{"$schema": "https://c3voc.de/schedule/schema.json", "generator": {"name": "pretalx", "version": "2026.3.0.dev0", "url": "https://pretalx.com"}, "schedule": {"url": "https://pretalx.com/bsides-tallinn-2026/schedule/", "version": "0.13", "base_url": "https://pretalx.com", "conference": {"acronym": "bsides-tallinn-2026", "title": "BSides Tallinn 2026", "start": "2026-09-24", "end": "2026-09-25", "daysCount": 2, "timeslot_duration": "00:05", "time_zone_name": "Europe/Helsinki", "colors": {"primary": "#154596"}, "rooms": [{"name": "Stage A", "slug": "5815-stage-a", "guid": "273887fa-13b0-52b2-8555-0f3780775535", "description": null, "capacity": null}, {"name": "Stage B", "slug": "5816-stage-b", "guid": "642b0bbe-cd1d-550e-ba3e-990cc4a33f0e", "description": null, "capacity": null}, {"name": "Village area", "slug": "5818-village-area", "guid": "9322fdfe-8a03-50c0-ac59-cce35be751de", "description": "Village area - hands-on activities all day long.", "capacity": null}, {"name": "Office 6", "slug": "6234-office-6", "guid": "3d9adb21-5c90-5a74-88d9-c4bf48d47c5f", "description": null, "capacity": null}, {"name": "MUSE 9:30-15:00", "slug": "6225-muse-930-1500", "guid": "7bc4a63a-282c-58ed-bcf6-a42bd3415f88", "description": null, "capacity": null}, {"name": "Workshop room (LD1) 9:30-15:00", "slug": "5817-workshop-room-ld1-930-1500", "guid": "8eb16a4e-7978-51db-a163-3328061bab41", "description": null, "capacity": null}, {"name": "Workshop room (LD2)", "slug": "6226-workshop-room-ld2", "guid": "9bb658cf-0326-5fa2-908a-d1d8c1868e56", "description": null, "capacity": null}], "tracks": [{"name": "VILLAGE", "slug": "7242-village", "color": "#00ccff"}, {"name": "Talk", "slug": "7244-talk", "color": "#0000f0"}, {"name": "Workshop", "slug": "7245-workshop", "color": "#1bb845"}], "days": [{"index": 1, "date": "2026-09-24", "day_start": "2026-09-24T04:00:00+03:00", "day_end": "2026-09-25T03:59:00+03:00", "rooms": {"Office 6": [{"guid": "316b0fac-8da3-5dd2-90b5-ad48a18acd0e", "code": "FRBPMV", "id": 104039, "logo": null, "date": "2026-09-24T09:30:00+03:00", "start": "09:30", "end": "2026-09-24T13:00:00+03:00", "duration": "03:30", "room": "Office 6", "slug": "bsides-tallinn-2026-104039-plc-unplugged-09-30-11-15", "url": "https://pretalx.com/bsides-tallinn-2026/talk/FRBPMV/", "title": "PLC unplugged (09:30, 11:15)", "subtitle": "", "track": "Workshop", "type": "Main track 25.09.2026", "language": "en", "abstract": "Sign-up form 9:30-11:00: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSdOjY6rFN2ZInDlhhISxCVzdPxOKuT_C_PicJ-Tbg_T827qPg/viewform?usp=sharing&ouid=104367224945762059530)\nSign-up form 11:15-12:45: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSfQToAcJ78Q2r57PzQt85G8zBkdu1aG4OJn7LEelwatuaqZFw/viewform?usp=sharing&ouid=104367224945762059530)\n\nProgrammable Logic Controllers (PLCs) are field-level devices in OT/ICS/SCADA systems that read sensors, execute logic and drive real machinery. Compromise a PLC and you can overspeed a pump, slam a valve shut or make a safety interlock ignore a fault.\n\nIn this workshop you will hunt down and exploit 5 security issues straight out of real-world PLC deployments.\n\nRequirement: Laptop with Wi-Fi and Ubuntu 24.04 VM (amd64/arm64).", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "Z3PM3J", "name": "Mait Peekma", "avatar": "https://pretalx.com/media/avatars/K7CUKR_F98q4VF.webp", "biography": "If you are reading this, you probably get paid to build or protect stuff. Mait does the opposite \u2014 but has somehow avoided handcuffs so far.", "public_name": "Mait Peekma", "guid": "43eefd3e-8ebd-5b2e-bb26-d7b435506f95", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/Z3PM3J/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/FRBPMV/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/FRBPMV/", "attachments": []}, {"guid": "7b1e8973-531d-5391-bb09-bfd5420fd444", "code": "PKPUQY", "id": 103552, "logo": null, "date": "2026-09-24T14:00:00+03:00", "start": "14:00", "end": "2026-09-24T18:00:00+03:00", "duration": "04:00", "room": "Office 6", "slug": "bsides-tallinn-2026-103552-anti-forensics-and-anti-anti-forensics-techniques-for-incident-responders-all-spots-full", "url": "https://pretalx.com/bsides-tallinn-2026/talk/PKPUQY/", "title": "Anti-Forensics (and Anti-Anti-Forensics) Techniques for Incident Responders (ALL SPOTS FULL)", "subtitle": "", "track": "Workshop", "type": "Main track 25.09.2026", "language": "en", "abstract": "Sign-up form: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSflrNlvBgEhynGyZiMNxAOgZrIG98CO1ViXK0M9v9ovC-JORQ/viewform?usp=sharing&ouid=104367224945762059530)\n\nA full-spectrum dive into anti-forensics across Windows and Linux (with a tad of MacOS, if time permits), centered on real incidents and modern attacker behavior. The course walks through classic log wiping, deeper filesystem tricks, PowerShell, timestomping, sandbox artifacts, memory-only execution, endpoint solution blind spots, and advanced Linux log manipulation.\n\nEach technique is paired with detection logic, weaknesses in attacker tradecraft, and practical forensic recovery paths. The material emphasizes hands-on analysis, including MFT/MSRUM/USN artifacts, ETW traces, VHDX extraction, /proc-based investigation, and highlights new research and tooling that shape current offensive and defensive strategies.\n\nThis is an excerpt from my full 2-3 day training I offer under my brand malmium.com (https://malmium.com/training-anti-forensics.html)", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JJSUWM", "name": "Stephan Berger", "avatar": "https://pretalx.com/media/avatars/C7AHN8_ik6J5wJ.webp", "biography": "Stephan Berger has over a decade of experience in cybersecurity. Currently working with the Swiss-based company InfoGuard, Stephan investigates breaches and hacked networks as Head of Investigation of the Incident Response team. An avid Twitter user under the handle @malmoeb, he actively shares insights on cybersecurity trends and developments. Stephan also authors the blog DFIR.ch, where he provides in-depth analysis and commentary on digital forensics and incident response. Stephan has spoken at numerous conferences, sharing his expertise with audiences worldwide.", "public_name": "Stephan Berger", "guid": "7cac3538-c233-5dbc-939e-274b67e36e27", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/JJSUWM/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/PKPUQY/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/PKPUQY/", "attachments": []}], "MUSE 9:30-15:00": [{"guid": "85dd4670-93fb-589c-9e8e-920715c6afd5", "code": "LSPSQU", "id": 103402, "logo": null, "date": "2026-09-24T09:30:00+03:00", "start": "09:30", "end": "2026-09-24T12:30:00+03:00", "duration": "03:00", "room": "MUSE 9:30-15:00", "slug": "bsides-tallinn-2026-103402-inside-scattered-spider-a-red-vs-blue-breach-attack-simulation", "url": "https://pretalx.com/bsides-tallinn-2026/talk/LSPSQU/", "title": "Inside Scattered Spider: A Red vs. Blue Breach & Attack Simulation", "subtitle": "", "track": "Workshop", "type": "Main track 25.09.2026", "language": "en", "abstract": "Sign-up form: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSfyDWjKYOrV0mHxXlkwjWINIIqRIC_2qKlu75dg7OjY4pYBSA/viewform?usp=sharing&ouid=104367224945762059530)\n\nScattered Spider redefined modern ransomware operations through sophisticated social engineering, privilege escalation, and rapid domain-wide compromise. In this immersive workshop, participants experience the attack from both perspectives: first as the attacker, then as the defender.\n\nWorking through a realistic breach simulation, you'll execute key phases of the attack before switching roles to detect, investigate, and respond using modern detection and endpoint security capabilities. By the end of the workshop, you'll understand not only how the attack works, but why defenders succeed, or fail, at each stage.\n\nYou'll learn:\n\nHow Scattered Spider gains initial access and escalates privileges.\nHow to detect and investigate each stage of the attack.\nWhere traditional defenses fall short.\nHow modern security operations and AI-assisted investigation can reduce time to detection and response.