Navigating the Invisible

Mehmet Onder Key, Furkan Aydogan (Linux system administrator)

DEF CON 33 · Day 1 · Main Stage

Overview

This talk, "Navigating the Invisible," delivered by Furkan Aydogan at DEF CON, delves into the complex and often opaque world of maritime security, presenting a dual perspective on intelligence gathering and offensive operations within this critical infrastructure sector. The presentation challenges conventional notions of open-source intelligence (OSINT) by introducing the concept of "All-Int," a broader methodology encompassing both publicly available data and commercially sourced, sometimes illicitly obtained, intelligence. The speakers, primarily focused on red team operations, highlight the increasing sophistication of adversaries targeting maritime assets and the necessity for defenders to adopt a similarly comprehensive approach.

Watch on YouTube

Visual summary for Navigating the Invisible by Mehmet Onder Key, Furkan Aydogan
Visual summary for Navigating the Invisible by Mehmet Onder Key, Furkan Aydogan

Key moments

  1. 0:00 Introduction and voyage plan for maritime security
  2. 2:00 Hybrid attack methodology using public intelligence data
  3. 3:35 Public case study: exposing sanction evasion with open data
  4. 5:55 Scaling maritime threat hunting with a risk engine
  5. 7:40 Shifting perspective: "Luffy's adventure" as an attacker
  6. 8:50 Luffy's "all int" attack: disrupting a vessel's voyage
  7. 10:30 Luffy's advanced attack: compromising systems and blackmailing

Navigating the Invisible

Speakers: Mehmet Onder Key; Furkan Aydogan (Linux system administrator)

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=JgKUrRaKo7o

Overview

This talk, "Navigating the Invisible," delivered by Furkan Aydogan at DEF CON, delves into the complex and often opaque world of maritime security, presenting a dual perspective on intelligence gathering and offensive operations within this critical infrastructure sector. The presentation challenges conventional notions of open-source intelligence (OSINT) by introducing the concept of "All-Int," a broader methodology encompassing both publicly available data and commercially sourced, sometimes illicitly obtained, intelligence. The speakers, primarily focused on red team operations, highlight the increasing sophistication of adversaries targeting maritime assets and the necessity for defenders to adopt a similarly comprehensive approach.

The talk is particularly relevant in an era where geopolitical tensions, economic sanctions, and the interconnectedness of global supply chains make maritime activities a prime target for illicit operations and cyberattacks. Aydogan, a Linux system administrator with five years in cybersecurity, frames the discussion around practical case studies – one public, investigating sanction evasion, and another private, illustrating advanced attacker tactics. This dual approach underscores the talk's core message: understanding both defensive intelligence aggregation and offensive exploitation vectors is paramount for securing the maritime domain.

Why this talk matters stems from its pragmatic blend of intelligence methodologies and attack simulations against real-world maritime vulnerabilities. It moves beyond theoretical discussions to demonstrate how seemingly disparate data points – from Automatic Identification System (AIS) tracks and satellite imagery to leaked credentials and human profiling – can be fused to expose deception or orchestrate sophisticated attacks. For cybersecurity professionals, maritime stakeholders, and intelligence analysts, "Navigating the Invisible" offers a critical perspective on the evolving threat landscape and actionable insights into bolstering defenses against hybrid physical and cyber threats.

Background

▶ Watch: Introduction and voyage plan for maritime security (0:00)

The maritime industry, a cornerstone of global trade and logistics, operates with a vast, interconnected, and often legacy-rich infrastructure, making it inherently vulnerable to a range of threats. Historically, security concerns primarily focused on physical piracy and contraband. However, the increasing digitalization of operational technology (OT) systems on vessels and at ports has introduced a new dimension of cyber risk. This talk situates itself at the intersection of these physical and cyber domains, emphasizing a "hybrid core" approach to security and intelligence, acknowledging that modern attackers also think in hybrid terms.

Prior work in maritime security has largely focused on Automatic Identification System (AIS) data for tracking vessels, satellite imagery for broad surveillance, and traditional intelligence gathering. However, the speakers argue that these individual data sets, when viewed in isolation, are often insufficient or even misleading. AIS data, for instance, can be manipulated or deliberately turned off, creating "dark" vessels. Similarly, satellite imagery alone might reveal a ship's presence but lack the crucial context of its identity or intent. The problem, therefore, lies in the fragmented nature of intelligence and the ease with which sophisticated actors can exploit these gaps.

