CFP Directory LogoCFP Directory
EventsSpeakersTalksOrganizationsFeaturesPricingWhy Us
Sign in

Company

  • About Us
  • Contact

Contact Info

Address:

13, Lorong Toh Aka

Georgetown 10100

Penang, Malaysia

Email:

info@cfp.directory

Website:

13thirtyseven.my

Business Hours

Monday - Friday:9:00 AM - 6:00 PM
Saturday:9:00 AM - 1:00 PM
Sunday:Closed

GMT+8 (Malaysia Standard Time)

© 2025 CFP Directory. All rights reserved.
13 Thirty Seven Sdn. Bhd. (1401538-A)
Privacy PolicyTerms of Service
Back to Speakers
Pengfei Yu

Pengfei Yu

Solution Architect at Picus Security

Singapore
English, Chinese (Mandarin)
Virtual Events

3

Talks Delivered

3

Events Spoken At

3

Countries Visited

1

Years Speaking

3

Total Talks Given

About

Pengfei is a Solution Architect at Picus Security, where he advise enterprise security teams in implementing automated adversary simulation operations and framework.


Previously, he worked as a Cybersecurity Engineer in GovTech's GCSOC team, where he led the implementation of continuous purple teaming across the Whole-of-Government. Before this role, he served on GovTech's red team, mainly dabbling in VAPT and Adversary Simulation.


Pengfei is certified with OSCP, eMAPT, Crest CRT, CCSK V4, etc. He has conducted research on emerging cybersecurity technologies and presented his findings at renowned conferences like Black Hat USA & Asia, DEFCON, SINCON, ROOTCON, etc.

Speaking Topics & Expertise

Areas of Expertise

Cyber Security
Mobile Security
CI/CD Security
Container Security
Kubernetes Security
SOC Operations
Offensive Security
Android Security

Presentation Types

Technical Talk
Workshop
Case Study

Audience Types

Security Engineers
Security Professionals
Penetration Testers
Purple Team
Red Team
Blue Team
Architects
CISOs

Speaking History

2023

The Creation of the Out-Of-Band Anti Virus Dock (OOBAVD)

ROOTCON 17
September 28, 2023
Philippines
Technical Talk
Conference
Hardware Hacking
Malware Analysis
AI/ML
View Slides & Materials

The Creation of the Out-Of-Band Anti Virus Dock (OOBAVD

DEFCON 31 HHV
August 11, 2023
Las Vegas
Technical Talk
Conference
Hardware Hacking
Malware Analysis
AI/ML

USB-based attacks account for over 52% of all cybersecurity attacks on operational technology (OT) systems in the industrial control systems (ICS) industry. Stuxnet's discovery in 2015 showed the vulnerability of air-gapped systems, previously considered invulnerable. These systems are found in secure military organizations and SCADA systems. The societal impact of such attacks can be enormous, as evidenced by Stuxnet's impact on Iran's nuclear programs.


Air-gapped systems, while considered secure, mostly require mobile storage devices like USB sticks for updates and data transfers, exposing them to malware. Adding peripherals like keyboards and mice will also render the systems vulnerable to BadUSB attacks. This all can be prevented by OOBAVD, which acts as an intermediary between air-gapped systems and USB devices, blocks malicious files from entering the air-gapped systems. OOBAVD being out of band also mitigates the risk of malware attacking the host's antivirus software.


So what exactly is OOBAVD and how does one take an anti-virus out of band?

Android Obfuscation - Balancing the Offence and Defence

SINCON 2023
January 5, 2023
Singapore
Technical Talk
Conference
Mobile Security
AI/ML

Connect

https://github.com/FA-PengFeiLinkedIn Profile

Experience Level

advanced