Kill Chain: A Platform Cybersecurity Podcast
Jul 24, 2026 · 1 hr 11 min · 13 segments
On this episode of Kill Chain, we go straight to the source with someone who spends his career trying to break into cars, trucks, and the chargers that power them. Kamel Ghali is an automotive…
So you just mentioned that you are teaching a course.
So you're probably familiar, a lot of cybersecurity conferences and events, they'll have like a conference where they have presentations, talks, workshops, sponsor booths, etc.
So the cybersecurity training is usually more hands on, it's usually kind of a separate ticket, you have to pay separately for the training and for the conference.
where you'll have an instructor who teaches you, you know, an intensive two-day class about something, right? A lot of conferences will have the training days before the conference.
DEF CON, I think, is a bit rare in that they do the conference first and then they have the training afterwards.
I'm going to be looking at a lot of A lot of different parts of the automotive, you know, security ecosystem.
So vehicles themselves, connected infrastructure like EV chargers, so on and so forth.
Nice.
So do you actually bring like ECUs in and set them up for, you know, training? Like what does the course look like curriculum wise? And like who are you trying to attract? Is it the hackers? Is it the professional cybersecurity engineers that work at the Ford and GM and the big OEMs? Or kind of what are you targeting there? Great question.
So I'm actually going to pull up my course listing and kind of just like make sure I don't misquote myself on the actual content in there.
But the idea is, is that it's, I'm trying to make a class that's valuable for everyone.
So not only the engineers and the hackers, we're going to be do the actual, we're going to do a lot of the hands on technical security work, the penetration testing, the hacking, of course, there's a lot of valuable content for them, a lot of hands on technical engineering exercises.
But there's a lot of content that's also relevant for the manager, or the, excuse me, executive class as well, right? So it kind of takes a walk through the overall automotive cybersecurity industry, explaining the history of the industry, how we got here, what we're doing, and then going into a couple of really in-depth case studies on past exploits that have been published targeting automotive systems.
then
And then from there, we go into just a tiny bit of like the regulations and stuff that are surrounding automotive cybersecurity.
And not only for cars, but there's a lot of regulations that are kind of mimicking the automotive security legislative structure that's being applied to other smart products like IoT devices, so on and so forth.
So you just mentioned that you are teaching a course.
So you're probably familiar, a lot of cybersecurity conferences and events, they'll have like a conference where they have presentations, talks, workshops, sponsor booths, etc.
So the cybersecurity training is usually more hands on, it's usually kind of a separate ticket, you have to pay separately for the training and for the conference.
where you'll have an instructor who teaches you, you know, an intensive two-day class about something, right? A lot of conferences will have the training days before the conference.
DEF CON, I think, is a bit rare in that they do the conference first and then they have the training afterwards.
I'm going to be looking at a lot of A lot of different parts of the automotive, you know, security ecosystem.
So vehicles themselves, connected infrastructure like EV chargers, so on and so forth.
Nice.
So do you actually bring like ECUs in and set them up for, you know, training? Like what does the course look like curriculum wise? And like who are you trying to attract? Is it the hackers? Is it the professional cybersecurity engineers that work at the Ford and GM and the big OEMs? Or kind of what are you targeting there? Great question.
So I'm actually going to pull up my course listing and kind of just like make sure I don't misquote myself on the actual content in there.
But the idea is, is that it's, I'm trying to make a class that's valuable for everyone.
So not only the engineers and the hackers, we're going to be do the actual, we're going to do a lot of the hands on technical security work, the penetration testing, the hacking, of course, there's a lot of valuable content for them, a lot of hands on technical engineering exercises.
But there's a lot of content that's also relevant for the manager, or the, excuse me, executive class as well, right? So it kind of takes a walk through the overall automotive cybersecurity industry, explaining the history of the industry, how we got here, what we're doing, and then going into a couple of really in-depth case studies on past exploits that have been published targeting automotive systems.
then
And then from there, we go into just a tiny bit of like the regulations and stuff that are surrounding automotive cybersecurity.
And not only for cars, but there's a lot of regulations that are kind of mimicking the automotive security legislative structure that's being applied to other smart products like IoT devices, so on and so forth.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.