
DEF CON 33 - From Pwn to Plan: Turning Physical Exploits Into Upgrades - Shawn
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 55:45
Physical red teaming should focus on helping organizations implement security improvements rather than just identifying vulnerabilities 1:57-2:17.
Key Takeaways:
• Red teams fill security gaps between physical, cyber, and other security teams 3:56-4:41
• New threats like AI lip reading make basic surveillance dangerous with just a $30 lens 4:54-5:41
• Effective red teaming requires immediate debriefing to help security teams understand vulnerabilities 13:44-14:30
• Common TTPs include underdoor tools, canned air attacks, and ESP keys 21:53-23:19
Making security teams look good while implementing fixes leads to better security and more testing opportunities 2:35-2:54.
Sources:
- 1:57-2:17 Two approaches to red teaming
- 3:56-4:41 Red teams filling security gaps
- 4:54-5:41 AI lip reading threat vector
- 13:44-14:30 Immediate debrief importance
- 21:53-23:19 Common physical TTPs
- 2:35-2:54 Benefits of proactive approach
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, welcome everyone. Thanks for spending lunch here. Um, all right, I will jump right in. Uh, quick show of hands before I do. Who has touched an underdoor tool before? Maybe 50%. That's awesome. Uh, what about lockpicks? Better. Um, what about who's actually gone in the field and done some type of physical pen test assessment? Awesome. All right, this is very helpful. So, I want to start with a key question before I jump in. Uh, raise your hand, and there's no right answer. This is not a trick question. Raise your hand if you think red teams should recommend fixes when they're done. Awesome. Raise your hand if you are brave enough to say that they shouldn't recommend fixes. They should just turn out vulnerabilities. That's a very valid like some that works at some companies. There…