home / talks & media / requiem-for-the-decommissioned
DEF CON 34 Red Team Village Workshop + Tactic

Requiem for the Decommissioned: When Dead Hosts Bite Back

// Red Team Village · DEF CON 34 · Aug 8, 2026
the talk

Every organization has a graveyard: hosts decommissioned after a migration, abandoned when a project died, or dropped from inventory after a reorg. Off the asset list, out of the patch cycle, out of mind, and still on the network.

This talk flips the usual angle. Instead of "this host is vulnerable because it's outdated," it asks "this host is outdated, so it's probably worth a closer look."

Abandonment isn't the excuse you write in a report; it's the lead you start from.

A forgotten host is frozen in time, everything around it moved on, and it didn't. The tell isn't one bad setting; it's drift from the organization's own norm, on several axes at once. So you don't compare a host to best practice. You compare it to its own family.

the method
1
Enumerate, quietly
Certificate Transparency (crt.sh). Zero packets to them.
2
Learn what healthy looks like here
The org's usual TLS, headers, year, certificate org name.
3
Measure drift
Time · wrong identity · below-norm posture · left exposed.
4
Correlate
One weak signal is noise; several at once is a lead.
5
Look at it
A screenshot catches what metadata can't.
6
Prioritize, then explain
The tool ranks; you decide.