Drone Blind Spots: Pentesting the Airspace Above Critical Infrastructure

Alec Hunter (Security Researcher · breathadare)

BSides Seattle 2026 · Day 1 · Track 1

Overview

Alec Hunter, who operates under the moniker "breathadare," delivered a compelling talk on a security domain most cybersecurity professionals never consider: the airspace above critical infrastructure. With five years of drone-focused cyber-physical security consulting and a decade of commercial drone operations, Hunter makes the case that America's 16 CISA-designated critical infrastructure sectors are almost entirely undefended against drone threats, and that penetration testers should expand into aerial assessments.

Watch on YouTube

Visual summary for Drone Blind Spots: Pentesting the Airspace Above Critical Infrastructure by Alec Hunter
Visual summary for Drone Blind Spots: Pentesting the Airspace Above Critical Infrastructure by Alec Hunter

Key moments

  1. 0:00 Blind spot #1: drone over a dam nobody noticed
  2. 4:00 FAA Remote ID mandate and the drone license plate analogy
  3. 6:00 Critical infrastructure has near-zero drone detection
  4. 10:00 Modern drone anatomy: Nvidia Jetson, AI, autonomous flight
  5. 12:00 Custom drones: threat effects, AI recon, and mother ship relay
  6. 16:00 Scenario development and pen test reporting structure
  7. 18:00 DTI layering: radar, RF, optical, and acoustic detection
  8. 24:00 Legal constraints: why you cannot shoot, jam, or hack drones

Drone Blind Spots: Pentesting the Airspace Above Critical Infrastructure

Speakers: Alec Hunter (breathadare), Cyber-Physical Security Consultant

Conference: BSides Seattle 2026

YouTube: https://www.youtube.com/watch?v=pHtiWXfoaiE

Overview

Alec Hunter, who operates under the moniker "breathadare," delivered a compelling talk on a security domain most cybersecurity professionals never consider: the airspace above critical infrastructure. With five years of drone-focused cyber-physical security consulting and a decade of commercial drone operations, Hunter makes the case that America's 16 CISA-designated critical infrastructure sectors are almost entirely undefended against drone threats, and that penetration testers should expand into aerial assessments.

The talk opened with a striking demonstration of blind spot number one: a photo of Oregon's Henry Hagg Lake dam with a drone visible at 1,500 feet that no audience member initially noticed. That same drone, using 28x zoom, could clearly identify a person standing on the dam's spillway. If the dam had basic DTI (Detect, Track, and Identification) technology, it would have known the drone's exact position, serial number, and pilot ID. It didn't, because almost no critical infrastructure in America has drone detection capability.

This is a call to action for the cybersecurity community to learn drone operations, get Part 107 certified, and apply penetration testing methodologies to the airspace dimension that organizations are ignoring entirely.

Background

▶ Watch: Blind spot #1: drone over a dam nobody noticed (0:00)

The regulatory landscape for drones shifted significantly on March 15, 2024, when the FAA mandated Remote ID for all new commercial drones. Remote ID functions as a drone's license plate: drones must broadcast their serial number via Bluetooth or Wi-Fi, along with their exact latitude, longitude, and altitude. The serial number is tied to the pilot's identity through the drone registration process. Consumer apps can detect these broadcasts from potentially miles away.

Despite this regulatory framework, Hunter's professional experience reveals a stark gap: critical infrastructure sites in America almost never detect drones. His standard initial assessment involves loitering a drone over a facility for one full battery cycle (approximately 20 minutes), then asking security personnel at a follow-up meeting if anyone reported a drone. The answer is consistently no.

CISA has published airware guidance documents advising critical infrastructure operators on drone protection, but these are recommendations, not enforceable compliance requirements. Hunter emphasized the asymmetry: adversaries on the ground face high risk when approaching critical infrastructure, but a drone operator faces very low consequences even when detected, because current US law severely restricts what anyone can do about a drone in flight.

The December 2025 ban on new Chinese-made drones (primarily DJI) has further complicated the landscape, limiting defenders and pen testers to used or domestically manufactured equipment.

Key Findings

▶ Watch: Critical infrastructure has near-zero drone detection (6:00)

Hunter's penetration testing experience yields several critical findings:

Detection gap is near-total. Most critical infrastructure sites have zero drone detection capability. When Hunter loiters a drone for 20 minutes over a facility, security teams never report it. Even audience members admitted they would not report seeing a drone.

Legal constraints favor attackers. Under US law, it is illegal to jam, hack, or interfere with a drone in flight (up to 20 years imprisonment). Shooting a drone is prosecuted as shooting down an aircraft. Civilian response is limited to watching, reporting, or deploying a follow-back drone. Only a few categories of sites (military bases, nuclear facilities) have authorization for kinetic drone neutralization.

Threat identification is non-trivial. Hunter demonstrated that consumer drones carrying cameras are visually indistinguishable from drones carrying threats. One of the images shown contained a bomb-carrying drone that looked identical to standard commercial drones. As drones become ubiquitous (food delivery, construction, law enforcement), identifying malicious intent becomes exponentially harder.

Aerial threat = capability x intent. Hunter presented a threat matrix crossing drone capability (consumer off-the-shelf, prosumer, DIY) with pilot intent (recreational, structured, sophisticated) to generate threat profiles ranging from casual espionage to APT-level chaotic disruption with swarms.

Technical Deep Dive

▶ Watch: Custom drones: threat effects, AI recon, and mother ship relay (12:00)

The talk covered the full aerial defense program lifecycle: establishing legitimacy and getting buy-in, site threat modeling, initial assessment, scenario development, reporting, system placement, tuning, retesting, and eventual red air operations.

