Wireshark for <s>hackers</s> reverse engineers
2026-09-20 , Tesla

While AI assisted tools are helping us speed run the analysis of unknown protocols, we still need to have a solid foundation to make sense of the larger picture. In this talk I will focus on three topics for that initial step of the investigation before analysis tools or even dissectors start to make sense.


While AI assisted tools are helping us speed run the analysis of unknown protocols, we still need to have a solid foundation to make sense of the larger picture. In this talk I will focus on three topics for that initial step of the investigation before analysis tools or even dissectors start to make sense: I will start start by sharing how to prepare a sane and fresh Wireshark environment for a new reverse engineering session. Then followed by example on how to weed out traffic and translating initial findings into usable information. Finally we will go through several TLS variants and see what we need to decrypt those to add plain text information to our protocol tree.
The skills demonstrated in this talk sit solidly before more advanced steps such as automated analysis with scapy/AI tools and writing full dissectors or reverse engineered implementations of communication protocols.

Erik de Jong is an elite hardware hacker and senior cybersecurity consultant, running his own company error32.io, with extensive experience in identifying vulnerabilities and securing complex systems. Known for a hands-on "brains first, tools second" approach and deep technical expertise, Erik specializes in reverse engineering, embedded systems, and hardware security. With a passion for crowdsourced security, Erik actively contributes to bug bounty programs and has participated in multiple bugbashes (live hacking events), where he's collaborated with other top hackers to uncover critical vulnerabilities in real-time.