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JZBTWS", "name": "Marvin Ngoma", "avatar": "https://pretalx.com/media/avatars/GYNGG7_CrABpCe.webp", "biography": "Marvin is a seasoned consultant and security architect. He has a strong passion for helping nordic and baltic organizations succeed in their cybersecurity programs. He has led many projects in both the private and public sectors, architecting and building Security Operations and Intelligence capabilities; unifying tools, processes, and people. Prior to joining Elastic, Marvin worked as a security consultant at IBM and was the primary SME for QRadar in the nordics and baltics.\n\nIn addition to his work with clients, Marvin frequently speaks at conferences, summits, and meetups on the latest security topics, making him a dedicated security evangelist. He holds a masters in Computer Science & Engineering from Chalmers University of Technology in Sweden, and is a very proactive member of ISC2, among other security bodies.", "public_name": "Marvin Ngoma", "guid": "57acd5ab-c2ae-5f53-a4d0-1cabf340c136", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/JZBTWS/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/LSPSQU/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/LSPSQU/", "attachments": []}], "Workshop room (LD1) 9:30-15:00": [{"guid": "4896c361-8212-5229-9424-d3ae3b6c8219", "code": "TMCQPB", "id": 103910, "logo": null, "date": "2026-09-24T09:30:00+03:00", "start": "09:30", "end": "2026-09-24T11:30:00+03:00", "duration": "02:00", "room": "Workshop room (LD1) 9:30-15:00", "slug": "bsides-tallinn-2026-103910-gotta-contain-em-all-collaborative-incident-response-training-through-gaming", "url": "https://pretalx.com/bsides-tallinn-2026/talk/TMCQPB/", "title": "Gotta Contain 'Em All: Collaborative Incident Response Training Through Gaming", "subtitle": "", "track": "Workshop", "type": "Main track 25.09.2026", "language": "en", "abstract": "Sign-up form: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSdtdi-PcGMdEWRj0-EARLu4UMCQt_2hxAyRkJkJ6R_Oe_LyFw/viewform?usp=sharing&ouid=104367224945762059530)\n\nIncident response isn't just about knowing your tools - it's about coordinating under pressure, communicating when things go sideways, and making calls with incomplete information. Traditional training focuses on isolated techniques, missing the collaborative reality of actual incidents. And most tabletop exercises? Painfully dull. Participants zone out, give checkbox answers, and leave having learned little.\n\nThis workshop introduces Malware & Monsters (https://malwareandmonsters.com), a framework that turns IR training into something people actually enjoy. Think tabletop role-playing meets creature-collection mechanics, where teams \"hunt and contain\" digital threats through story-driven gameplay.\nGame-based learning works - research shows it beats traditional instruction for skill building and retention. M&M makes participants actively discover concepts instead of sitting through lectures. Scenarios include organizational pressures, evolving threats, and stakeholder drama, turning abstract security concepts into tangible problems.\n\nYou'll experience the full methodology: learn the mechanics, build custom scenarios based on real malware families (mapped to MITRE ATT&CK), and run live simulations. Participants take specialized roles - Hunter, Analyst, Forensicator, Communicator, Coordinator, or Researcher - experiencing how security functions actually collaborate during incidents.\n\nThe framework includes legacy malmons from malware history\u2014because history always repeats itself, and understanding past threats reveals patterns in current attacks. The \"type effectiveness\" system teaches strategic thinking about matching defenses to threats. Evolution mechanics show how attacks escalate when containment fails.\n\nParticipants walk away with ready-to-use materials and facilitation techniques for training that actually works.\n\nBest of all? M&M is free to play in most cases.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "EUVE7T", "name": "Klaus Agnoletti", "avatar": "https://pretalx.com/media/avatars/JZ8NCF_NRSojrT.webp", "biography": "Klaus Agnoletti has been an all-round infosec professional since 2004. As a long-time active member of the infosec community in Copenhagen, Denmark, he co-founded BSides K\u00f8benhavn in 2019. \n\nCurrently he's a freelance storytelling cyber security advisor specializing in security transformation and community focused marketing, employer branding, playing security games  and other fun assignments and ideas coming his way. \n\nLately he has also become a neurodiversity advocate speaking about ADHD to educate and break down taboos in an industry with a vast overrepresentation of neurodiversity and not very many talking about it.", "public_name": "Klaus Agnoletti", "guid": "72b2acfd-d78f-5489-8ba7-10d5f3452ed6", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/EUVE7T/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/TMCQPB/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/TMCQPB/", "attachments": []}, {"guid": "7b0e9b5b-4f68-5046-abfa-1250c165aae7", "code": "9MPHHC", "id": 102781, "logo": null, "date": "2026-09-24T12:00:00+03:00", "start": "12:00", "end": "2026-09-24T14:00:00+03:00", "duration": "02:00", "room": "Workshop room (LD1) 9:30-15:00", "slug": "bsides-tallinn-2026-102781-mastering-bash-for-hackers-extreme-command-line-power", "url": "https://pretalx.com/bsides-tallinn-2026/talk/9MPHHC/", "title": "Mastering Bash for Hackers: Extreme Command-Line Power", "subtitle": "", "track": "Workshop", "type": "Main track 25.09.2026", "language": "en", "abstract": "Sign-up form: [**Google form**](https://docs.google.com/forms/d/e/1FAIpQLSc7YHDN0zuZxnWsWdCvDJAFC_SVsdjSal6T0uwqr-6cUIUKBA/viewform?usp=sharing&ouid=104367224945762059530)\n\nBash isn\u2019t just an interface to your daily laptop - it\u2019s a weapon. In this hands-on workshop, we\u2019ll push bash beyond its typical use, leveraging it for hacking, data processing, automation, and real-world security applications. Whether you\u2019re crafting exploits, analyzing massive datasets, or automating reconnaissance, this session will equip you with the skills to turn bash into your ultimate hacking tool.\n\n- Master advanced bash scripting techniques for automation, and hacking.\n- Process terabytes of leaked password data and uncover real-world security insights.\n- Use bash to manipulate and extract intelligence from logs, network traffic, and system artifacts.\n- Generate graphs, automate reports, and convert file format entirely from the command line.\n- Learn how to replace GUI-based tools with bash scripts for speed and stealth.\n\nBy the end of this workshop, you\u2019ll be able to:\n- Automate and accelerate security tasks with powerful one-liners and scripts.\n- Use bash to analyze, manipulate, and exploit data in security research.\n- Apply bash in unconventional ways, from image processing to document forensics.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "ZEXGTB", "name": "Kirils Solovjovs", "avatar": "https://pretalx.com/media/avatars/9TGUPN_6m3XuWT.webp", "biography": "Kirils Solovjovs is Latvia's leading white-hat hacker and IT policy activist, known for uncovering and responsibly disclosing critical security vulnerabilities in national and international systems. An expert in penetration testing, network flow analysis, and reverse engineering, he is also a lifelong command-line enthusiast. Kirils started programming at age 7 and by grade 9 was spending his lunch breaks writing machine code directly in a hex editor. He uses bash daily for hacking, automation, and large-scale data processing and is sometimes contracted by major online education providers to proofread their bash certification exams. He currently is the lead researcher at Possible Security.", "public_name": "Kirils Solovjovs", "guid": "e5a8144c-bc60-592c-9428-0534f0658038", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/ZEXGTB/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/9MPHHC/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/9MPHHC/", "attachments": []}], "Workshop room (LD2)": [{"guid": "95bbb87d-79e2-5c85-9978-66852206101e", "code": "7BLJ9P", "id": 103808, "logo": null, "date": "2026-09-24T09:30:00+03:00", "start": "09:30", "end": "2026-09-24T11:30:00+03:00", "duration": "02:00", "room": "Workshop room (LD2)", "slug": "bsides-tallinn-2026-103808-wifi-discovery-and-monitoring-101-primarily-with-kismet", "url": "https://pretalx.com/bsides-tallinn-2026/talk/7BLJ9P/", "title": "Wifi Discovery and monitoring 101 primarily with Kismet", "subtitle": "", "track": "Workshop", "type": "Main track 25.09.2026", "language": "en", "abstract": "Sign-up form: [**Google form**](https://docs.google.com/forms/d/e/1FAIpQLSdLBMX6Vri_5y7ayR_Nl5U9FA3KniNe-m3h7InRaFvGq2hePA/viewform?usp=sharing&ouid=104367224945762059530)\n\nA practical two-hour workshop for up to 18 participants working in nine pairs.