<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.3.0.dev0. -->
<schedule>
    <generator name="pretalx" system="pretalx.com" version="2026.3.0.dev0" />
    <version>0.13</version>
    <conference>
        <title>BSides Tallinn 2026</title>
        <acronym>bsides-tallinn-2026</acronym>
        <start>2026-09-24</start>
        <end>2026-09-25</end>
        <days>2</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://pretalx.com</base_url>
        
        <time_zone_name>Europe/Helsinki</time_zone_name>
        
        
        <track name="VILLAGE" slug="7242-village"  color="#00ccff" />
        
        <track name="Talk" slug="7244-talk"  color="#0000f0" />
        
        <track name="Workshop" slug="7245-workshop"  color="#1bb845" />
        
    </conference>
    <day index='1' date='2026-09-24' start='2026-09-24T04:00:00+03:00' end='2026-09-25T03:59:00+03:00'>
        <room name='Office 6' guid='3d9adb21-5c90-5a74-88d9-c4bf48d47c5f'>
            <event guid='316b0fac-8da3-5dd2-90b5-ad48a18acd0e' id='104039' code='FRBPMV'>
                <room>Office 6</room>
                <title>PLC unplugged (09:30, 11:15)</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-24T09:30:00+03:00</date>
                <start>09:30</start>
                <duration>03:30</duration>
                <abstract>Sign-up form 9:30-11:00: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSdOjY6rFN2ZInDlhhISxCVzdPxOKuT_C_PicJ-Tbg_T827qPg/viewform?usp=sharing&amp;ouid=104367224945762059530)
Sign-up form 11:15-12:45: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSfQToAcJ78Q2r57PzQt85G8zBkdu1aG4OJn7LEelwatuaqZFw/viewform?usp=sharing&amp;ouid=104367224945762059530)

Programmable Logic Controllers (PLCs) are field-level devices in OT/ICS/SCADA systems that read sensors, execute logic and drive real machinery. Compromise a PLC and you can overspeed a pump, slam a valve shut or make a safety interlock ignore a fault.

In this workshop you will hunt down and exploit 5 security issues straight out of real-world PLC deployments.

Requirement: Laptop with Wi-Fi and Ubuntu 24.04 VM (amd64/arm64).</abstract>
                <slug>bsides-tallinn-2026-104039-plc-unplugged-09-30-11-15</slug>
                <track>Workshop</track>
                
                <persons>
                    <person id='97248'>Mait Peekma</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/FRBPMV/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='7b1e8973-531d-5391-bb09-bfd5420fd444' id='103552' code='PKPUQY'>
                <room>Office 6</room>
                <title>Anti-Forensics (and Anti-Anti-Forensics) Techniques for Incident Responders (ALL SPOTS FULL)</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-24T14:00:00+03:00</date>
                <start>14:00</start>
                <duration>04:00</duration>
                <abstract>Sign-up form: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSflrNlvBgEhynGyZiMNxAOgZrIG98CO1ViXK0M9v9ovC-JORQ/viewform?usp=sharing&amp;ouid=104367224945762059530)

A full-spectrum dive into anti-forensics across Windows and Linux (with a tad of MacOS, if time permits), centered on real incidents and modern attacker behavior. The course walks through classic log wiping, deeper filesystem tricks, PowerShell, timestomping, sandbox artifacts, memory-only execution, endpoint solution blind spots, and advanced Linux log manipulation.

Each technique is paired with detection logic, weaknesses in attacker tradecraft, and practical forensic recovery paths. The material emphasizes hands-on analysis, including MFT/MSRUM/USN artifacts, ETW traces, VHDX extraction, /proc-based investigation, and highlights new research and tooling that shape current offensive and defensive strategies.

This is an excerpt from my full 2-3 day training I offer under my brand malmium.com (https://malmium.com/training-anti-forensics.html)</abstract>
                <slug>bsides-tallinn-2026-103552-anti-forensics-and-anti-anti-forensics-techniques-for-incident-responders-all-spots-full</slug>
                <track>Workshop</track>
                
                <persons>
                    <person id='102622'>Stephan Berger</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/PKPUQY/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='MUSE 9:30-15:00' guid='7bc4a63a-282c-58ed-bcf6-a42bd3415f88'>
            <event guid='85dd4670-93fb-589c-9e8e-920715c6afd5' id='103402' code='LSPSQU'>
                <room>MUSE 9:30-15:00</room>
                <title>Inside Scattered Spider: A Red vs. Blue Breach &amp; Attack Simulation</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-24T09:30:00+03:00</date>
                <start>09:30</start>
                <duration>03:00</duration>
                <abstract>Sign-up form: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSfyDWjKYOrV0mHxXlkwjWINIIqRIC_2qKlu75dg7OjY4pYBSA/viewform?usp=sharing&amp;ouid=104367224945762059530)

Scattered Spider redefined modern ransomware operations through sophisticated social engineering, privilege escalation, and rapid domain-wide compromise. In this immersive workshop, participants experience the attack from both perspectives: first as the attacker, then as the defender.

Working through a realistic breach simulation, you&apos;ll execute key phases of the attack before switching roles to detect, investigate, and respond using modern detection and endpoint security capabilities. By the end of the workshop, you&apos;ll understand not only how the attack works, but why defenders succeed, or fail, at each stage.

