Radiofrequency
Analysis of radio links and proprietary signals with SDR: capture, demodulation and replay, from trackside balises to control transmitters.
Hardware security · RF · Drones · Critical infrastructure
I'm David Meléndez Cano, an R&D engineer and hardware security researcher. I work with radiofrequency, drones, embedded systems and railway signalling. I teach in the cybersecurity master's degrees at the University of Castilla-La Mancha and the Complutense University, I run trainings and speak at DEF CON, Black Hat and RootedCON. I'm the author of the book «Hacking con Drones» and founder of TechFrontiersLabs.
Analysis of radio links and proprietary signals with SDR: capture, demodulation and replay, from trackside balises to control transmitters.
Building drones from scratch, evading counter-drone systems, side channels over WiFi beacon frames and frequency hopping on low-cost platforms.
Embedded Linux, firmware, buses (I2C, UART, RS-485) and reverse engineering of undocumented protocols.
Railway signalling (ASFA, ERTMS/ETCS) and building control: how they can be attacked with off-the-shelf tools, and how to protect them.
A selection of drones, robots and radiofrequency projects. Each card links to its page with the details.

A research series on the security of railway signalling, from the legacy Spanish ASFA system to the European ERTMS/ETCS.

Our own drone and controller for research and training in drone radio warfare: jamming-resistant links and alternative channels.

A nanodrone with embedded Linux that evades counter-drone systems, with a hidden WiFi channel and a radio fallback. It costs around $70.

A quadcopter controlled by a home router running Linux. Origin of the TRRP platform (Trash Robotic Router Platform).

A teleoperated ground robot with camera, telemetry, laser rangefinding and a dual firing turret. First robotics prize at Campus Party 2010.

An own-design IoT electrocardiograph with signal processing in the browser and identification of P-QRS-T waves.

Reverse engineering of the undocumented protocol of a building control system, starting from a broken air conditioner.

A Pacman agent trained with reinforcement learning, as the final project of Berkeley's online CS188 Artificial Intelligence course.
A dated record of my public talks, demos and workshops. Every entry links to an external source (official program, video or slides published by the event) so anyone can verify it.
Media appearances, interviews and podcasts.
A technical manual on how a drone works inside: sensors, stabilisation, PID control, Kalman filters, telemetry and radio. It lets you build one from scratch and understand how it's attacked and defended.
View on 0xWord