus relies on security testing of IT and industrial cyber-physical systems. Based on his prior experience in cyber defense, he works with companies to develop security capabilities and secure products. Reinhard is an experienced instructor and develops tailored security trainings. His mission is to apply research methods (combinatorial security testing) to industrial applications, like automotive, embedded or cloud.
From Garage Testing to CI Pipelines: Towards automated Security Testing of Automotive Containers
Linux and containers are increasingly used in modern automotive ECUs, including infotainment systems and HPCs, yet security testing and prototyping remain challenging as organizations adapt to CI/CD practices. Moving from ad-hoc testing to automated Dynamic Application Security Testing (DAST) introduces hurdles such as supporting automotive protocols (e.g., CAN) in CI environments, integrating testing tools with the system under test, and automating repeatable, cost-effective test cases.
This talk presents approaches to integrating automotive applications into automated build systems and explores practical testing methods, including smart fuzzing, Scapy-based automation, and combinatorial testing.

Ben Gardiner
Ben is a Senior Cybersecurity Research Engineer contractor at the National Motor Freight Traffic Association, Inc. (NMFTA)™. He specializes in hardware and low-level software security, with over ten years of professional experience in embedded systems design and a master’s degree in Applied Math and Stats from Queen’s University. He has presented his research at numerous global events, including DEF CON, Hack in Paris, and the Cybertruck Challenge.
Truck Hacking Workshop
This four-hour TCAT training course introduces you to the TCAT platform and its role in vehicle cybersecurity workflows. Through a fast-paced combination of instruction and integrated hands-on labs, participants complete practical exercises in UDS and J1939 diagnostics, controller application enumeration, and vehicle data-flow analysis using simulators.

Dr. Friedrich Wiemer
Friedrich Wiemer is a security researcher at Robert Bosch GmbH working on in-vehicle network security. He (co-)drives the CANsec and CAN FD Adaptation Layer specifications in the CiA working groups and contributes to the Automotive MACsec and MKA profiles of Open Alliance TC17.
Foundational Security from Ethernet to CAN: Prototyping CANsec and FDAL with Scapy
MACsec is the established link-layer security for automotive Ethernet, while CAN and CAN FD — still carrying most safety-critical traffic — lack an equivalent. We address this gap by reusing MACsec for CANsec, the Layer 2 security protocol for CAN XL (CiA 613-2), and extending it to CAN FD via the CAN FD Adaptation Layer (FDAL), bringing a consistent trust foundation to existing nodes.
Scapy supported this work end-to-end: integrating CAN XL from the Linux kernel, implementing CANsec and FDAL, generating test vectors for vendors, and enabling a proof-of-concept Ethernet application over secured CAN FD.

Antonio Vasquez Blanco
Industrial Engineer turned Security Researcher, now part of the Innovation Department at Tarlogic. Passionate about electronics, reverse engineering (especially bare-metal), radio frequency, and everything low-level. Author and contributor to projects like BlueSpy, BSAM, UsbBluetooth and Ghidra Findcrypt, Ghidra SVD, Ghidra DTB…
Unlocking Hidden Bluetooth Capabilities with Scapy
Bluetooth security research lacks support for advanced capabilities comparable to monitor mode in WiFi adapters. Beyond the standardized interfaces of Bluetooth controllers lies a layer of vendor-specific functionality where powerful features exist but are typically inaccessible through conventional tooling.
Starting from real-world Bluetooth security research and existing tooling gaps, this talk explores direct controller interaction over USB, the discovery of vendor specific HCI commands, and how reverse engineering efforts can be turned into practical tooling by extending Scapy.
Along the way, we unlock capabilities such as MAC spoofing and low level protocol access, features that are normally hidden from the operating system and standard Bluetooth stacks.

Willem Melching
Willem Melching is an independent security researcher with over 7 years of experience, specializing in automotive security and reverse engineering. He contributed to openpilot at comma.ai, develops tools like the SecOC Key Extractor, and shares research via his blog “I CAN Hack.” He also offers car hacking training and holds a degree from TU Delft.
Tool-Assisted Reverse Engineering Workshop
How can you leverage AI tooling to speed up reverse engineering of automotive firmware binaries? Suited for both beginner and advanced Ghidra users.
The workshop will start with a short introduction by the instructor, but will be mostly hands-on. You can pick any of the following subjects:
- Using emulation to assist in reverse engineering
- Using Ghidra MCP to fully automate reverse engineering
- Writing Ghidra plugins for tasks such as automatically recognizing AUTOSAR functions
- Writing loaders for custom formats, easily load automotive update files