\n\nExplore Wi-Fi and Bluetooth activity around you: what can be seen, what cannot, and why. Participants will use Kismet to discover nearby wireless networks and devices, then interpret the results in context.\n\nThe workshop covers:\nAn introduction to Wi-Fi and Bluetooth discovery: scanning vs. passive monitoring\nHow channels, monitor mode, signal range, and hardware affect device visibility\nA practical introduction to Kismet and its core capabilities\nGuided testing with organizer-provided Wi-Fi devices\nObserving how device interactions appear in Kismet\n\nParticipants will leave to be  able  better understand and interpret the wireless environment around them.\n\nPlease bring a laptop with VirtualBox installed and Ethernet capability (or a suitable adapter). The organizer will provide nine USB/USB-C 802.11ax Wi-Fi adapters, one per pair.\n\nBringing your own compatible Wi-Fi or Bluetooth hardware is encouraged. This may also allow additional participants to take part if all adapter places are filled. Please ask the instructor in advance if you would like to confirm whether your hardware is suitable.\n\nAll active testing is limited to organizer-provided devices in the workshop environment", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "XZU3AB", "name": "Toomas Lepik", "avatar": "https://pretalx.com/media/avatars/ECDJ8N_1R1eEHr.webp", "biography": "A well-seasoned Cyber Security Analyst with 20+ years of experience across the IT industry, specialising in network forensics, malware analysis, and incident handling. Blends hands-on technical investigation with  critical thinking\u2014and a healthy appreciation for laziness, meaning efficient solutions that avoid unnecessary work. Passionate about secure software practices and turning messy incidents into clear, actionable answers. Away from the keyboard, likes sauna and  happily pets dogs and most other domestic animals", "public_name": "Toomas Lepik", "guid": "32713cad-9901-55c3-8470-774a5e485208", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/XZU3AB/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/7BLJ9P/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/7BLJ9P/", "attachments": []}, {"guid": "0cc64fb7-d33f-5be3-87a5-f40a256a223d", "code": "L9BSJD", "id": 103986, "logo": null, "date": "2026-09-24T12:00:00+03:00", "start": "12:00", "end": "2026-09-24T13:30:00+03:00", "duration": "01:30", "room": "Workshop room (LD2)", "slug": "bsides-tallinn-2026-103986-ham-radio-workshop-and-exam-all-spots-full", "url": "https://pretalx.com/bsides-tallinn-2026/talk/L9BSJD/", "title": "HAM radio workshop and exam (ALL SPOTS FULL)", "subtitle": "", "track": "Workshop", "type": "Main track 25.09.2026", "language": "en", "abstract": "Sign-up form: [**Google form**](https://docs.google.com/forms/d/e/1FAIpQLSeMYQwT8ww8Tig3xwbBRT-KkxjSRlQrft9ntquQrqhuvqBAZA/viewform?usp=sharing&ouid=104367224945762059530)\n\nBecoming amateur radio operator is not that hard, specially if you come from techie background. Workshop will cover basics needed to get certified as class D (entry-level) amateur radio operator, from physics to law to communication protocols, equipment and community.\n\nIf you feel ready - perhaps [having studied](https://es1tp.github.io/comms-parent/#/public/et) and [tried answering exam questions](https://es1tp.github.io/comms-parent/#/public/et/pages/qualification/products/D-%20kvalifikatsiooniklass/offers/qualification_cat_d_et_qualification_D) - you can pass both practical and theoretical part of exam during BSides Tallinn.\n\nWorkshop is planned together with village on 25th - so participants can get an intro course to amateur radio, do first communication tests and take amateur radio operator's exam on-site (class D), like in famous DEFCON https://defcon.social/@HamRadioVillage.\n\nVillage, workshop and exams are organized by Radio Network Committe of Eesti Raadioamat\u00f6\u00f6ride \u00dching (https://eesti-raadioamatooride-uhing.github.io/raadiosidevorkude-toimkond/) having goal of building and maintaining repeaters, IP and radio networks, digital systems, and cybersecurity.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "E39C83", "name": "Peeter Marvet", "avatar": "https://pretalx.com/media/avatars/TWAF7C_afAFFD7.webp", "biography": "Estonian Radio Amateurs Union https://erau.ee/en/ has been active since 1935, with members taking part in contests and organizing field days. Workshop and village are created by ERA\u00dc's Radio Networks Committee, tasked to build and maintain repeaters, IP and radio networks, digital systems, and taking care of related cybersecurity.\n\nOur goal is simple: more airtime, more coverage, more radio amateurs on the air every day.", "public_name": "Peeter Marvet", "guid": "f7b075b5-2a39-538f-aef6-8fc93cb5c746", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/E39C83/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/L9BSJD/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/L9BSJD/", "attachments": []}]}}, {"index": 2, "date": "2026-09-25", "day_start": "2026-09-25T04:00:00+03:00", "day_end": "2026-09-26T03:59:00+03:00", "rooms": {"Stage A": [{"guid": "19d6532d-f9ca-5645-919c-ea0d6f9f4e67", "code": "YQZXNJ", "id": 104664, "logo": null, "date": "2026-09-25T10:00:00+03:00", "start": "10:00", "end": "2026-09-25T10:45:00+03:00", "duration": "00:45", "room": "Stage A", "slug": "bsides-tallinn-2026-104664-keynote-by-alvar-soome-how-to-eat-a-wooden-carrot", "url": "https://pretalx.com/bsides-tallinn-2026/talk/YQZXNJ/", "title": "KEYNOTE by Alvar Soome \"How to eat a wooden carrot\"", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "When we look around, we see that Estonia is doing amazing things, building fantastic systems and leading IT innovation all over the world. Public WIFI is even in bogs and all children learn how to program already in kindergarden. This is what we sell. But what is the actual reality behind the curtains. \n\nHow we order wooden carrots and wonder why they aren't edible? \nHow is it possible that simple database modification takes one year? \nWhat is \"IT disaster formula\" in IT sector and how can we solve it? Can we? \nWhy smart people with great ideas tend to vanish from public sector? Hopefully before burnout! And what do we mean, when we say that this is \"security circus\" and who let the clowns out?", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "TTHSEC", "name": "Alvar Soome", "avatar": "https://pretalx.com/media/avatars/3M933R_9vdN5ku.webp", "biography": "IT relict, from ancient ages. From Assembly to Python, from developer to CIO. From village to city. From books to AI ... Alvar Intelligence.", "public_name": "Alvar Soome", "guid": "f8a243be-eedd-5f28-9925-544b53fc5931", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/TTHSEC/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/YQZXNJ/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/YQZXNJ/", "attachments": []}, {"guid": "c38d1458-fa71-5397-ac2d-5c1d37c30ce6", "code": "DA8AXB", "id": 103964, "logo": null, "date": "2026-09-25T11:00:00+03:00", "start": "11:00", "end": "2026-09-25T11:45:00+03:00", "duration": "00:45", "room": "Stage A", "slug": "bsides-tallinn-2026-103964-identifying-100-cybercriminals-in-1-hour", "url": "https://pretalx.com/bsides-tallinn-2026/talk/DA8AXB/", "title": "Identifying 100 Cybercriminals In 1 Hour", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "Cybercriminals have become highly effective at weaponizing data stolen from compromised computers. Over the years, an entire underground economy has emerged around infostealers, fueling the trade of stolen credentials, session cookies, and digital identities.