The 4th edition of RomHack Training is arriving in Rome from September 28 to October 1, 2026. We are hosting three intensive, deep-dive technical courses at the Polo Didattico in Rome.
Whether you are looking to master reverse engineering, Windows/Linux exploitation, or hardware hacking these sessions are designed to provide hands-on knowledge directly from industry leaders before we head to RomHack Camp on October 2.
Seats are strictly limited to ensure a high-quality instructor-to-student ratio; all tickets include the 4-day course, digital training materials, lunch, and coffee breaks (accommodation is not included in the price).
The training concludes just as RomHack Camp begins at Flaminio Village (October 2 to 4). Every training participant will receive 1 free attendance ticket for the Camp.
Please note: The free Camp ticket covers event entrance only and does not include accommodation. Participants must independently purchase their tent space or bungalow if they wish to stay on-site at the Flaminio Village.
Go from zero to hardware hacking hero. This intensive 4-day training is a deep dive into the marvelous world of Hardware Hacking and Embedded Security. Forget just reading a book—this is a very technically-oriented, hands-on experience where you will get your hands dirty with real-world hardware.
Participants will learn the essential TTPs (Tactics, Techniques, and Procedures) used during professional security audits. From reversing PCBs and identifying “The Good, The Bad & The Ugly” debugging protocols (UART, SPI, JTAG) to dumping firmware from NAND/eMMC memories, we cover the entire hardware attack surface. By the end of the session, you’ll be able to identify, extract, and analyze firmware, performing both static and dynamic analysis to uncover vulnerabilities in the devices that surround us.
9:00 - 18:00
Master PCB reversing, firmware dumping/analysis, and hardware debugging protocols.
Security Researchers, Pentesters, and AppSec professionals curious about Hardware.
Target hardware devices, specialized hacking tools, and all necessary electronic components.
Luca Bongiorni is working as Director of a CyberSecurity Lab and founder of WHID – We Hack In Digsuise (www.whid.ninja). Luca is also actively involved in InfoSec where his main fields of research are: Radio Networks, Hardware Hacking, Internet of Things, and Physical Security. He also loves to share his knowledge and present some cool projects at security conferences around the globe: BlackHat Europe & USA, TROOPERS, HackInParis, DEFCON, HackInBo, RomHack, Defcon Moscow, OWASP Chapters, Security Analyst Summit, etc. At the moment, he is focusing his researches on bypassing biometric access control systems, IIoT Security & Forensics, Air-Gapped Environments and IoOT (Internet of Offensive Things).
Full Price
Early Bird
NOT AVAILABLE ANYMORE
Widely regarded as the most advanced class on Windows heap exploitation, Corelan Heap doesn’t just teach you how to use known exploits—it teaches you how to conduct your own research. From precise heap folding with “Memorigami” to bypassing the latest Windows 11 mitigations, this 4-day intensive deep-dive covers the entire landscape of modern memory corruption. You will move beyond the stack to master the primary attack surface of today: the Heap.
9:00 - 18:00
Master Windows Heap internals, advanced Feng Shui, and 64-bit exploitation.
Advanced Pentesters, Vulnerability Researchers, and Exploit Developers.
Verbose courseware, custom lab VMs, and life-long post-training support.
Peter Van Eeckhoutte is the founder of Corelan Team and the author of the world-renowned “Exploit Writing Tutorials” series. With decades of experience in the field, he is a recognized authority in Windows exploit development and vulnerability research. Peter is known for his unique ability to break down highly complex low-level concepts into digestible, logical steps, focusing on a “mindset” approach rather than just technical execution. His training has been delivered globally to military, intelligence, and private sector organizations.
Full Price
Early Bird
NOT AVAILABLE ANYMORE
A 4-day Linux kernel exploitation frenzy!
This training guides researchers through the field of Linux kernel exploitation. In a series of practical labs, the training explores the process of exploiting kernel bugs in a modern Linux distribution on the x86-64 architecture.
The training is structured as a series of lectures, each followed by one or more hands-on labs. The goal of each lab is to write a Linux kernel exploit following the techniques described during the lecture.
The training starts with beginner topics but proceeds into advanced areas as well. The beginner chapters include learning how to escalate privileges and bypass foundational mitigations in x86-64 kernels. The advanced chapters are primarily dedicated to the modern Slab (heap) exploitation techniques and include an in-depth analysis of the kernel allocators’ internals.
The core requirement for this training is the ability to read and write C code. Basic knowledge of the x86-64 architecture and assembly, GDB, and the common binary exploitation techniques would also come in handy. There is no need to know any Linux kernel internals: all required parts are covered during the training.
9:00 - 18:00
exploiting
linux kernel
developers
bug hunters / pentesters
slides/workbook
laboratories (VM)
Andrey Konovalov is a security researcher focusing on the Linux kernel.
Andrey found multiple zero-day bugs in the Linux kernel and published proof-of-concept exploits for these bugs to demonstrate the impact. Andrey contributed to several security-related Linux kernel subsystems and tools: KASAN — a fast dynamic bug detector; syzkaller — a widely-used kernel fuzzer; and Arm Memory Tagging Extension (MTE) — an exploit mitigation.
Andrey gave talks at many security conferences such as OffensiveCon, Zer0Con, Android Security Symposium, and Linux Security Summit. Andrey also maintains a collection of Linux kernel security–related materials and a channel on Linux kernel security.
See xairy.io for all of Andrey’s articles, talks, and projects.
Full Price
Early Bird
NOT AVAILABLE ANYMORE