
OWASP ISTG in Practice: A CTF-Style IoT Hacking & Defending Lab
Step into the world of ethical hacking and uncover the unseen vulnerabilities hiding inside everyday connected devices. This immersive, beginner-friendly lab teaches IoT security the way professionals actually practice it — using the OWASP IoT Security Testing Guide (ISTG) as your map — wrapped in an approachable Capture-the-Flag format, and led by the team that authors and field-tests the methodology.
No experience necessary. Just bring your curiosity. Whether you’re a student, a tech enthusiast, or someone eyeing a cybersecurity career, this session makes real device hacking accessible, hands-on, and genuinely fun.
Working against a custom-built networking device, you’ll follow the ISTG methodology from the outside in. You’ll start at the hardware: reading and interpreting physical signals to locate and identify an exposed UART interface (ISTG-PHY, ISTG-INT) — the kind of serial debug port that, in real-world assessments, hands attackers an unauthenticated root shell within minutes of opening the enclosure. Unlocking that interface opens a cyber range where you’ll pivot through firmware secrets (ISTG-FW), then practice attacks at the network and application layers — each flag mapped back to an ISTG test-case category, so you leave understanding not just how you got in, but how the risk is classified and defended.
By the end, you’ll have a repeatable, standards-based mental model for testing any connected device — and a firsthand look at the most overlooked risks living inside the networks we all rely on.
Aaron Guzman is CISO of Cisco Network Product Engineering, the organization responsible for securing Cisco’s enterprise and industrial networking portfolio — from wireless access points, routers, and switches to IoT cameras and sensors — much of the infrastructure that moves the world’s data. He is the author of the IoT Penetration Testing Cookbook and a technical reviewer for Practical IoT Hacking and Bug Bounty Bootcamp. As OWASP’s IoT Project Leader, he leads the IoT Security Testing Guide (ISTG) — the very methodology at the heart of this lab. He started as a hacker, driven by a curiosity to take things apart and make them do what they were never designed to — a curiosity that now scales across hardware, firmware, supply chains, and software at enterprise scale.
Piero Picasso (p33_p33_) is a Senior Security Leader for Device Penetration Testing at Cisco, where he leads security testing for network infrastructure and IoT devices. Based in the Fort Lauderdale area, he brings over 20 years of experience in offensive security, penetration testing, and product security engineering. Over five-plus years at Cisco — including as Offensive Security Leader at Cisco Meraki — he built and scaled security testing programs for cloud-managed networking products. Earlier, he assessed Fortune 500 clients as a penetration tester at Secureworks and led ethical hacking within Citi’s regulated financial environment. He continues to advance Cisco’s device security posture through hands-on testing methodologies and cross-functional security research.
Las Vegas Convention Center, 3150 Paradise Rd, Las Vegas, NV 89109, USA
VägbeskrivningSkanna med kameran – eventet öppnas i Somo-appen.