\n \nIn this talk, we'll demonstrate how the infostealer ecosystem can be turned against the criminals themselves. By combining publicly available infostealer logs with a simple yet powerful automation pipeline, it becomes possible to identify the very actors who rely on this stolen data to conduct their operations.\n \nWe'll present the methodology and the results of applying it to one of the world's most notorious cybercriminal underground forums. The outcome is striking: over 100 hacker aliases were automatically linked to their underground personas and real-world identities in approximately one hour - an average of one attribution in less than 2 minutes - with virtually no manual effort.\n \nThe session will walk through the technical approach, discuss its limitations and explore what large-scale automated attribution means for threat intelligence, cybercrime investigations, and defenders seeking to understand the adversaries they face.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "D39QMT", "name": "Ago Ambur", "avatar": "https://pretalx.com/media/avatars/TN3ZZH_DBzLDe8.webp", "biography": "Ago is the Co-founder and Chief Operating Officer at Glazer, bringing deep technical expertise in cybercrime and cyber investigations. Ago joined Estonia's National Criminal Police at the age of 19 and went on to lead the Cybercrime Bureau, overseeing advanced technical and intelligence operations. His expertise spans low-level systems engineering, cyber investigations, and applied intelligence, having contributed to several of Estonia's landmark cybercrime investigations.", "public_name": "Ago Ambur", "guid": "516f4563-91a4-51d7-8dd6-0cfdc14f5f6f", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/D39QMT/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/DA8AXB/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/DA8AXB/", "attachments": []}, {"guid": "d3a0302c-a87f-5c5f-81d3-7948a7ab5ebb", "code": "CDEHNZ", "id": 103638, "logo": null, "date": "2026-09-25T13:00:00+03:00", "start": "13:00", "end": "2026-09-25T13:45:00+03:00", "duration": "00:45", "room": "Stage A", "slug": "bsides-tallinn-2026-103638-iranopasmigirim-unmasking-an-ever-evolving-github-hosted-espionage-campaign-against-iranian-dissidents", "url": "https://pretalx.com/bsides-tallinn-2026/talk/CDEHNZ/", "title": "Iranopasmigirim - Unmasking an ever-evolving GitHub-Hosted Espionage Campaign Against Iranian Dissidents", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "What began as routine triage of low-detection malware from MalwareBazaar quickly revealed a full-fledged campaign targeting dissidents, using Custom-built tooling with no meaningful overlap with known malware families, pointing to a dedicated, well-resourced developer rather than a repurposed off-the-shelf toolkit.\n\nThis talk walks through the investigation from that first sample to a fuller picture of the Threat Actor, which has focused on espionage-motivated targeting connected to Iran. We detail the malware's architecture and capabilities, and show how pivoting on code artefacts, unique behavioural fingerprints, and network indicators allowed us to cluster additional, previously unattributed samples under the same actor. \n\nThis talk shows the ever-changing TTPs and Malware being used, from C++-based malware, over Nim and Go, to finally Rust. \n\nAttendees will leave with a concrete case study in threat actor discovery starting from minimal initial evidence, practical pivoting techniques for connecting sparse indicators into a coherent cluster, and a set of detection opportunities and indicators for identifying this activity. This talk is aimed at a broad security audience and requires no prior familiarity with the actor, offering both a compelling investigative narrative and actionable takeaways for threat hunters, analysts, and defenders alike.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "LMC9QL", "name": "Evgen Blohm", "avatar": "https://pretalx.com/media/avatars/PQML9Q_NdEn9o4.webp", "biography": "Evgen Blohm is an experienced DFIR expert who has been involved in responding to a large number of cyber incidents. He is based in Hamburg, Germany and is currently working for InfoGuard AG, where he is also supporting customers with compromise assessments and dark web monitoring.", "public_name": "Evgen Blohm", "guid": "b8a6e559-22ea-5193-9acb-eb4ba100e0fa", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/LMC9QL/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/CDEHNZ/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/CDEHNZ/", "attachments": []}, {"guid": "c5c81668-8e83-5fae-b4ea-ebb7d617bb3c", "code": "EBR3ZH", "id": 103934, "logo": null, "date": "2026-09-25T14:00:00+03:00", "start": "14:00", "end": "2026-09-25T14:45:00+03:00", "duration": "00:45", "room": "Stage A", "slug": "bsides-tallinn-2026-103934-hidden-risks-in-industrial-communications-real-findings-from-a-manufacturing-ot-environment", "url": "https://pretalx.com/bsides-tallinn-2026/talk/EBR3ZH/", "title": "Hidden Risks in Industrial Communications: Real Findings from a Manufacturing OT Environment", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "How do you know the communication your production depends on is actually secure?\nCommunication is everywhere in manufacturing. Controllers, applications, machines and systems constantly talk to each other, but the protocols behind that communication usually do not get much attention. If production keeps running, then everything is fine. Until something goes wrong and protocol vulnerabilities turn into real availability and safety problems like an explosion.\nI wanted to look a little deeper into industrial communication, so I studied a real manufacturing environment and analysed how common protocols like Modbus TCP, OPC DA, OPC UA and MQTT were configured and used in production.\nIn this talk, I will share the most interesting findings, explain why they matter in practice and discuss ways to improve communication security based on IEC 62443. My goal is to help you look at communication in your own OT environment from a different perspective and maybe start asking questions you had not thought to ask before.\n\nThird-party version:\nHow do you know the communication your production depends on is actually secure?\nCommunication is everywhere in manufacturing. Controllers, applications, machines and systems constantly talk to each other, but the protocols behind that communication usually do not get much attention. If production keeps running, then everything is fine. Until something goes wrong and protocol vulnerabilities turn into real availability and safety problems like an explosion.\nThe speaker wanted to look a little deeper into industrial communication, so they studied a real manufacturing environment and analysed how common protocols like Modbus TCP, OPC DA, OPC UA and MQTT were configured and used in production.\nIn this talk, the speaker will share the most interesting findings, explain why they matter in practice and discuss ways to improve communication security based on IEC 62443. The speaker\u2019s goal is to help you look at communication in your own OT environment from a different perspective and maybe start asking questions you had not thought to ask before.