The talk highlights the limitations of traditional Open-Source Intelligence (OSINT), which typically relies solely on publicly available information. While OSINT is foundational, the speakers introduce "All-Int" as a necessary evolution. This methodology recognizes that effective intelligence in high-stakes environments, such as maritime security, often requires integrating information from a wider spectrum, including commercial data feeds, paid Cyber Threat Intelligence (CTI) tools, data acquired from underground marketplaces (e.g., "deep web"), and sector-specific intelligence outputs. This broader perspective is crucial because adversaries are not constrained by ethical or legal boundaries in their data acquisition, often leveraging a mix of legitimate and illicit sources to achieve their objectives. The need for "All-Int" arises from the reality that critical pieces of intelligence, such as confirmation of a vessel's true ownership (hidden behind shell companies) or access to private port operational dashboards, frequently reside beyond the reach of purely open-source methods.

Key Findings

▶ Watch: Public case study: exposing sanction evasion with open data (3:35)

The presentation reveals several critical findings that underscore the complexity of maritime security and the evolving nature of threats:

  1. The Insufficiency of Pure OSINT: A central finding is the explicit distinction between "OSINT" and "All-Int." The speakers assert that relying solely on publicly available data is often inadequate for comprehensive threat detection or effective offensive operations in the maritime domain. "All-Int" encompasses a broader spectrum, including paid CTI tools, commercial data for sale, deep web intelligence, and sector-specific reports, which attackers and advanced defenders leverage.
  2. Hybrid Threat Landscape: The maritime environment faces a "hybrid core" of physical and cyber threats. Attackers are not limited to one vector but combine digital exploits (e.g., compromising port systems with CVEs, using leaked credentials) with physical deceptions (e.g., AIS spoofing, going dark) and human vulnerabilities (e.g., blackmailing crew members) to achieve their goals.
  3. Sophisticated Deception Schemes are Prevalent: The "MVC Sea Serpent" case study vividly demonstrates how vessels engage in organized deception to evade sanctions. This involves manipulating or disabling AIS signals in sanctioned zones, disguising ship identities (creating "zombie" ships with false IMO numbers), and conducting rendezvous with other vessels to transfer illicit cargo, all while maintaining an appearance of legitimate operation.
  4. Data Fusion for Irrefutable Evidence: Individual intelligence data sets (AIS tracks, satellite imagery, official databases) are often meaningless in isolation. However, when aligned and analyzed together through an intelligence cycle, they can provide "irrefutable proof" of illicit activities. The convergence of a vessel going "dark" on AIS in a sanctioned zone with Synthetic Aperture Radar (SAR) satellite imagery showing its physical presence and a rendezvous confirms deception.
  5. Human Element as a Critical Vulnerability: Despite advanced technical defenses, the human factor remains a significant weak point. The "Luffy" scenarios illustrate how attackers can profile individuals, exploit leaked personal details, and resort to blackmail or social engineering to bypass technical controls and achieve objectives, such as gaining access to systems or directly influencing vessel operations.
  6. Actionable Intelligence Requires Expert Context: While automated risk scoring engines can flag anomalies like GPS jittering or unusual AIS behavior, the talk stresses that these tools are "not a real weapon" without the contextual expertise of human maritime analysts or captains. Their knowledge is essential to differentiate genuine threats from benign operational anomalies.

These findings collectively paint a picture of a maritime domain under constant threat from adaptive adversaries, necessitating a multi-faceted, intelligence-driven, and human-augmented approach to security.

Technical Deep Dive

▶ Watch: Scaling maritime threat hunting with a risk engine (5:55)

The technical depth of the talk spans both defensive intelligence gathering and offensive attack methodologies within the maritime sector. The core defensive strategy revolves around an enhanced intelligence cycle that fuses various data sources, moving beyond basic OSINT.

