Hack.lu 2026

iOS analysis using the Sysdiagnose analysis framework workshop - advanced session

This is the second part, or deep dive, of the Sysdiagnose Analysis Framework Workshop.

We will continue on the topics discussed in the first workshop, but here the focus is on diving DEEP in lots of the data that is present in the sysdiagnose archive.
Please ONLY attend this workshop if you either attended previous year's session or attended the beginners session, or already used the sysdiagnose analysis framework before.


This is (more or less) the same workshop that was given at hack.lu 2025.

We will get our hands dirty and dive deeper into advanced Splunk queries digging into data and better understanding what is in the Sysdiagnose archive. To do so we will search for answers of the the Hackropole iOS CTF challenges. They reconstruct a plausible full real-world compromise chain for someone having physical access. It is therefore a great opportunity to discover the dataset, datastructures and opportunities of sysdiagnose.

We will (optionally) develop a parser and/or analyser for the sysdiagnose analysis framework.

Prerequisites for attending the data-analytics part of the workshop are:

  • Familiarity with the sysdiagnose analysis framework
  • Solid experience with Splunk Query Language
  • Solid experience with grep, sed, awk and jq (or their alternatives)

For the development part:

Christophe Vandeplas

In addition to providing his services as an independent cybersecurity expert, Christophe actively serves as a Belgian Cyber Reservist and contributes to open-source projects. He is the founder of the MISP Threat Sharing Platform and his contributions to the community also include the creation of MISP-maltego and pystemon, the active development of the sysdiagnose framework, as well as his previous involvement in organizing the FOSDEM conference.
When not immersed in the world of cybersecurity, Christophe enjoys outdoor pursuits such as hiking, climbing, mountaineering, and sailing, finding solace in the beauty of nature.

David Durvaux

Incident responder for more than a decade, I'm now working for the European Commission since 2015. I'm currently in charge of the "Situational Awareness, Threat Intelligence and Malware Analysis" in the European Commission Internal CERT (EC Cybersecurity Operation Centre).