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "ZQU3HR", "name": "Vladyslava Shekula", "avatar": "https://pretalx.com/media/avatars/CNWMBL_8Tka84V.webp", "biography": "Hi, my name is Vladyslava. I work as a Cyber Physical Security Consultant in WOTOS. I moved to Estonia about five years ago from Ukraine to study Cyber Security Engineering at TalTech and later continued with the Master's in Cybersecurity, which I completed this year. During my Bachelor's, I worked for more than two years as a DevOps engineer at Playtech. After my Bachelor's, I became interested in OT security and joined my current position. Today, I work with risk assessments, disaster recovery planning, tabletop exercises, business impact assessment, procurement, compliance and I\u2019m also involved in other security projects.", "public_name": "Vladyslava Shekula", "guid": "e8ff250f-52e4-530f-8cd9-6501c24cd969", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/ZQU3HR/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/EBR3ZH/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/EBR3ZH/", "attachments": []}, {"guid": "4ffd744d-9d7a-5c48-bf08-d085cfe118d1", "code": "L3BA3T", "id": 103879, "logo": null, "date": "2026-09-25T15:30:00+03:00", "start": "15:30", "end": "2026-09-25T16:15:00+03:00", "duration": "00:45", "room": "Stage A", "slug": "bsides-tallinn-2026-103879-reporting-vulnerabilities-to-estonian-companies-2026-edition", "url": "https://pretalx.com/bsides-tallinn-2026/talk/L3BA3T/", "title": "Reporting vulnerabilities to Estonian companies - 2026 edition", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "A decade ago I got the cops called on me for kindly telling an Estonian company about a vulnerability on their site. Let's find out if that's still a thing in 2026.\n\nIn this talk I will cover a handful of vulnerabilities I reported to various Estonian companies, how they reacted, and perhaps even what bounties they paid out.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "KNUBSL", "name": "Lyra Rebane", "avatar": "https://pretalx.com/media/avatars/F3KBJ3_RC4jsBb.webp", "biography": "I like to play around with the web and browsers for fun. Sometimes I find bugs. 13 CVEs in Chrome.\nhttps://lyra.horse/blog/", "public_name": "Lyra Rebane", "guid": "a3d31182-5647-5da5-b232-f260aa0cc2e4", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/KNUBSL/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/L3BA3T/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/L3BA3T/", "attachments": []}, {"guid": "d2017c34-e63d-5e04-8809-a63936076a9a", "code": "3G7EGU", "id": 103630, "logo": null, "date": "2026-09-25T16:30:00+03:00", "start": "16:30", "end": "2026-09-25T17:15:00+03:00", "duration": "00:45", "room": "Stage A", "slug": "bsides-tallinn-2026-103630-who-said-the-agent-could-do-that-catching-the-correctly-signed-out-of-mandate-action", "url": "https://pretalx.com/bsides-tallinn-2026/talk/3G7EGU/", "title": "Who Said the Agent Could Do That? Catching the Correctly-Signed, Out-of-Mandate Action", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "Your AI agent holds your keys. Every signature it produces verifies. So who checks that it stayed inside the job you actually gave it?\n\nThis is a live-demo talk with one public sandbox you can attack from your seat.\n\nWe walk the spectrum of machine-checkable legitimacy. BotGuard asks whether a human is at a browser, with no anchor at all. Private Access Tokens (Apple, Cloudflare) ask whether the device is genuine, anchored in hardware. Cloudflare's PACT asks whether the agent is legitimate, again without a hardware anchor. Meanwhile large language models are draining the first moat: the once-esoteric TLS knowledge that made bot-detection bypasses an expert's game - cipher ordering, JA3/JA4 fingerprinting, automation signals - is now a couple of prompts away. The fourth rung asks the question that remains once agents act on their own: what did it do, under whose authority, and was it in mandate? The thesis: the attack surface is migrating from presence to authority.\n\nThe demo is live, on a public MIT-licensed sandbox (github.com/tyche-institute/aep-sandbox). Layer 1 is an unsigned hash chain, and I forge it on stage: a full re-chain passes. That is the deliberate lesson: hashing without anchoring is un-anchored legitimacy in miniature. Layer 2 adds Ed25519-signed Action Evidence Packages (AEPs) bound to a scoped, signed mandate and closes the easy breaks (tamper, key forgery, mandate swap, replay, signature strip), each with its own DENY verdict. Then the headline: an action where every cryptographic check passes and the verifier still returns DENY:scope_violation. Correctly signed, out of mandate, rejected. The agent cannot self-grant authority.\n\nBring a laptop - or just a browser. The same verifier now runs client-side at tyche.institute/lab/aep-ctf/, parity-tested against the Python original on every shipped case, so you can attack it from your seat with nothing installed. For the full kit: Python 3.8+ and pip install cryptography. Seven attack scripts and a CTF judge ship with the repo, plus one standing challenge: craft an evidence package that makes verify.py say ALLOW for an action the mandate does not authorize. My own four-lens pre-publication bypass hunt found no key-free bypass. Prove me wrong, during the talk.\n\n---\n\n## What actually happens on stage\n\nA walk up the four rungs of machine-checkable legitimacy, from \"is there a human?\" to \"was this action in mandate?\", ending on a live break where every signature verifies and the verifier still refuses.\n\n### The shift\nPresence checks are a moat, and AI is draining it. Bot detection asks whether a human is at the browser; hardware attestation raises that to whether the device is genuine; agent-legitimacy schemes ask whether the agent is legitimate. None of them answer what the agent actually did. If presence checks are dying, the question moves up: not who is at the keyboard but what was done, under whose authority, inside which scope. The answer demonstrated here is a per-action evidence package plus a scoped, signed mandate that an offline third party can adjudicate: a mandate-conformance receipt.\n\n### The live demo, exactly\nPublic repo: github.com/tyche-institute/aep-sandbox (MIT, self-contained, runs fully offline; Python 3.8+ and the cryptography package only). In-browser version: tyche.institute/lab/aep-ctf/\n\n- Layer 1 - unsigned SHA-256 hash chain. Catches single-field edits and reorders. A full re-chain forge passes. Deliberate: hashing alone is insufficient, the un-anchored-legitimacy rung in miniature.\n- Layer 2 - Ed25519-signed Action Evidence Package + scoped signed mandate. Trust anchored in listed issuer and agent keys. One appraiser, verify.py, answers ALLOW or DENY:<reason>.\n- Layer 3 - outcome digest folded into a Trusted Platform Module (TPM) quote. Forged outcomes and replays die at tpm2_checkquote. (Emulated swtpm, not a hardware root; I say so on stage.)\n\nThe attack matrix, each with its exact verdict: tamper_field -> DENY:content_mutated \u00b7 forge_rechain -> ledger passes, signed layer DENY:aep_sig_invalid \u00b7 forge_full (attacker keys) -> DENY:issuer_not_listed \u00b7 swap_mandate / strip_sig -> DENY:aep_sig_invalid \u00b7 replay -> first ALLOW, second DENY:replayed \u00b7 and the headline, exceed_scope -> DENY:scope_violation.\n\nThe first six are the easy breaks cryptography already closes. The seventh is the point. \"Faking a mandate\" is really two attacks: forging or escalating the mandate token (crypto catches that) versus acting outside the intent of a genuine mandate (only mandate-conformance checking catches that). Design principle, not magic: the agent must never be the sole and final judge of its own mandate.\n\n### What I got wrong - on purpose, and by accident\nLayer 1 is my own anti-pattern: I shipped an unsigned hash chain precisely so the room can watch a full re-chain forge sail straight through it. The accident is the better story - my own pre-publication bypass hunt caught my verifier throwing a traceback on a non-numeric amount instead of returning a clean DENY: a fail-open shape hiding inside a design I had already called fail-closed. And while building the attestation layer I hit a freshness bug in an open-source RATS verification service; the upstream maintainer acknowledged it and invited the fix. You will see all three.\n\n### Play along (the CTF)\nOpen tyche.institute/lab/aep-ctf/ and attack the verifier in your browser, or clone the repo: python3 verify.py samples/good.aep.json (ALLOW) -> python3 verify.py samples/exceed-scope.aep.json (DENY:scope_violation). Run all seven attacks with make attacks, or go for the win: craft an AEP that makes verify.py return ALLOW for an action the reference mandate does not authorize (a refund over the cap, an issuer outside the trust anchor), drop it at attacks/out/CHALLENGE.aep.json, and let did_you_break_it.py judge you.