← Back to Blog

July 1, 2026

AvengerCon X: The Hacker Con the Army Had to Fight to Build

8 min read

The origin story of AvengerCon X, the cultural rift it was built to bridge, and what the 780th MI Brigade's history panel revealed about standing up a cyber force from nothing.

cybersecuritymilitarycareerconference

In my previous post, I discussed Day 1’s hands-on workshop at AvengerCon X. Day 2 moved into the auditorium for an opening ceremony, a keynote on the conference’s own origins, and a history panel featuring the people who built the 780th Military Intelligence Brigade’s cyber force from scratch. This is the story I took away from both, and why I believe more people, in and out of the military, should know it exists.

A cultural civil war

Back in 2016, there was an ongoing debate within the 780th about whether it was possible to be both technically proficient and a leader. Officers who preferred hands-on roles as operators faced ostracism, perceived as deviating from the expected leadership style. One of the founders described the situation as a cultural civil war, with hacker culture (characterized by curiosity, disruption, and comfort operating outside conventional boundaries) on one side and military culture (emphasizing adherence to established parameters) on the other.

The concern wasn’t the existence of this tension itself. Rather, it was the risk that if no one actively worked to reconcile the two cultures, military culture would eventually absorb and eliminate hacker culture, as larger, more structured systems tend to do with smaller, unconventional ones. The objective became defining what it means to be a cyber warrior without forcing a dichotomy between hacker and soldier. A poignant line from that era resonates with me: leaders cannot assume risk in a domain they lack understanding. If individuals are to take calculated risks in cyber, someone above them must genuinely comprehend the implications of their actions.

The origins of AvengerCon

The concept for AvengerCon originated at a Johnny Rockets on the Las Vegas Strip, a seemingly improbable setting that only makes sense in retrospect. The underlying frustration was simple: only a limited number of soldiers, ranging from 4 to 6 annually, were able to attend DEF CON, leaving them with no opportunity to share their experiences with others upon their return. While debriefing conferences were possible, transferring the entire experience to others was not feasible.

So, they decided to create their own event. It’s called AvengerCon, named after Alpha Company, 71st’s callsign: the Avengers. The first year was limited to that single company and held within a classified R&E symposium. The event ran on improvised crypto challenges and lock-picking tasks, with junior soldiers tasked with presenting the material. In the second year, they moved to an unclassified venue, which was significant for two reasons. Firstly, it opened the door to the outside hacking community (DEF CON’s Watchtower Village appeared that year). Secondly, it allowed them to secure sponsorships, a deliberate shift away from the bootstrapped, whatever-we-can-scrounge approach of the first year.

The principles that kept it a hacker convention

A few early decisions explain why this event still feels distinct from a typical industry conference. The founders modeled it after DEF CON, not RSA, prioritizing hacker culture over cybersecurity-industry culture. They eliminated the vendor hall and maintained a focus on technical talks, Capture The Flag (CTF) competitions, and curiosity-driven sharing. The dress code is “hacker casual,” meaning no visible rank, so attendees’ contributions are judged based on their ideas rather than their insignia. Additionally, the community was intentionally built to be broadly inclusive, welcoming individuals from the Army, Navy, Marines, the intelligence community, and joint forces.

Keynotes were carefully sourced entirely from outside the military. Notable speakers included Eugene Spafford, Chris Eagle (co-author of The Ghidra Book), and Jeff Moss, the founder of DEF CON himself, among others. At one point, the organizers politely declined General Nakasone as a keynote speaker to preserve the tradition of having an outside perspective. This choice was genuinely unusual for a military-run event and reflected their true values: an outside mirror held up to the force, rather than another internal voice assuring them of their success.

There’s also a mentorship program because junior soldiers weren’t volunteering to present on their own. Instead of letting that talent go unnoticed, the organizers created a structure to bring it to the forefront. Almost everything you see at the conference today, including drone racing, started because a junior soldier raised their hand and asked, “Can we try this?”

