Cultivating M4D SK1LLZ In the DEF CON Community
Yan Shoshitaishvili, Perri Adams
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
This talk, "Cultivating M4D SK1LLZ In the DEF CON Community," introduces Defcon Academy, a new initiative aimed at providing structured, accessible cybersecurity education to the broader DEF CON community. Presented by Perri Adams and Yan Shoshitaishvili, the session highlights the critical need for practical skill development in the cybersecurity landscape and positions Defcon Academy as a community-driven solution. The speakers, both seasoned veterans of the Capture The Flag (CTF) competitive hacking scene, draw upon their extensive experience to articulate the value of hands-on learning and mentorship in mastering complex security concepts.

Key moments
- 0:00 Introduction and Defcon Academy challenge announcement
- 0:50 Perri Adams' background: CTF player, RPIsec
- 2:00 Perri on Defcon CTF, DARPA AICC, and mentorship
- 3:59 Yan Shoshitaishvili (Zardus) begins his introduction
Cultivating M4D SK1LLZ In the DEF CON Community
Speakers: Yan Shoshitaishvili; Perri Adams
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=KnCp5K51IEA
Overview
This talk, "Cultivating M4D SK1LLZ In the DEF CON Community," introduces Defcon Academy, a new initiative aimed at providing structured, accessible cybersecurity education to the broader DEF CON community. Presented by Perri Adams and Yan Shoshitaishvili, the session highlights the critical need for practical skill development in the cybersecurity landscape and positions Defcon Academy as a community-driven solution. The speakers, both seasoned veterans of the Capture The Flag (CTF) competitive hacking scene, draw upon their extensive experience to articulate the value of hands-on learning and mentorship in mastering complex security concepts.
The core premise of Defcon Academy is to democratize the kind of deep, practical knowledge often gained through intense CTF participation or dedicated mentorship, making it available to a wider audience. This initiative aims to bridge the gap between theoretical understanding and the "mad skills" required to tackle real-world security challenges. By fostering an environment of continuous learning and practical application, Defcon Academy seeks to empower individuals at all skill levels to enhance their capabilities and contribute more effectively to the security community.
The talk emphasizes that the initiative is more than just a platform; it's a philosophy rooted in the DEF CON ethos of collaborative learning and pushing boundaries. It underscores the importance of a supportive community, where individuals can learn from each other, overcome technical hurdles, and collectively elevate the state of cybersecurity expertise. This talk serves as a call to action for the community to engage with and benefit from this new educational resource.
Background
▶ Watch: Introduction and Defcon Academy challenge announcement (0:00)
The cybersecurity industry faces a persistent and growing skill gap, where the demand for qualified professionals far outstrips the supply. Traditional academic routes often struggle to keep pace with the rapidly evolving threat landscape, leading to a deficit in practical, hands-on skills necessary for effective defense and offense. This problem is exacerbated by the complexity of modern systems and the specialized knowledge required to analyze and secure them.
Capture The Flag (CTF) competitions have long served as an informal, yet highly effective, training ground for aspiring and experienced cybersecurity professionals. CTFs offer a dynamic environment where participants can apply theoretical knowledge to solve real-world-inspired security puzzles, ranging from reverse engineering binaries and exploit development to web exploitation, cryptography, and forensics. The competitive nature, coupled with the immediate feedback of successful exploits, provides a powerful learning incentive.
Perri Adams, a key speaker, exemplifies this journey. She began her cybersecurity career as a CTF player with the RPIsec team, even competing in the prestigious Defcon Finals in 2018. Her formative experience included being challenged to learn objdump – a command-line utility for displaying information from object files – before being "allowed" to use more advanced tools like IDA Pro (a popular disassembler and debugger). This anecdote powerfully illustrates the value of foundational understanding and the mentorship often found within CTF teams. She later contributed to the CTF community by running the Defcon CTF itself, experiencing firsthand the challenges of designing educational yet robust security puzzles. Currently, at DARPA, she is involved in initiatives like AICC, which addresses complex software security challenges, further underscoring the real-world impact of the skills honed through CTFs.
The existence of Defcon Academy is a direct response to the recognized success of CTF-style learning and the desire to scale this effective methodology. It aims to formalize and expand access to this practical, challenge-based education, making it available beyond the confines of competitive teams to anyone in the DEF CON community seeking to cultivate "mad skills." The problem Defcon Academy addresses is not just the skill gap, but also the often-steep learning curve and lack of structured guidance that newcomers face when trying to enter the highly specialized world of offensive and defensive security. By providing curated challenges and a supportive platform, the Academy seeks to lower this barrier to entry and foster a new generation of skilled practitioners.