Modern drones are defined by their capability, not their airframe. Even decade-old F250 frames become modern when equipped with Nvidia Jetson companion computers capable of edge computing, AI processing, and fully autonomous flight. Key capabilities include signal intelligence (SIGINT), autonomous recon, and relay operations.

Hunter described several custom-built drones:

  • A drone hacking training platform operated inside an anechoic chamber (Faraday cage) for legally practicing jamming, spoofing, and hijacking
  • A threat effects drone reaching 90 mph with a 3D-printed fake payload, used for psychological response training
  • An AI recon drone capable of autonomous flight with signal intelligence collection and wireless signal triage
  • A mother ship drone that carries and deploys a smaller canary drone via servo, using the larger drone as a relay to test facility response to the smaller intrusion drone

For defenders, three categories of response drones exist: the SkyX10 follow-back drone (follows intruding drones back to their launch point), soft kill drones that disable threats without destruction (enabling forensics), and the Anduril Anvil hard kill drone that uses AI to calculate an intercept course and physically rams the threat drone.

The DTI layering strategy for site protection involves four detection systems: radar (farthest range, identifies drone cross-section), radio frequency detection (captures Remote ID and signal types, enables triangulation), optical DTI (visual confirmation of drone type within facility boundary), and acoustic DTI (limited utility). Primary detection systems operate on outer rings; secondary systems on inner rings verify what outer rings detect. The concept of First Opportunity Detection (FOD) measures the earliest moment a system could have detected a drone.

System tuning involves automated drone flights writing predetermined patterns; if the word appears correctly in the C2 interface, the systems are properly calibrated. Scenario-based retesting then verifies that detection systems would defeat previously approved test cases.

Red team operations require maintaining signature discipline, executing threat profiles precisely, avoiding safety hazards, and providing clean artifacts immediately for blue team analysis.

Demo / Proof of Concept

▶ Watch: Scenario development and pen test reporting structure (16:00)

Hunter showed photographs from actual site assessments, including the Henry Hagg Lake (Scoggins Dam) engagement where a drone at 1,500 feet with 7x and 28x zoom captured detailed imagery of the dam and personnel. He also demonstrated photos of his custom-built drones including the threat effects drone, AI recon drone, and mother ship drone with its deployable canary. A DTI placement diagram for the Scoggins Dam showed recommended positions for three RF detection units and one acoustic detection system. The facility cost estimate for a basic drone defense system was cited at approximately $250,000, not including operational costs.

Defensive Implications

▶ Watch: Legal constraints: why you cannot shoot, jam, or hack drones (24:00)

The most immediate implication is that critical infrastructure operators need to assess their drone vulnerability. Hunter recommends that every critical infrastructure site on CISA's list should have at least one staff member certified as a drone pilot who can respond to intrusions by following back to the launch point. This is currently the most effective legal response available.

Organizations should invest in layered DTI systems (radar, RF, optical) and consider response drones (follow-back at minimum). The estimated cost of $250,000 for systems alone, plus operational costs, means this is a board-level budget decision.

For the cybersecurity community, Hunter makes the case that aerial penetration testing is the natural progression from traditional physical pen testing. Getting a Part 107 certification from the FAA is the entry point, and the skillset maps directly from existing red team methodologies.

The legal landscape creates a significant defender disadvantage: law enforcement cannot do anything more than civilian observers can regarding drones. Only military bases and a handful of critical infrastructure sites with catastrophic consequence potential (nuclear facilities) are authorized for kinetic drone response.

Key Takeaways

  • America's critical infrastructure has near-zero drone detection capability, despite drones being an escalating threat vector across all 16 CISA critical infrastructure sectors
  • Remote ID is the drone's license plate (mandated March 2024), but most facilities lack the DTI systems to read it
  • Legal constraints heavily favor drone attackers: jamming, hacking, or shooting drones carries up to 20 years imprisonment; only watching, reporting, or following back is legal for civilians and most law enforcement
  • Aerial pen testing is a natural extension of physical security testing; cybersecurity practitioners should consider Part 107 certification
  • Layered DTI systems (radar, RF, optical) cost approximately $250,000 per site and should be treated as essential infrastructure defense
  • Every critical infrastructure site should have a certified drone pilot on staff for incident response

About the Speaker(s)

Alec Hunter (moniker: breathadare) has been providing cyber-physical security consultancy specializing in hardware, IoT, and drones for five years, with an additional decade of commercial drone services including real estate and other applications. He conducts drone penetration testing and aerial assessments at critical infrastructure sites across the United States. His background is in penetration testing and red teaming, and he describes drone security as the natural progression of that career path.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Hunter opens a genuinely underexplored attack surface for the cybersecurity community. The aerial pen testing methodology is well-structured, the custom drone builds (AI recon, mother ship relay, threat effects) show real offensive creativity, and the finding that critical infrastructure has near-zero drone detection is a damning indictment. This is more of a practitioner's field guide than deep technical research, but it defines a new specialization that deserves attention.

Heather Calloway (CISO) — STRONG ACCEPT

Hunter exposes a systemic governance gap that should alarm every CISO responsible for physical facilities. The finding that critical infrastructure consistently fails to detect a drone loitering for 20 minutes is a board-level risk finding. The legal framework that prevents defenders from neutralizing drone threats while imposing minimal consequences on attackers creates an asymmetry that demands policy advocacy. The $250K cost estimate for basic DTI systems gives CISOs a concrete budget number to bring to leadership.

→ Top-rated talks at BSides Seattle 2026

All talks from BSides Seattle 2026