\n\n### What I am honest about\n- The package proves integrity, authority, and scope offline. Whether a mandate still stands needs a freshness mechanism (short-lived mandates or signed status lists), and I show exactly where that seam sits rather than hand-waving it.\n- If you know IETF RATS (Remote ATtestation procedureS): that attests the platform, not the act-under-mandate. Capability tokens (macaroons, biscuits, UCAN) authorize actions but leave no offline per-action evidence. The piece shown here is the mandate-enforcement layer on a working verifier, evaluated by adversarial breaks.\n- No product, no vendor: everything demonstrated is MIT-licensed and public before the talk.\n\nAudience takeaway: a working mental model for where bot-detection is going and one open-source verifier to break on your own laptop. The sentence to bring home: a correctly-signed action can still be an unauthorized action, and you can catch it.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "WPHKV3", "name": "Anton Sokolov", "avatar": "https://pretalx.com/media/avatars/HWRAHS_zIxi8fV.webp", "biography": "Anton Sokolov is a researcher at Tyche Institute in Tallinn, Estonia, and works as a Public Key Infrastructure engineer. His research focuses on verifiable evidence for AI governance, cryptographic provenance, public-source audit trails, and open infrastructure for accountable AI-agent workflows.", "public_name": "Anton Sokolov", "guid": "9e5329c4-7fc3-5d5c-9896-062c116b4375", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/WPHKV3/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/3G7EGU/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/3G7EGU/", "attachments": []}, {"guid": "51bc2b25-903b-57af-b781-8be482577897", "code": "88YHPJ", "id": 103598, "logo": null, "date": "2026-09-25T17:30:00+03:00", "start": "17:30", "end": "2026-09-25T18:15:00+03:00", "duration": "00:45", "room": "Stage A", "slug": "bsides-tallinn-2026-103598-we-have-mythos-at-home", "url": "https://pretalx.com/bsides-tallinn-2026/talk/88YHPJ/", "title": "We have Mythos at home", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "Bolt's product security team secures applications for over 200 million customers and 4.5 million partners across 600+ cities in 50 countries.\n\nDespite this scale, our request to gain access to Mythos-class models was left on read. So we decided to build our own tooling around models we already had to figure out whether we should feel scared or empowered due to the rise of AI-powered vulnerability finders.\n\nThis talk is a story of what happens when you duct-tape \"good enough\" models into a security reviewer for a codebase serving more than 5 billion requests per day. We will share our experience of building layers  of deterministic scaffolding and multi-agent cross-checking to keep the TP to FP ratio under control.\n\n**Attendees will gain insights into:**\n* **Architecture on a budget:** Why \"deterministic pipeline first, LLM last\" beats throwing a whole codebase at a model and praying.\n* **Multi-agent QA:** How worker agents plus a validator agent cut false positives, assign vibes-based severity ratings and where that pattern still falls apart.\n* **Wins and misses:** Concrete findings our tool caught that humans missed - and why vice versa might not matter.\n* **Prompting for security:** Why narrow, focused scopes produce accurate findings and generic \"find the vulns\" prompts produce finding-shaped garbage.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "WR7MJV", "name": "Andres J\u00f5gi", "avatar": "https://pretalx.com/media/avatars/YFL3M8_HIseQ2N.webp", "biography": "Product Security Manager @ Bolt\nApplies Chekhov\u2019s Gun to cybersecurity: \"If an alert or a tool doesn't serve a clear purpose, it\u2019s just noise, use it or cut it.\"", "public_name": "Andres J\u00f5gi", "guid": "32740301-435a-53ed-b627-f4009955db5e", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/WR7MJV/"}, {"code": "3AUNGN", "name": "Dadash", "avatar": "https://pretalx.com/media/avatars/BQ83Y3_JFz4K8I.webp", "biography": "Product Security Engineer @ Bolt. Interested in web, mobile and API security, with a growing interest in AI-assisted vulnerability discovery. Building tooling to make security faster, reliable and available to everyone.", "public_name": "Dadash", "guid": "d295d9d5-85ca-5aca-b5e0-6106dcbb820f", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/3AUNGN/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/88YHPJ/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/88YHPJ/", "attachments": []}], "Stage B": [{"guid": "90cb23bf-faf9-56ed-837c-735af0bc33b1", "code": "VVKWCX", "id": 103613, "logo": null, "date": "2026-09-25T11:00:00+03:00", "start": "11:00", "end": "2026-09-25T11:45:00+03:00", "duration": "00:45", "room": "Stage B", "slug": "bsides-tallinn-2026-103613-detection-in-technicolour-finding-the-gaps-your-dashboard-cannot-see", "url": "https://pretalx.com/bsides-tallinn-2026/talk/VVKWCX/", "title": "Detection in Technicolour: Finding the Gaps Your Dashboard Cannot See", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "Security teams measure what their detection systems produce: alerts, incidents, false positives, response times, and technique coverage. These metrics are useful, but they describe only what became visible. They tell us much less about telemetry that was never generated, never collected, rejected during parsing, stripped of context during normalization, or delivered too late to support a detection.\n\nDashboards make this limitation easy to overlook. They show ingestion rates, parser success, rule activity, and correlation volume in reassuring colour. Yet a high parse-success rate excludes anything rejected before the parser recorded it. Low ingestion latency does not tell us whether the right events were collected. A rule that fires regularly may be healthy, or it may simply be seeing the small part of the environment that still produces usable evidence. We often use measures of pipeline activity as evidence of detection coverage.\n\nEvery detection system works within a blindness budget. Collection capacity is finite. Parsing accuracy requires engineering effort. Longer retention consumes storage that might otherwise support faster access or broader collection. Near-real-time detection often acts on incomplete evidence. Correlation depends on fields retaining stable meaning after they have passed through several systems. A decision that appears reasonable at one stage can remove options from the next, with no visible failure until a detection is missed.\n\nThis talk follows security telemetry through a production SIEM stack, from generation and collection to parsing, normalization, storage, correlation, hunting, and detection. It brings together three views that are usually discussed separately: the architect deciding where state, trust, and failure boundaries belong; the developer implementing the pipeline and its instrumentation; and the detection engineer depending on that pipeline to preserve enough evidence for a rule to work. Looking at the same system from all three perspectives exposes failures that remain hidden when each layer is assessed in isolation.\n\nMissing telemetry is only one part of the problem. Analysts adapt to the alert streams they receive. When false positives and repetitive alerts dominate, dismissal becomes a rational response to limited attention. Rules continue to fire, but trust declines. Investigations become shallower, and alerts remain open without meaningful action. Too little evidence and too much noise reach the same operational result through different mechanisms.\n\nThe talk uses six working categories for examining missed detections: collection gaps, parsing gaps, data-quality failures, semantic loss, correlation failures, and detections that never received enough evidence to fire. The boundaries are not always clean. A malformed event may appear to be a parsing problem, a schema problem, or a collection problem depending on where measurement begins. The useful question is not which label fits best, but where the evidence disappeared and whether the pipeline can demonstrate that it was present.