Key Findings
▶ Watch: Perri Adams' background: CTF player, RPIsec (0:50)
Given the nature of this talk as an announcement and introduction to a new initiative rather than a research presentation, the "key findings" are best understood as the foundational principles and observed needs that drove the creation of Defcon Academy. The primary "finding" is the proven efficacy of Capture The Flag (CTF) methodologies for developing practical cybersecurity skills. Speakers Perri Adams and Yan Shoshitaishvili, through their own extensive experience in CTFs and the wider security community, have identified several critical insights:
- Practical Skills are Paramount: The ability to apply theoretical knowledge to solve real-world security problems is more valuable than rote memorization. CTFs inherently demand this practical application, forcing players to understand system internals, exploit vulnerabilities, and analyze complex code.
- Mentorship and Community Accelerate Learning: Perri Adams explicitly states that having teammates, like those on RPIsec, was formative for her learning. The ability to "phone a friend" or get help when stuck on a challenging problem significantly accelerates skill acquisition. Defcon Academy aims to replicate this supportive, collaborative learning environment.
- Foundational Knowledge is Essential: The anecdote about learning objdump before IDA Pro highlights the importance of understanding underlying mechanisms before relying on high-level tools. This principle suggests that effective security education must build a strong foundation.
- Accessibility and Scalability of Hands-on Learning: While CTFs are excellent, they are often exclusive or intimidating for newcomers. Defcon Academy seeks to make this type of learning accessible to a broader audience, providing a structured path for skill development without the immediate pressure of a high-stakes competition.
- Addressing the Cybersecurity Skill Gap: The very existence of Defcon Academy is a response to the persistent skill shortage in the industry. The initiative "finds" that a community-driven, practical education platform can directly contribute to closing this gap by nurturing talent.
In essence, the "key findings" are the distilled lessons from years of competitive hacking and security research: that effective cybersecurity education is hands-on, community-driven, foundationally strong, and widely accessible. Defcon Academy is the embodiment of these findings, designed to cultivate these "mad skills" within the DEF CON community.
Technical Deep Dive
▶ Watch: Perri on Defcon CTF, DARPA AICC, and mentorship (2:00)
The provided transcript primarily focuses on the conceptual introduction and personal motivations behind Defcon Academy, rather than detailing specific technical findings or vulnerabilities. Therefore, a traditional "Technical Deep Dive" into a novel exploit, protocol analysis, or architectural flaw is not applicable to this talk.
However, based on the context provided by Perri Adams's background, we can infer the types of technical skills and challenges that Defcon Academy aims to cultivate. Her experience with CTFs (Capture The Flag) and specific tools like objdump and IDA Pro offers insight into the technical domains the Academy would likely cover.
CTF Challenges and Skill Domains:
CTFs typically encompass a wide array of technical disciplines, demanding deep understanding of various computing layers:
- Binary Exploitation (Pwn): This category involves analyzing compiled executables to find vulnerabilities like buffer overflows, format string bugs, and use-after-free errors. Participants learn to use tools like GDB (GNU Debugger), objdump (as mentioned by Perri for low-level binary inspection), and more advanced disassemblers and debuggers like IDA Pro or Ghidra (though Ghidra came later than Perri's initial experience). The goal is often to gain arbitrary code execution or read sensitive data. Skills include assembly language comprehension (e.g., x86, ARM), understanding memory layouts, and exploiting system calls.
- Reverse Engineering (Re): This involves taking a compiled program and understanding its functionality without access to the source code. This requires proficiency with disassemblers, decompilers, and debuggers to reconstruct algorithms, identify obfuscated logic, and bypass anti-tampering mechanisms.
- Web Exploitation: Focuses on vulnerabilities in web applications, such as SQL injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Server-Side Request Forgery (SSRF), directory traversal, and authentication bypasses. Tools like Burp Suite and browser developer tools are essential.
- Cryptography: Involves breaking or analyzing cryptographic schemes. This can range from identifying weak ciphers and key management flaws to exploiting mathematical vulnerabilities in common algorithms.
- Forensics: Deals with digital evidence collection and analysis, often involving disk images, network packet captures (PCAP files), memory dumps, and log files to reconstruct events or uncover hidden information.
- Miscellaneous/Trivial: Often includes challenges requiring general Linux command-line proficiency, scripting skills (e.g., Python), or creative problem-solving outside traditional categories. The initial "challenge race" mentioned for Defcon Academy, testing "Linux knowledge," falls into this foundational category.
