Black Hat Europe 2025 | Network Operations Center (NOC) Report

Black Hat
Black HatJun 4, 2026

Why It Matters

The NOC’s real‑time, fully controlled network provides a unique proving ground for security solutions, accelerating product maturity and offering attendees concrete insights into protecting high‑traffic, high‑risk environments.

Key Takeaways

  • NOC replaces all network gear for real‑time attack mitigation.
  • Partners like Cisco, Arista, Palo Alto provide integrated security hardware.
  • Black Hat traffic acts as “needle in a needle” for threat detection.
  • 85% encrypted traffic; misconfigured VPNs still expose attendee data.
  • Over 6,000 devices connected; Wi‑Fi 6/7 supports high‑density environment.

Summary

The Black Hat Europe 2025 Network Operations Center (NOC) report details how organizers rebuild the entire network stack—routers, firewalls, switches, and access points—for each event, enabling instant mitigation of attacks and live visibility into the most hostile conference traffic. Key insights include deep integration with vendors such as Arista, Cisco, Corelight, Jamf, and Palo Alto, and a data‑driven approach that treats the conference’s flood of malicious‑looking traffic as a "needle in a needle" environment, allowing rapid identification of genuine threats. Statistics show 85% of traffic is encrypted, over 6,000 unique wireless devices connected, and a peak of 1,346 concurrent Wi‑Fi users, highlighting both the scale and the challenges of securing a high‑density venue. Notable moments from the presentation feature Grifter’s candid admission that they reject sponsorship money to preserve equipment integrity, and a vivid description of real‑time dashboards—"Vibes" visualizations and Palo Alto XIM—that track alerts, human interventions, and automation opportunities. The team also highlighted misconfigured VPNs leaking location data, underscoring the need for robust endpoint controls. The report underscores how Black Hat’s NOC serves as a live testbed for security products, accelerating vendor integration and driving improvements that later reach enterprise customers. Attendees and vendors alike gain actionable intelligence on device behavior, encryption adoption, and network performance, shaping future security strategies for similarly aggressive environments.

Original Description

Back with another year of soul-crushing statistics, the Black Hat NOC team will be sharing all of the data that keeps us equally puzzled, and entertained, year after year. We'll let you know all the tools and techniques we're using to set up, stabilize, and secure the network, and what changes we've made over the past year to try and keep doing things better. Of course, we'll be sharing some of the more humorous network activity and what it helps us learn about the way security professionals conduct themselves on an open WiFi network.
By:
Neil Wyler | Vice President of Defensive Services, Coalfire
Bart Stump | Managing Principal, Coalfire

Comments

Want to join the conversation?

Loading comments...