Defensive Intelligence Methodology (All-Int):

  1. Data Collection and Mapping: The process begins with collecting AIS (Automatic Identification System) data, which provides real-time vessel identification, position, course, and speed. However, the talk immediately questions its reliability, noting that AIS can be manipulated or turned off.
  2. Identity Verification: To counter AIS deception, official databases (e.g., flag state registries, classification societies) are queried to verify a vessel's true IMO number and ownership. Cross-referencing this data can expose "zombie" ships operating under false identities.
  3. Satellite Imagery for Physical Confirmation: When AIS signals go "dark," Synthetic Aperture Radar (SAR) satellite imagery becomes crucial. SAR satellites can penetrate cloud cover and darkness, providing high-resolution images of vessels regardless of weather or time of day. This is used to confirm a vessel's physical presence and identify rendezvous activities, even if it's not transmitting AIS. The talk emphasizes that a SAR image showing two ships meeting precisely where an AIS signal disappeared provides "irrefutable proof" of deception.
  4. Intelligence Alignment and Analysis: The strength of the "All-Int" approach lies in aligning these disparate data sets. An AIS track showing an inconsistent heading, combined with an IMO number belonging to a different ship, and SAR imagery confirming a rendezvous in a sanctioned zone, collectively forms a compelling chain of evidence.
  5. Risk Scoring Engine (Proof of Concept): To scale this hunt, the speakers developed a simple risk scoring engine. This engine assigns points for suspicious behaviors, such as:
  • AIS signal going dark in high-risk areas.
  • Inconsistent heading or declared destination.
  • Association with known "zombie" ships.
  • Potential GPS jittering, a technique to flood tracking systems with noise, causing erratic position reports.

The engine provides a dashboard to highlight anomalies, but its effectiveness is augmented by human analysts and maritime experts who provide context and differentiate genuine threats from operational noise.

Offensive Attack Methodologies (Luffy's Adventures):

The talk uses two fictional "Luffy" scenarios to illustrate advanced attacker techniques, highlighting the blend of cyber, physical, and human exploitation:

  1. Port System Compromise (CVE 2025874):
  • Reconnaissance: Luffy tracks a target vessel (ARXXSN) but needs to confirm its departure and arrival ports.
  • Credential Theft/Leak: He gains access to a private portal using "leaked credentials from private dashboards" to confirm the departure point.
  • Vulnerability Exploitation: At the identified arrival port authority, Luffy discovers a vulnerability, CVE 2025874. While the exploit wasn't publicly shared, he "bought it on a marketplace" to gain system access. This highlights the commercialization of exploits and the deep web's role in attacker capabilities.
  • OT System Manipulation: With system access, Luffy targets the port's solar-powered lighting system. The implication is that controlling this system could disrupt night-time arrivals, causing delays or accidents.
  1. Escort Vessel Compromise and Human Exploitation:
  • Initial Compromise: Luffy compromises an account with access to "all terminal operation systems in South Africa" to target a vessel carrying critical cargo.
  • Lateral Movement/Supply Chain Attack: Noticing the target ship is escorted, he uses "more leak data" to breach the escort vessel's operating company.
  • Vessel Specification Analysis: Reviewing specifications, he realizes a direct attack on the well-equipped escort vessel would fail.
  • Human Vulnerability Exploitation: Luffy shifts focus to human vulnerabilities. He gains access to the crew list and extensively profiles the commanding officer, collecting "every personal detail available."
  • Blackmail: The ultimate goal is to "call him and ask him to hand over the protected vessel directly by the crew member," which is explicitly described as "purely a blackmail." This demonstrates how personal data, often collected through illicit means, can be weaponized against individuals to achieve operational control.

These offensive scenarios underscore the "All-Int" approach from an attacker's perspective, where a combination of technical exploits, illicit data acquisition, and social engineering is leveraged to achieve complex objectives. The mention of premium tools like Signal Ocean, Starboard Anzi, Thread Links Premium Dashboard, Email Box CC Searcher, and Premium Thread Circular further emphasizes the breadth of data sources available to both attackers and advanced defenders.

Demo / Proof of Concept

▶ Watch: Luffy's "all int" attack: disrupting a vessel's voyage (8:50)

The talk presented two distinct demonstrations or proofs of concept, illustrating both defensive capabilities and offensive tactics.

1. Risk Scoring Engine for Maritime Anomaly Detection:

The first demo showcased a proof of concept (PoC) for a simple risk scoring engine designed to detect suspicious behaviors in maritime traffic. While not a live, interactive demonstration of the tool itself, the speakers presented a mockup of its dashboard and explained its underlying logic. The engine's purpose is to assign points for various anomalies, such as:

  • Vessels entering high-risk zones.
  • Inconsistent AIS data (e.g., declared destination not matching heading).
  • AIS signals going dark.
  • Detecting GPS jittering, a technique where spoofed GPS signals introduce noise, causing tracking systems to report erratic or incorrect positions.