Dr. Natasha Alkhatib
Natasha is an AI and automotive cybersecurity expert specializing in connected and autonomous vehicle security. She holds a PhD from the Polytechnic Institute of Paris, where her research focused on AI-based intrusion detection for automotive networks. As Cybersecurity and Software Update Project Manager at Renault, she leads the deployment of Cybersecurity Management Systems in compliance with UNR155. Dr. Alkhatib is a published researcher and frequent speaker on AI-driven automotive cybersecurity and cyber resilience.
Beyond Blind Fuzzing: AI for Automotive Cybersecurity Testing
In this talk, Dr. Natasha Alkhatib will demonstrate how artificial intelligence can transform automotive security testing. Using a local AI model, the system learns how a vehicle’s electronics respond, identifies high-risk areas, and focuses testing on the most security-critical functions instead of probing blindly. This intelligent approach uncovers exploitable vulnerabilities significantly faster than traditional methods.
Drawing on real evaluation results across targets with different security postures, Dr. Alkhatib will discuss the potential of AI-driven security testing and what it means for the future of automotive cyber resilience and the growing role of AI in protecting connected vehicles.

Charan Krishnamurthy
Charan is a cybersecurity engineer specializing in automotive and embedded systems, with experience in threat modelling, secure software development, and security architecture for connected and autonomous platforms. He focuses on translating cybersecurity and Cyber Resilience Act (CRA) requirements into practical engineering solutions that enable secure, compliant, and scalable products.
EU Cyber Resilience Act: Myths, Expectations and Practical Implementation
The EU Cyber Resilience Act (CRA) is one of the most significant new cybersecurity regulations for digital products, yet many organizations still struggle to understand what it really means in practice. This session separates fact from fiction by addressing common myths around CRA compliance, discussing what conformity assessment and future Notified Bodies are expected to focus on, and sharing practical lessons learned from early implementation activities. Attendees will gain a clear understanding of how organizations can approach CRA readiness pragmatically, avoid common pitfalls, and build on existing cybersecurity practices rather than starting from scratch.

Janine Funke
Janine is an advisor, trainer, and lead assessor helping organizations navigate complex security and regulatory challenges. She actively contributes to shaping the industry through her involvement in standards and regulatory initiatives and regularly speaks at international cybersecurity conferences. Janine is also a founding member of CRAIG (Cyber Resilience Act Implementation Group), a non-profit community supporting organizations in the practical implementation of the EU Cyber Resilience Act.
EU Cyber Resilience Act: Myths, Expectations and Practical Implementation
The EU Cyber Resilience Act (CRA) is one of the most significant new cybersecurity regulations for digital products, yet many organizations still struggle to understand what it really means in practice. This session separates fact from fiction by addressing common myths around CRA compliance, discussing what conformity assessment and future Notified Bodies are expected to focus on, and sharing practical lessons learned from early implementation activities. Attendees will gain a clear understanding of how organizations can approach CRA readiness pragmatically, avoid common pitfalls, and build on existing cybersecurity practices rather than starting from scratch.

Damien Cauquil
Damien is a security engineer at Quarkslab, France. He loves electronics, embedded devices, wireless protocols and to hack all of these not especially in that order. He authored several Bluetooth Low Energy tools like Btlejuice and Btlejack, discovered a way to hack into an existing Bluetooth Low Energy connection and other tools on a lot of different topics that tickle his mind but not always related to security or wireless protocols.
Talk) WHAD: We have a demo!
WHAD is a unified Python framework for wireless security research, supporting Bluetooth Low Energy, ZigBee, LoRaWAN, and more. Built around Scapy, it provides customizable protocol stacks and hardware-independent tooling for developing proof-of-concepts, testing tools, and wireless attacks. This talk introduces the framework and demonstrates how it can manipulate wireless traffic, build custom tools, and emulate legitimate devices.
Workshop) Hacking ZigBee and ANT Devices with WHAD
This hands-on workshop introduces WHAD through its command-line tools and Python API. Participants will sniff traffic, inject packets, and develop custom tools while interacting with ZigBee and proprietary wireless devices, including ANT and Enhanced ShockBurst, gaining practical experience in wireless security testing.

