DEF CON 33 - What Game Hackers teach us about Offensive Security & Red Teaming - Joe 'Juno' Aurelio

DEF CON 33 - What Game Hackers teach us about Offensive Security & Red Teaming - Joe 'Juno' Aurelio

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 30:07

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Based on the transcript and the feedback that the original summary "failed," here's a revised summary that more accurately captures the core message, key technical details, and nuances of the talk:

Summary: Game hacking offers critical insights into offensive security and red teaming by demonstrating profound technical parallels with malware development. This connection reveals shared techniques in stealth, process injection, evasion, and the fundamental cat-and-mouse dynamic between attackers and defenders. While distinct from unethical cheating, game hacking provides a legitimate framework for understanding modern adversarial tactics. 1:50

Key Takeaways:
Game Hacking ≠ Just Cheating: It encompasses modding, speedrunning, reverse engineering (e.g., game preservation), and cheating. The focus here is on the technical methods used, not the ethics of online cheating. 2:00-3:30
Two Core Cheat Types:

  • Internal Cheats: Code injected directly into the game process (e.g., DLL injection), modifying memory in real-time (like a "mod"). Requires stealthy loading mechanisms to evade detection. 3:30-4:45
  • External Cheats: Operate via separate processes (e.g., Cheat Engine) or hardware devices interacting indirectly with the game, leaving the game process "clean." 4:45-5:30
    Direct Malware Parallels: Both cheaters and malware developers rely on identical Windows API abuse (e.g., OpenProcess, ReadProcessMemory, WriteProcessMemory) for process injection, memory manipulation, and stealth. Techniques like process migration (hiding code within a legitimate process) are a hallmark of both. 5:30-7:00, [8:00-9:00](https://www.youtube.com/watch?v

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, thank you all for coming. This is what game hacking teaches us about offensive security and red teaming. We'll be talking about game hacking. Uh this for the game hacking village for Defcon 33. So first of all, a disclaimer. I don't condone cheating in games. Uh especially not online or competitive games. I think uh cheating is really unfair, but I think what uh game hacking teaches you is really interesting. and it's really technically deep and it has a lot of parallels especially with malware. Um, and that's a little bit about what we what we will be talking about today. Um, and yeah, cheaters cheaters are are usually bad at the game. It's a skill issue. Get good. Uh, so a little bit about myself. Um, my day job, I'm a security researcher. I primarily look at mobile applicatio…