The mockup dashboard visually highlighted potential anomalies, allowing an analyst to quickly identify vessels warranting further investigation. The key takeaway from this demo was the emphasis on human augmentation: the engine could flag potential issues instantly, but "the real intelligence comes from a human analyst" who provides context and discerns genuine threats from false positives (e.g., a faulty transponder vs. deliberate GPS spoofing). The speakers acknowledged that for the tool to become a "real weapon," it needs input from maritime experts (e.g., ship captains) to accurately define high-risk zones and understand operational nuances.

2. Luffy's Adventures: Attacker Methodologies in Action:

The second set of demonstrations came in the form of two detailed "private case studies" involving a fictional attacker named Luffy. These were presented as narrative scenarios rather than live code execution, but they served as proofs of concept for how sophisticated, "All-Int" driven attacks could unfold against maritime targets.

  • Scenario 1: Port Disruption via CVE Exploitation:
  • Luffy's goal was to disrupt or delay a vessel's voyage.
  • The demo outlined a multi-step attack: using "leaked credentials from private dashboards" to confirm departure/arrival ports, identifying CVE 2025874 in the port authority's systems, acquiring an exploit from a "marketplace," and gaining system access.
  • The PoC demonstrated that with system access, manipulating an OT system like the port's "solar-powered lighting system" could have significant operational impact, especially for a night-time arrival. This scenario highlighted the blend of cyber exploitation (CVE, leaked credentials) with potential physical disruption.
  • Scenario 2: Escort Vessel Control via Human Exploitation:
  • Luffy targeted a vessel carrying critical cargo, escorted by a security vessel.
  • This PoC illustrated a supply chain attack: compromising accounts with access to "all terminal operation systems," then using "more leak data" to breach the escort vessel's operating company.
  • The core demonstration focused on human vulnerabilities. After realizing a direct attack on the escort vessel was infeasible, Luffy gained access to the crew list, "profiled the escort vessel's commanding officer," and collected "every personal detail available."
  • The PoC culminated in a plan for "purely a blackmail" to compel the commanding officer to hand over the protected vessel. This demonstrated how extensive personal data, often sourced from illicit marketplaces, could be weaponized through social engineering and blackmail to bypass all technical defenses.

Both sets of demonstrations, the risk scoring engine PoC and the Luffy narrative PoCs, effectively illustrated the core thesis of the talk: that a hybrid approach combining diverse intelligence sources, technical exploits, and human element considerations is crucial for both defending against and executing advanced maritime operations.

Defensive Implications

▶ Watch: Luffy's advanced attack: compromising systems and blackmailing (10:30)

The insights from "Navigating the Invisible" provide crucial guidance for maritime defenders, emphasizing a shift from reactive, siloed security to a proactive, comprehensive "All-Int" strategy.