Romain Cayre
Romain is an Assistant Professor at INSA Toulouse and LAAS-CNRS, France, specializing in wireless, IoT, and embedded systems security. His research focuses on hacking embedded wireless stacks and developing offensive and defensive techniques for protocols such as Bluetooth Low Energy and IEEE 802.15.4. He has led projects including WazaBee, InjectaBLE, and OASIS, and is the main developer of Mirage, a widely used offensive framework for wireless communication protocols, as well as its successor, WHAD.
Talk) WHAD: We have a demo!
WHAD is a unified Python framework for wireless security research, supporting Bluetooth Low Energy, ZigBee, LoRaWAN, and more. Built around Scapy, it provides customizable protocol stacks and hardware-independent tooling for developing proof-of-concepts, testing tools, and wireless attacks. This talk introduces the framework and demonstrates how it can manipulate wireless traffic, build custom tools, and emulate legitimate devices.
Workshop) Hacking ZigBee and ANT Devices with WHAD
This hands-on workshop introduces WHAD through its command-line tools and Python API. Participants will sniff traffic, inject packets, and develop custom tools while interacting with ZigBee and proprietary wireless devices, including ANT and Enhanced ShockBurst, gaining practical experience in wireless security testing.

Dieter Schuster
Dieter Schuster has worked in embedded security at Fraunhofer AISEC for more than 15 years, specializing in automotive security and vehicle penetration testing over the last decade. As part of the Fraunhofer AISEC Automotive Security Lab, he delivers hands-on training that combines realistic workshop environments with current attack techniques and practical exercises.
V2X Wardriving – They Drive, We Listen
Vehicle-to-Everything (V2X) communication has quietly become a reality. Many modern vehicles now support Cooperative Intelligent Transport Systems (C-ITS), enabling Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication. But how widespread is this technology? What infrastructure is already deployed? Which messages are exchanged, and what are the associated privacy and security implications?
In this talk, we provide an overview of the European C-ITS ecosystem, explain the underlying standards, and demonstrate how off-the-shelf hardware can be used to research V2X protocols. We present the tooling we developed to analyze real-world deployments, share our findings on current implementations and communication patterns, and discuss potential attack surfaces, privacy concerns, and open research questions. Attendees will gain practical insights into the current state of V2X security and the opportunities for further exploration.

Nikolai Puch
Nikolai Puch is a research associate and penetration tester at Fraunhofer AISEC, as well as a PhD candidate at the Technical University of Munich, focusing on secure and usable solutions for tooling machines. As a penetration tester, he specializes in the various wireless interfaces of vehicles.
V2X Wardriving – They Drive, We Listen
Vehicle-to-Everything (V2X) communication has quietly become a reality. Many modern vehicles now support Cooperative Intelligent Transport Systems (C-ITS), enabling Vehicle-to-Vehicle (V2V) and Vehicle-to-Infrastructure (V2I) communication. But how widespread is this technology? What infrastructure is already deployed? Which messages are exchanged, and what are the associated privacy and security implications?
In this talk, we provide an overview of the European C-ITS ecosystem, explain the underlying standards, and demonstrate how off-the-shelf hardware can be used to research V2X protocols. We present the tooling we developed to analyze real-world deployments, share our findings on current implementations and communication patterns, and discuss potential attack surfaces, privacy concerns, and open research questions. Attendees will gain practical insights into the current state of V2X security and the opportunities for further exploration.

Jonas Horreis
Jonas is a senior penetration tester at dissecto with a focus on automotive security. He started by automating ECU security tests for his bachelor’s thesis, expanded into securing EV-charging infrastructure and electric-vehicle architectures during his master’s research, and later investigated advanced fuzzing techniques as a university research assistant. Now he applies this knowledge to secure the ECUs of the future.
AI-Assisted Penetration Testing of Embedded Systems
Discover how AI can enhance penetration testing of embedded systems in this hands-on workshop. Participants will combine established security tools such as Scapy, Wireshark, tcpdump, and nmap with AI-assisted workflows for reconnaissance, protocol analysis, vulnerability assessment, and automated test orchestration. The AI dynamically adapts test workflows, recommends follow-up tests based on previous results, assists with troubleshooting, and supports report generation and severity ranking. Through practical exercises on Ethernet, CAN, diagnostics, and serial interfaces, participants will learn how to build efficient, repeatable, and adaptive security assessments for modern embedded systems.

Enno Rey
Enno Rey has been working in information security since the late 1990s, in both offense and defense, and in a variety of roles: as a researcher, as the founder of a security company celebrating its 25th anniversary this year, and as the initiator of TROOPERS, an international gathering of security folks.
Scapy Keynote
In this keynote, Enno will reflect on RFC keywords, IPv6 extension headers, and other interesting life topics





