Perri's emphasis on learning objdump before IDA Pro highlights a pedagogical approach that values understanding the raw output of a binary (assembly, section headers, symbol tables) before relying on the more user-friendly, abstracted views provided by advanced tools. This builds a deeper, more fundamental technical understanding crucial for complex security work. The mention of AICC (AI Cyber Challenge) by DARPA, which Perri helped create, further hints at the advanced and cutting-edge software security challenges that skilled individuals developed through Defcon Academy might eventually tackle, potentially involving automated vulnerability discovery and AI-driven defense.
While the talk does not provide specific technical details of Defcon Academy's platform or challenges, it strongly implies that the technical content will be rooted in these practical, hands-on CTF disciplines, designed to build a strong foundation from the ground up.
Demo / Proof of Concept
▶ Watch: Yan Shoshitaishvili (Zardus) begins his introduction (3:59)
The talk initiated a live, interactive demonstration directly tied to the Defcon Academy initiative: a challenge race accessible at ctf.defcon.academy. This served as an immediate and practical "proof of concept" for the type of hands-on learning the Academy aims to provide.
Upon the opening of the talk, attendees were encouraged to navigate to ctf.defcon.academy and engage with an initial set of challenges. The speakers explicitly stated that these challenges were "not extraordinarily hard stuff" and were designed to "test your Linux knowledge, how much Linux do you know?" This indicates a focus on foundational skills, making the entry point accessible to a broad audience, from beginners to those looking to refresh their basics.
The live challenge race served several purposes:
- Immediate Engagement: It allowed the audience to experience the Defcon Academy platform firsthand, rather than just hearing about it.
- Skill Assessment: By focusing on Linux fundamentals, it provided a self-assessment opportunity for participants.
- Gamification and Incentive: The "challenge race" aspect, with an "award ceremony" for the farthest ahead participants receiving "challenge coins," introduced a competitive and rewarding element, characteristic of CTFs.
- Platform Validation: It demonstrated that the Defcon Academy platform was operational and ready for community interaction.
While the specifics of the Linux challenges were not detailed in the transcript, the nature of such challenges typically involves tasks like:
- Navigating the file system (
cd,ls) - File manipulation (
cat,grep,find) - Understanding permissions (
chmod,chown) - Process management (
ps,kill) - Basic scripting
- Interpreting command output
This live demonstration was crucial in illustrating the practical, interactive, and community-oriented approach that Defcon Academy embodies. It immediately translated the abstract concept of "cultivating M4D SK1LLZ" into a tangible, executable experience for the audience.
Defensive Implications
While the talk focuses on skill development, the implications for cybersecurity defenders are profound and direct. Defcon Academy, by cultivating "M4D SK1LLZ," aims to directly enhance the capabilities of individuals who will eventually serve in defensive roles, or better equip those already defending systems. The defensive implications can be broken down into several key areas:
- Improved Threat Understanding: By engaging in CTF-style challenges, defenders gain firsthand experience in how systems are attacked and exploited. This attacker-centric perspective is invaluable for building robust defenses. Understanding the techniques, tactics, and procedures (TTPs) of adversaries from an offensive standpoint allows defenders to anticipate attacks, identify potential weaknesses proactively, and prioritize defensive measures more effectively. For example, understanding buffer overflows from an exploitation perspective enables a defender to better implement Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), or Canaries and to recognize indicators of compromise associated with such attacks.
- Enhanced Incident Response and Forensics: The skills honed in CTF categories like forensics directly translate to incident response. The ability to analyze system logs, network traffic (PCAPs), memory dumps, and file system artifacts is critical for identifying the scope of a breach, understanding the attack vector, and remediating effectively. Defcon Academy's practical challenges would provide hands-on training in these crucial areas.
- Better Secure Development Practices: Individuals who have participated in web exploitation or binary exploitation challenges are far more likely to write secure code themselves or to identify vulnerabilities in code reviews. Knowing common pitfalls like SQL injection or Cross-Site Scripting (XSS) from an attacker's perspective fosters a "security-first" mindset in development, leading to more resilient applications and systems.
- Proactive Security Testing (Red Teaming/Penetration Testing): While primarily offensive, red teaming and penetration testing are essential defensive strategies. Organizations need skilled individuals who can emulate real-world adversaries to test their defenses before attackers do. Defcon Academy provides a training ground for these roles, helping organizations identify and fix vulnerabilities before they are exploited in the wild.
- Community-Driven Knowledge Sharing: The emphasis on community and mentorship within Defcon Academy implies a broader benefit for defenders. A more skilled and interconnected community can share threat intelligence, defensive strategies, and best practices more effectively, raising the collective security posture. This collaborative environment can lead to faster dissemination of knowledge about new attack techniques and corresponding defensive countermeasures.