  1. Adopt an "All-Int" Mindset: Defenders must move beyond traditional OSINT. This means integrating commercial threat intelligence feeds, subscriptions to premium maritime tracking and analytics platforms (e.g., Signal Ocean Premium Dashboard, Starboard Anzi, Thread Links Premium Dashboard), and potentially monitoring dark web forums for mentions of critical infrastructure or leaked credentials. Assuming adversaries leverage these broader sources, defenders must too.
  2. Strengthen Intelligence Fusion Capabilities: Individual data points like AIS tracks or satellite images are insufficient. Organizations need robust intelligence fusion platforms and processes to correlate diverse data sets – AIS, SAR imagery, official vessel registries, port schedules, CTI, and even social media – to build a complete picture. This helps identify discrepancies, confirm physical presence when AIS is dark, and unmask deception.
  3. Prioritize Supply Chain and Third-Party Security: The "Luffy" scenarios highlight the vulnerability of the maritime supply chain. Breaching an escort vessel's operating company or a port authority through leaked credentials or CVEs demonstrates that an attacker doesn't need to directly target the main vessel. Defenders must rigorously vet third-party vendors, suppliers, and partners, ensuring their security posture meets stringent requirements. Regular audits and penetration testing of these extended networks are essential.
  4. Enhance Vulnerability Management and Patching: The mention of CVE 2025874 underscores the importance of a mature vulnerability management program. Port authorities and vessel operators must identify, prioritize, and patch vulnerabilities in their IT and OT systems promptly. Legacy systems, often prevalent in maritime infrastructure, pose a particular challenge and may require virtual patching or robust compensating controls.
  5. Fortify Credential Management and Access Controls: Leaked credentials were a recurring theme in the offensive scenarios. Defenders must implement strong authentication mechanisms (e.g., multi-factor authentication for all critical systems), enforce strict password policies, regularly rotate credentials, and continuously monitor for credential leaks on public and dark web platforms. Least privilege access should be enforced across all systems, particularly those controlling operational technology.
  6. Invest in Human-Centric Security and Awareness: The most potent attacks in the "Luffy" scenarios exploited human vulnerabilities through profiling and blackmail. Defenders must:
  • Implement robust security awareness training that includes recognizing social engineering tactics and the dangers of oversharing personal information.
  • Conduct regular phishing and social engineering simulations.
  • Develop incident response plans specifically for human-targeted attacks (e.g., what to do if an employee is blackmailed).
  • Emphasize a culture where suspicious requests are reported without fear of reprisal.
  1. Integrate Maritime Expertise into Security Operations: Automated tools and risk engines are valuable but require human context. Security operations centers (SOCs) in the maritime sector should integrate personnel with deep operational knowledge of shipping, port logistics, and vessel operations. This expertise is vital for accurately interpreting anomalies, tuning detection systems (e.g., for GPS jittering), and making informed decisions about potential threats.
  2. Prepare for Hybrid Attacks: Defenders must assume adversaries will combine cyber, physical, and human vectors. Incident response plans should account for scenarios where, for example, a cyber breach is used to facilitate a physical act of sabotage or where human coercion leads to unauthorized operational changes. Cross-functional teams involving IT, OT, physical security, and HR are essential for responding to such complex incidents.

By adopting these defensive implications, maritime organizations can build a more resilient security posture, capable of navigating the invisible threats highlighted in the talk.

Key Takeaways

  • "All-Int" is the New Standard: Effective maritime security requires moving beyond traditional OSINT to an "All-Int" approach, integrating commercial, illicit, and sector-specific intelligence sources to gain a comprehensive view of threats and deceptions.
  • Hybrid Threats Demand Hybrid Defenses: Attackers combine cyber exploits (CVEs, leaked credentials), physical deception (AIS manipulation, SAR evasion), and human vulnerabilities (blackmail, social engineering). Defenders must build strategies that address this multi-faceted threat landscape.
  • Data Fusion is Critical for Deception Detection: Individual data points (AIS, satellite imagery, official databases) are often insufficient. Fusing and correlating these sources through a structured intelligence cycle is essential to uncover sophisticated deception schemes like sanction evasion or "zombie" ship operations.
  • Human Expertise Augments Automation: While automated risk scoring engines can flag anomalies like GPS jittering, human maritime experts are indispensable for providing context, differentiating genuine threats from operational noise, and transforming raw data into actionable intelligence.
  • Supply Chain and Human Element are Key Attack Vectors: Adversaries frequently target third-party vendors, port authorities, and individual personnel through leaked credentials, known CVEs, and personal profiling to gain access or exert influence, bypassing direct vessel defenses.
  • Proactive Defense Requires Attacker Empathy: Understanding how red teams and malicious actors leverage diverse information (paid CTI, deep web data, human profiling) to plan and execute attacks is crucial for building robust, anticipatory defensive strategies.

About the Speaker(s)

Furkan Aydogan is described as a Linux system administrator from the Czech Republic. He has been contributing to the cybersecurity ecosystem for five years and currently serves as a "captain" in the cybersecurity field, primarily focusing on red team operations. This talk represents his team's first venture into the maritime domain, a field they intend to continue exploring based on their project's findings.

Mehmet Onder Key is listed as a co-speaker but does not speak in the provided transcript. Based on the metadata, he is credited for his involvement in the talk.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A well-intentioned but shallow foray into maritime security from a team that is visibly new to the domain. The 'All-Int' framing is mostly rebranding of standard OSINT-plus-paid-tools practice, the offensive scenarios are narrative fiction rather than demonstrated tradecraft, and the CVE cited appears fabricated. Not ready for DEF CON.

Heather Calloway (CISO) — WEAK

A technically ambitious attempt to map hybrid threat methodology onto maritime infrastructure, but it never crosses into institutional accountability, governance, or actionable defense at the organizational level. The offensive scenarios are illustrative, not instructive — and the defensive implications read like a generic security checklist stapled to a domain-specific threat narrative.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33