\n\nAttendees will see how to assess telemetry freshness, parser health, schema completeness, ingestion delay, correlation readiness, unknown-event rates, rule dependencies, orphaned rules, and signs of analyst fatigue. These measurements do not produce a complete account of detection quality, but they expose failures that conventional SOC dashboards usually hide.\n\nThe question is not whether the pipeline is active. It is whether enough of the right evidence survives the pipeline to detect anything that matters.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "WKVMJW", "name": "Zafer Balkan", "avatar": "https://pretalx.com/media/avatars/MWJ9QN_eVJZDq9.webp", "biography": "Zafer Balkan is a cybersecurity, compliance, and IT operations professional based in Tallinn, Estonia. His work spans security governance, infrastructure security, business continuity, risk management, defensive operations, and practical security engineering. He currently works as Security and Compliance Manager at Nets Estonia, part of Nexi Group, where he supports IT security and compliance decision-making, risk assessment, business impact analysis, business continuity and disaster recovery planning, internal audits, security control implementation, vulnerability analysis, and pentesting coordination in the finance/payment-services sector. \n\nBefore moving into finance-sector security and compliance, Zafer built a substantial technical and operational background in NATO and defense environments. His earlier roles covered IT management, communication and information systems security, systems and network administration, blue-team operations, IAM across internet-connected and air-gapped networks, SIEM/EDR environments, security appliances, virtualization, backup, disaster recovery, and secure software practices.", "public_name": "Zafer Balkan", "guid": "165e7d44-0762-5213-8c4d-7e146e82e2f3", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/WKVMJW/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/VVKWCX/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/VVKWCX/", "attachments": []}, {"guid": "41bbdeaa-c34d-52af-8902-a17a60cc0f89", "code": "QXGUCZ", "id": 103904, "logo": null, "date": "2026-09-25T13:00:00+03:00", "start": "13:00", "end": "2026-09-25T13:45:00+03:00", "duration": "00:45", "room": "Stage B", "slug": "bsides-tallinn-2026-103904-every-path-counts-when-defenders-learn-to-think-in-graphs", "url": "https://pretalx.com/bsides-tallinn-2026/talk/QXGUCZ/", "title": "Every Path Counts: When Defenders Learn to Think in Graphs", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "Last year, in Every Step Counts, I showed how to measure detection of individual attacker steps, one technique at a time. It's how most blue teams work: can I detect this; can I detect that. But real intrusions are not isolated steps. They are paths, and attackers walk them by chaining identities, privileges, and trust. This talk asks a more ambitious question: can we simulate how an adversary would move through an environment and predict the identity attack paths they would take across Active Directory and cloud before they take them?\n\nThis is where graphs change the game. When you model an environment as a graph, identities, hosts, and privileges become nodes, and the permissions and trust relationships between them become edges. Attackers have always seen the world this way; this session is about defenders learning to see it too. We'll walk through how attack paths form, how to read them, and how to find the choke points where cutting a single edge collapses dozens of paths at once.\n\nFrom there we turn insight into action. You'll leave knowing how to map your own Active Directory and cloud estate, surface the paths hiding inside it, identify the few choke points that matter so you can fix less and prevent more, and prioritise remediation by real impact instead of working down an endless list of findings. Best of all, it's built on open tooling you can run yourself, so the whole approach travels home with you and works against the environment you already have.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "PMA7BX", "name": "Jarkko Kinnunen", "avatar": "https://pretalx.com/media/avatars/CK8GEB_wyFisXy.webp", "biography": "Jarkko Kinnunen is a Security Solution Engineer at Microsoft and Co-Founder of KuoSec community. A passionate advocate for the Blue Team, he specializes in developing continuous security services and enhancing SOC operations. By day, he advises companies and partners on designing and implementing solutions built on Microsoft security technologies. After working hours, he loves helping the community to do stuff...", "public_name": "Jarkko Kinnunen", "guid": "38821019-4a54-53e0-a509-d61a6e3a0592", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/PMA7BX/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/QXGUCZ/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/QXGUCZ/", "attachments": []}, {"guid": "9996f3b9-32ae-5162-8392-7189880cde37", "code": "A79GBX", "id": 103549, "logo": null, "date": "2026-09-25T14:00:00+03:00", "start": "14:00", "end": "2026-09-25T14:45:00+03:00", "duration": "00:45", "room": "Stage B", "slug": "bsides-tallinn-2026-103549-deconstructing-modern-macos-initial-access-vectors", "url": "https://pretalx.com/bsides-tallinn-2026/talk/A79GBX/", "title": "Deconstructing Modern macOS Initial Access Vectors", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware.\n\nWe will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). Finally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).\n\nAttendees will walk away with a technical understanding of contemporary macOS tradecraft, real-world attacker methodologies, and the insights needed to hunt for and defend against modern Mac-focused threats.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "JJSUWM", "name": "Stephan Berger", "avatar": "https://pretalx.com/media/avatars/C7AHN8_ik6J5wJ.webp", "biography": "Stephan Berger has over a decade of experience in cybersecurity. Currently working with the Swiss-based company InfoGuard, Stephan investigates breaches and hacked networks as Head of Investigation of the Incident Response team. An avid Twitter user under the handle @malmoeb, he actively shares insights on cybersecurity trends and developments. Stephan also authors the blog DFIR.ch, where he provides in-depth analysis and commentary on digital forensics and incident response. Stephan has spoken at numerous conferences, sharing his expertise with audiences worldwide.", "public_name": "Stephan Berger", "guid": "7cac3538-c233-5dbc-939e-274b67e36e27", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/JJSUWM/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/A79GBX/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/A79GBX/", "attachments": []}, {"guid": "0f7143d2-748a-5f1d-9c23-e51a0e9e085a", "code": "VAGAWE", "id": 103966, "logo": null, "date": "2026-09-25T15:30:00+03:00", "start": "15:30", "end": "2026-09-25T16:15:00+03:00", "duration": "00:45", "room": "Stage B", "slug": "bsides-tallinn-2026-103966-language-matters", "url": "https://pretalx.com/bsides-tallinn-2026/talk/VAGAWE/", "title": "Language Matters", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "Technology is a coy field: what happens on machine level is almost never what happens in the eyes of the end-user, so far are they detached. One must trust what the wizard in between claims to be happening, unfortunately therefore having to put all trust in said wizard. \n\nWith the advent and popularisation of LLMs, the masses of people who seemingly \u201cgain knowledge\u201d or \u201caccess\u201d to machines has risen rapidly. This poses several threats in itself, but my research focuses mainly on how culture, specifically words and language, influence how we perceive and use technology, and why most of the tech world today is taken hostage by a handful of American software companies (Anthropic, OpenAI etc). \n\nMy talk focuses on these core topics and findings: \n> The Use of Anthropomorphisation in Marketing and UX language of