BSidesPDX-2025

Drone Blind Spots: Pentesting the Airspace Above Critical Infrastructure
2025-10-24 , Talk 1

Critical-infrastructure sites have hardened perimeters, access controls, and robust camera systems that deter and catch ground-level intrusions. But what about the airspace above them? This talk addresses a gap many sectors share: detecting and responding to drones. We’ll walk through how airspace pentesting over critical infrastructure actually works, what on-site defenders can do to strengthen detection and response, and demystify how to legally and safely get started with aerial assessments. Attendees will leave with equipment recommendations, a clear runbook for performing this work, and a persuasive narrative to secure budget and buy-in for launching aerial assessment and drone-defense programs.


Who this talk is for:
• Offensive-security practitioners: penetration testers, red-teamers, and physical-security assessors who want to add an aerial dimension to their repertoire.

• Defenders & Incident Responders: facility-security, SOC analysts, and OT/ICS staff responsible for protecting critical sites and infrastructure.

• Aspiring newcomers: students, hobbyists, and those curious about where drones, radio frequency, and physical security intersect.

Helpful Knowledge:
• A working grasp of the standard pentest workflow and common physical-security controls (cameras, access systems, perimeters).

• Basic awareness of FAA Part 107 / small-UAS regulations (key points and every acronym will be spelled out on slides).

Alec (@brathadair) is a cyber-physical systems (CPS) security researcher specializing in Electromagnetic Spectrum Operations (EMSO), with extensive experience in drone-based Red Air engagements. He currently serves as a Security Consultant at SpookSec and was previously the Lead Offensive Security Engineer at Phoenix Technologies. He holds several certifications, including DSOC, DOCP, CSVA, CBBH, CDFP, OSWP, and FAA Part 107.