The lock pick story

My favorite anecdote from the entire session was about a lock-pick village. The legal office (the SJA) refused to approve a memorandum of understanding for it. Instead of killing the idea, the commander personally assumed the risk and allowed it to proceed. As a result, the organizers decided to theme an entire year of the conference around lock picks. That’s the spirit of the event: bureaucratic friction met with defiance and a sense of humor, not compliance and quiet retreat.

Even the t-shirts have a story. They were funded as a “force protection measure” because “we want to look like a hacker con” wasn’t, on its own, a fundable justification. The conference art has a similar backstory: for its first three years it leaned on the NSA graphics department before eventually scaling down to a two-person effort. Sometimes, institutional creativity is its own skill.

What the history panel added

While the opening keynote provided the founding story, the history panel (moderated by Lt. Col. Rob Frost, with panelists including a former command chief warrant officer, a former brigade commander, a long-serving command sergeant major, and one of the brigade’s original operators) added the institutional weight behind it.

The persistent problems were candidly acknowledged. The training pipeline has been the single most significant long-standing issue throughout every panelist’s tenure. While the workforce roadmap was initially designed to define knowledge, skills, and abilities, it has been misappropriated as a mandatory pipeline to justify force structure to Congress. Consequently, the brigade has never had control over the seats, course conduct, or funding associated with it. Force structure has consistently prioritized operators over supporting roles, including capability development, information operations, and other areas. As one panelist aptly put it, “we’re not form-fit for the current fight, let alone the future fight.” Furthermore, the incentive pay program was severely flawed at its inception, leading to soldiers being penalized for naming and processing errors. In response, one panelist devised a workaround by signing the form first and allowing the review chain to catch up later, simply to secure the correct date for back pay. That first-generation program is now being replaced by Cyber Mastery Incentive Pay, which aims to set a consistent pay framework across all the services, with a congressionally directed implementation report due to the Department of War in October 2026 and Guard and Reserve inclusion still being worked out.

But the progress was real too. Operational independence stands out as the most significant long-term gain: the force started with no platforms of its own and cobbled-together chains of command, and now runs its own joint mission operations centers, the first one stood up from nothing in 45 days and a second following shortly after in Georgia. Dynamic targeting transformed the approval cycle entirely. It used to require locking in specific IP addresses weeks or months ahead of an operation, a process built for a world where infrastructure sat still. Adversary infrastructure now stands up and disappears within 24 hours, so that old process became useless, and the push has been toward approving targets hours before execution instead of months out, with agentic reconnaissance the next frontier. And the talent pipeline has genuinely strengthened: roughly 5,000 applicants compete for 160 to 200 enlisted seats now, with the Guard and Reserve running 21 teams combined (11 Guard and 10 Reserve), more than the active component. The panelists were careful to frame that as more than raw headcount. The 780th and 781st are driving a CNMF University aimed at genuine domain mastery rather than checking off a work-role certification, and one panelist kept returning to the idea of the “cognitive warrior,” the recognition that cognitive load in this domain is real and that mental and physical fitness both matter to sustaining it.

The panel closed on a quote from a Colonel Buckner, from around 2015: “50% confident we got 25% of it right” when the force was first being built. The point wasn’t self-deprecation. It was a direct handoff: the people still in uniform today have the opportunity, and the responsibility, to fix the rest. As one panelist put it, “if you get happy with the way things are, the adversary will outpace us.”

Why I’m writing this at all

This story is bigger than one brigade. It’s an argument for a specific way of building any team that has to stay technical over time: protect the curious people instead of sanding them down, let outsiders challenge you on purpose, and treat every bureaucratic “no” as a design constraint rather than a stop sign. That’s true whether you’re standing up a cyber force or just trying to keep a small security team sharp inside a larger organization that doesn’t fully understand what it does.

AvengerCon has grown well past what its founders expected, and it grew because the community around it kept showing up and building things. If you’re anywhere near this space next year, whether you’re in the military, industry, or just cyber-curious, it’s worth finding your way in. That’s how it gets bigger, and better, for the next class of people who need exactly what I got out of Day 1 and Day 2.