large language models (why it\u2019s bad and how to fight it) i.e \u201cyour model does not hallucinate, it\u2019s just wrong\u201d\n> The permeation of cultural myths in the perception and utilisation of technology (or how the Bible, the Odyssey and James Cameron affect how large-scale security decisions are made incl. on government and military level)\n> who benefits and who\u2019s at risk from these misuses (and deceptions), and why it affects the security community so heavily (couple real-life examples and case studies)\n\nFindings include: \n- comparison of how varying cultures explain and utilise frontier technologies (i.e can there be AI apocalypse, if your culture does not know apocalypse) \n- examples of how marketing language affects real security decisions (the holy triad of CEOs, CISOs and Mythos) \n- practical thoughts on how the security community can fight back", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "8BDQDL", "name": "Siret Schutting", "avatar": "https://pretalx.com/media/avatars/97W9NP_t9wZDTR.webp", "biography": "Siret is an information security and strategic communication expert and researcher, focusing on cognitive security, frontier technologies, defence and space (particularly LEO). She teaches information security and risk management at Tartu University, trains teams and organisations in cyberhygiene and resilience and consults companies on implementing infosec management systems. She is the founder & CEO of Digital Round Table, a think tank focused on security research, international infosec collaboration and technology education.", "public_name": "Siret Schutting", "guid": "beb15de8-42ff-53c8-928c-956e86f39b74", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/8BDQDL/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/VAGAWE/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/VAGAWE/", "attachments": []}, {"guid": "0a64febb-0cc3-5995-8d6c-af0d0f2f7089", "code": "SEYK7L", "id": 103996, "logo": null, "date": "2026-09-25T16:30:00+03:00", "start": "16:30", "end": "2026-09-25T17:15:00+03:00", "duration": "00:45", "room": "Stage B", "slug": "bsides-tallinn-2026-103996-beyond-the-narrative-mapping-the-hidden-infrastructure-of-information-warfare", "url": "https://pretalx.com/bsides-tallinn-2026/talk/SEYK7L/", "title": "Beyond the Narrative: Mapping the Hidden Infrastructure of Information Warfare", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "Information warfare is usually examined through its visible outputs, including fabricated stories, coordinated accounts, bot networks and manipulated audiences, but every campaign also depends on a quieter technical layer that receives far less scrutiny. Developers, data systems, monitoring platforms and institutional relationships make influence operations scalable, measurable and sustainable over time.\nThis talk presents an investigation into that hidden layer. Starting with a small collection of fragmented indicators, we followed traces across professional profiles, source code repositories, conference appearances, corporate records, procurement data and employment history. Although each signal appeared ordinary in isolation, their combined pattern revealed a previously undocumented relationship between software engineering, regional monitoring infrastructure and a state-linked influence ecosystem.\nRather than focusing only on a single attribution, the session follows real life case study and shows the investigative flow by moving from weak signals to defensible hypotheses, correlating technical capabilities with operational requirements, separating confirmed relationships from circumstantial inference and communicating conclusions without overstating certainty. It also examines the complications that frequently appear in this type of research, including public-facing professional identities, opaque subcontracting arrangements, misleading corporate footprints and records that do not align cleanly across time.\nThe broader lesson is that countering information warfare requires more than identifying false narratives after they begin to spread. Defenders must also understand the infrastructure, labour, organisations and supply chains that support these operations. When propaganda networks are treated as security systems with developers, dependencies, dashboards, data flows and operational weaknesses, investigators can apply many of the same techniques already used in threat intelligence and incident response.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "THPAWQ", "name": "Oskar Gross", "avatar": "https://pretalx.com/media/avatars/SBATNH_RtCd03e.webp", "biography": "Oskar Gross is the CEO of Glazer Technologies and a former criminal police officer. He joined the National Criminal Police in late 2015 to establish the Cybercrime Bureau, focusing on cybercrime intelligence and investigations. The unit investigated several major cross-border cases, including the \u20ac577 million HashFlare fraud case. In 2023, Oskar was appointed Head of the Estonian National Criminal Police, leaving the role in 2024 when he relocated to Brussels. He holds a PhD in computer science from the University of Helsinki.", "public_name": "Oskar Gross", "guid": "431a6194-05f3-5862-8c3e-f7bb9a4ca75a", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/THPAWQ/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/SEYK7L/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/SEYK7L/", "attachments": []}, {"guid": "7e7bb36c-d22f-500d-bd28-7900f13753de", "code": "88LUCH", "id": 103846, "logo": null, "date": "2026-09-25T17:30:00+03:00", "start": "17:30", "end": "2026-09-25T18:15:00+03:00", "duration": "00:45", "room": "Stage B", "slug": "bsides-tallinn-2026-103846-nobody-monitors-the-monitor-chaos-engineering-for-the-security-team-s-own-infrastructure", "url": "https://pretalx.com/bsides-tallinn-2026/talk/88LUCH/", "title": "Nobody monitors the monitor: Chaos engineering for the security team's own infrastructure", "subtitle": "", "track": "Talk", "type": "Main track 25.09.2026", "language": "en", "abstract": "We ask a lot of questions about other people's infrastructure resilience. Turns out we'd never asked them about our own.\n\nThis is the story of what happened when security team finally did. We sat down to write a Business Continuity Plan for our security monitoring platform \u2014 a SIEM ingesting 60+ log sources, running detections across infrastructure serving millions of users across 50 countries \u2014 and discovered that \"untested\" covers a lot more ground than we'd assumed. \n\nSome failure modes were obvious. The interesting ones weren't: the silent degradation scenario where the platform stays technically up but detection rules quietly stop running and no alert fires; the compounding case where a routine outage overlaps with an active incident and your tolerable downtime drops from days to hours; the log volume spike that leaves you triaging a live attack with an increasingly incomplete picture \u2014 and no indication that the picture is incomplete.\n\nAttendees will leave with:\n\n- Why your SIEM needs a BIA, not just an SLA. The difference between \"it should recover in 4 hours\" and \"here's what breaks if it doesn't.\"\n- The failure scenarios that don't look like failures. Silent degradation and partial log loss are harder to detect - and more dangerous - than a clean outage.\n- A chaos test list for security infrastructure. What to test and what we found when we actually ran pieces of it.", "description": null, "recording_license": "", "do_not_record": false, "persons": [{"code": "RM8KY7", "name": "Iuliia Laaneots", "avatar": "https://pretalx.com/media/avatars/VYWSGV_YUTLHFS.webp", "biography": "Iuliia is a Cloud Security Manager at Bolt. Official title: keeps the infrastructure safe. Unofficial title: professional worst-case-scenario imaginer.", "public_name": "Iuliia Laaneots", "guid": "73224279-f70a-551e-a15d-0fe54cd40364", "url": "https://pretalx.com/bsides-tallinn-2026/speaker/RM8KY7/"}], "links": [], "feedback_url": "https://pretalx.com/bsides-tallinn-2026/talk/88LUCH/feedback/", "origin_url": "https://pretalx.com/bsides-tallinn-2026/talk/88LUCH/", "attachments": []}]}}]}}}