Filipi Pires
Drogonsec is an open-source, high-performance security scanner built for developers and CI/CD pipelines. In a single run, it combines four analysis engines: SAST for 20+ languages, SCA for dependency CVEs, secret detection with 50+ patterns (AWS, GCP, GitHub, JWTs, SSH keys), and IaC misconfiguration analysis for Terraform and Kubernetes, all mapped to OWASP Top 10:2025 and CWE, with CVSS 3.1 scoring and SARIF output for GitHub and Azure DevOps integration.
This Arsenal session will demo Drogonsec scanning real-world repositories live, showing findings across all four engines, explaining rule design decisions, and showcasing how teams can extend it with custom YAML rules. Attendees leave with a running tool they can drop into their pipelines the same day.
Filipi Pires
Head of Technical Advocacy
I’ve been working as Head of Technical Advocacy at SCYTHE, Founder & Investor at CROSS-INTEL, BSides Porto Organizer, Red Team Village Director (DEF CON), Senior Advisor Raices Cyber Academy, Founder of Red Team Community (Brazil and LATAM), AWS Community Builder, Snyk Ambassador and Application Security Specialist. International Speaker at Security and New technologies events in many countries such as US (Black Hat & Defcon), Canada, France, Spain, Germany, Poland, Black Hat MEA - Middle-East - and others, I’ve served as University Professor in Master Degree in Portugal, Graduation and MBA courses at Brazilian colleges.
Black Hat US 2025 - https://blackhat.com/us-25/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat US 2024 - https://blackhat.com/us-24/arsenal/schedule/presenters.html#filipi-pires-46329 Black Hat MEA 2025 - https://blackhatmea.com/speaker/filipi-pires-0 Black Hat MEA 2024 - https://blackhatmea.com/speaker/filipi-pires