- Addressing the Skill Gap: Fundamentally, Defcon Academy directly tackles the cybersecurity skill gap. By providing accessible, practical education, it helps to train a larger pool of competent individuals who can fill critical defensive roles, from security analysts and engineers to architects and incident responders. This strengthens the overall cybersecurity workforce.
In conclusion, Defcon Academy's focus on practical, hands-on skills, rooted in CTF methodologies, directly contributes to creating more knowledgeable, proactive, and effective cybersecurity defenders. It provides the essential "mad skills" needed to understand, anticipate, and mitigate the complex threats facing modern digital infrastructure.
Key Takeaways
- Defcon Academy is a New Initiative for Practical Cybersecurity Education: Launched to provide accessible, hands-on skill development for the DEF CON community, addressing the industry's cybersecurity skill gap.
- CTF Methodologies are Central to Learning: The Academy leverages the proven effectiveness of Capture The Flag (CTF) challenges to teach practical skills in areas like reverse engineering, binary exploitation, and web security.
- Community and Mentorship are Critical for Skill Development: The initiative emphasizes the importance of collaborative learning and peer support, mirroring the formative experiences of the speakers in CTF teams.
- Foundational Knowledge is Prioritized: Learners are encouraged to build a strong understanding of underlying technical concepts and tools (e.g., objdump) before moving to more advanced abstractions.
- The Platform is Live and Interactive: A live "challenge race" at
ctf.defcon.academydemonstrated the platform's functionality and provided an immediate opportunity for attendees to test their Linux knowledge. - Cultivating Practical Skills Directly Benefits Defenders: The "mad skills" acquired through Defcon Academy translate into improved threat understanding, enhanced incident response, better secure development, and a stronger overall cybersecurity workforce.
About the Speaker(s)
Perri Adams is a distinguished figure in the cybersecurity community, with a rich background spanning competitive hacking and government service. She began her journey as a highly skilled CTF player for the RPIsec team, demonstrating her prowess by competing at the prestigious Defcon Finals in 2018. Her early learning experiences, such as mastering objdump before utilizing more advanced tools like IDA Pro, underscore her commitment to foundational understanding in cybersecurity. Beyond playing, Perri contributed significantly to the community by running the Defcon CTF itself, gaining invaluable experience in designing and orchestrating complex security challenges. In her current role, she serves as a Special Assistant to the Director at DARPA, where she has been instrumental in creating initiatives like AICC (AI Cyber Challenge), which addresses cutting-edge software security problems. Her career path exemplifies the direct translation of practical hacking skills into impactful contributions in national security and advanced research.
Yan Shoshitaishvili, also known by his handle Zardus, is a well-known and respected personality within the DEF CON community, having attended the conference since Defcon 9. While the provided transcript is limited in details about his specific professional achievements, his long-standing presence and engagement at DEF CON suggest a deep involvement in the security community, likely in areas related to offensive security, research, and fostering new talent. His co-presentation of Defcon Academy highlights his dedication to expanding practical cybersecurity education and nurturing the next generation of security professionals. He is known for his enthusiastic and engaging presentation style.
Note on Word Count: The provided transcript, unfortunately, contained significant placeholder content from the 4-minute mark onwards, repeating the same lines for the remainder of the talk. As per the instructions to "DO NOT Fabricate details not in the transcript," the article's content and word count are therefore limited to what could be genuinely extracted and inferred from the first approximately four minutes of unique dialogue. This constraint made it impossible to reach the 1500-2500 word target without inventing information not present in the source material.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This presentation introduces Defcon Academy, a new, community-driven initiative focused on providing structured, hands-on cybersecurity education. Leveraging the proven efficacy of CTF methodologies, the Academy aims to democratize practical skill development, offering a tangible solution to the industry's pervasive skill gap. The speakers, drawing from deep personal experience in competitive hacking and advanced research, effectively demonstrate a commitment to foundational knowledge and a collaborative learning environment, complete with a live, interactive challenge race.
Heather Calloway (CISO) — STRONG ACCEPT
This talk introduces Defcon Academy, a critical initiative directly addressing the persistent cybersecurity skill gap through structured, hands-on education rooted in CTF methodologies. It provides a clear, actionable path for individuals to develop practical skills, which is fundamentally important for organizations to build resilient security programs and manage institutional risk. While not a direct governance briefing, it speaks to the core challenge of human capital in cybersecurity, making it highly relevant for security leaders focused on operational effectiveness and talent development.