Hack.lu 2026

Internet Background Radiation: Exploiting the Void

Network telescopes capture vast amounts of unsolicited Internet traffic, much of which is often dismissed as background noise. In reality, this traffic contains valuable information about Internet-wide scanning, botnet activity, exploitation attempts, misconfigurations, data leaks, DDoS activity, and more.

The workshop will introduce the approaches used by CIRCL and NASK/CERT.PL to extract useful information from network telescope, while also leaving ample time for independent experimentation. Participants will leave with a practical understanding of how to turn seemingly meaningless packets into observations of large-scale Internet phenomena and actionable threat intelligence.


In the first part of this workshop, we will draw on the experience operating and analysing large network telescopes at NASK/CERT.PL and CIRCL. We will present the collection and processing pipelines, explain how raw packets are transformed into structured and enriched datasets, and walk through real-world examples showing how Internet noise can be turned into actionable cyber threat intelligence. We will also compare observations from different telescope environments and discuss both the strengths and limitations of this data source.

The second part will switch to a hands-on, hackathon-style format. Participants will receive access to selected telescope datasets and analysis tools and will be encouraged to explore the data, formulate hypotheses, identify unusual behaviour, and investigate findings that capture their interest. The instructors will provide guidance and technical support, but there will be no predefined workflow or expected outcome. The goal is to recreate the exploratory process researchers use when analysing previously unexplored Internet traffic.

Requirements: Participants should bring a laptop and have a basic understanding of network protocols (layer 3 and above).

Paweł Pawliński

Paweł Pawliński is an expert at CERT.PL. His job experience includes data analysis, threat tracking, automation and coordinating international activities.

Jan Adamski

Senior Software Engineer at NASK’s Cybersecurity Team, specializing in large-scale Internet measurements, darknet and network-telescope analytics, and vulnerability research. Author of multiple CVEs, including CVE-2023-4617 (CVSS 10.0), and contributor to projects focused on IoT security, Bluetooth threat analysis, and unsolicited-traffic intelligence. Speaker at the FIRST 26 Annual Conference and leading Polish cybersecurity events, including The Hack Summit and Oh My Hack. He holds an ICT background from Warsaw University of Technology.

Jakub Koman

Senior Cybersecurity Specialist at NASK’s Cybersecurity Team, focused on large-scale network event analysis and the day-to-day operation of a network telescope. Previously conducted IoT security research and developed a custom framework for penetration testing of Bluetooth devices. Holder of multiple cybersecurity certifications, including OSCP+.

Paul JUNG

Paul Jung (paul.jung@circl.lu) is a long-time security professional with over two decades of experience in the cybersecurity field in Luxembourg. He has built extensive consulting expertise across multiple industries, covering activities from offensive security assessments to incident response and digital forensics. Prior to joining the Computer Incident Response Center Luxembourg (CIRCL), he served as Senior Security Architect in the Managed Network Security department of the European Commission, where he led the technical direction of major security projects. He later joined Excellium Services (acquired by Thales Group in 2022), where he founded and led TCS-CERT, a multi-country CSIRT dedicated to intrusion response. Paul regularly speaks at international conferences such as FIRST, Virus Bulletin, Botconf, and Hack.lu, and has published articles on DDoS, botnets, and incident response. He is a native French speaker and fluent in English.