You&apos;ll learn:

How Scattered Spider gains initial access and escalates privileges.
How to detect and investigate each stage of the attack.
Where traditional defenses fall short.
How modern security operations and AI-assisted investigation can reduce time to detection and response.</abstract>
                <slug>bsides-tallinn-2026-103402-inside-scattered-spider-a-red-vs-blue-breach-attack-simulation</slug>
                <track>Workshop</track>
                
                <persons>
                    <person id='102159'>Marvin Ngoma</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/LSPSQU/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Workshop room (LD1) 9:30-15:00' guid='8eb16a4e-7978-51db-a163-3328061bab41'>
            <event guid='4896c361-8212-5229-9424-d3ae3b6c8219' id='103910' code='TMCQPB'>
                <room>Workshop room (LD1) 9:30-15:00</room>
                <title>Gotta Contain &apos;Em All: Collaborative Incident Response Training Through Gaming</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-24T09:30:00+03:00</date>
                <start>09:30</start>
                <duration>02:00</duration>
                <abstract>Sign-up form: [**Google forms**](https://docs.google.com/forms/d/e/1FAIpQLSdtdi-PcGMdEWRj0-EARLu4UMCQt_2hxAyRkJkJ6R_Oe_LyFw/viewform?usp=sharing&amp;ouid=104367224945762059530)

Incident response isn&apos;t just about knowing your tools - it&apos;s about coordinating under pressure, communicating when things go sideways, and making calls with incomplete information. Traditional training focuses on isolated techniques, missing the collaborative reality of actual incidents. And most tabletop exercises? Painfully dull. Participants zone out, give checkbox answers, and leave having learned little.

This workshop introduces Malware &amp; Monsters (https://malwareandmonsters.com), a framework that turns IR training into something people actually enjoy. Think tabletop role-playing meets creature-collection mechanics, where teams &quot;hunt and contain&quot; digital threats through story-driven gameplay.
Game-based learning works - research shows it beats traditional instruction for skill building and retention. M&amp;M makes participants actively discover concepts instead of sitting through lectures. Scenarios include organizational pressures, evolving threats, and stakeholder drama, turning abstract security concepts into tangible problems.

You&apos;ll experience the full methodology: learn the mechanics, build custom scenarios based on real malware families (mapped to MITRE ATT&amp;CK), and run live simulations. Participants take specialized roles - Hunter, Analyst, Forensicator, Communicator, Coordinator, or Researcher - experiencing how security functions actually collaborate during incidents.

The framework includes legacy malmons from malware history&#8212;because history always repeats itself, and understanding past threats reveals patterns in current attacks. The &quot;type effectiveness&quot; system teaches strategic thinking about matching defenses to threats. Evolution mechanics show how attacks escalate when containment fails.

Participants walk away with ready-to-use materials and facilitation techniques for training that actually works.

Best of all? M&amp;M is free to play in most cases.</abstract>
                <slug>bsides-tallinn-2026-103910-gotta-contain-em-all-collaborative-incident-response-training-through-gaming</slug>
                <track>Workshop</track>
                
                <persons>
                    <person id='102962'>Klaus Agnoletti</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/TMCQPB/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='7b0e9b5b-4f68-5046-abfa-1250c165aae7' id='102781' code='9MPHHC'>
                <room>Workshop room (LD1) 9:30-15:00</room>
                <title>Mastering Bash for Hackers: Extreme Command-Line Power</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-24T12:00:00+03:00</date>
                <start>12:00</start>
                <duration>02:00</duration>
                <abstract>Sign-up form: [**Google form**](https://docs.google.com/forms/d/e/1FAIpQLSc7YHDN0zuZxnWsWdCvDJAFC_SVsdjSal6T0uwqr-6cUIUKBA/viewform?usp=sharing&amp;ouid=104367224945762059530)

Bash isn&#8217;t just an interface to your daily laptop - it&#8217;s a weapon. In this hands-on workshop, we&#8217;ll push bash beyond its typical use, leveraging it for hacking, data processing, automation, and real-world security applications. Whether you&#8217;re crafting exploits, analyzing massive datasets, or automating reconnaissance, this session will equip you with the skills to turn bash into your ultimate hacking tool.

- Master advanced bash scripting techniques for automation, and hacking.
- Process terabytes of leaked password data and uncover real-world security insights.
- Use bash to manipulate and extract intelligence from logs, network traffic, and system artifacts.
- Generate graphs, automate reports, and convert file format entirely from the command line.
- Learn how to replace GUI-based tools with bash scripts for speed and stealth.

By the end of this workshop, you&#8217;ll be able to:
- Automate and accelerate security tasks with powerful one-liners and scripts.
- Use bash to analyze, manipulate, and exploit data in security research.
- Apply bash in unconventional ways, from image processing to document forensics.</abstract>
                <slug>bsides-tallinn-2026-102781-mastering-bash-for-hackers-extreme-command-line-power</slug>
                <track>Workshop</track>
                
                <persons>
                    <person id='101814'>Kirils Solovjovs</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/9MPHHC/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Workshop room (LD2)' guid='9bb658cf-0326-5fa2-908a-d1d8c1868e56'>
            <event guid='95bbb87d-79e2-5c85-9978-66852206101e' id='103808' code='7BLJ9P'>
                <room>Workshop room (LD2)</room>
                <title>Wifi Discovery and monitoring 101 primarily with Kismet</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-24T09:30:00+03:00</date>
                <start>09:30</start>
                <duration>02:00</duration>
                <abstract>Sign-up form: [**Google form**](https://docs.google.com/forms/d/e/1FAIpQLSdLBMX6Vri_5y7ayR_Nl5U9FA3KniNe-m3h7InRaFvGq2hePA/viewform?usp=sharing&amp;ouid=104367224945762059530)

A practical two-hour workshop for up to 18 participants working in nine pairs.

Explore Wi-Fi and Bluetooth activity around you: what can be seen, what cannot, and why. Participants will use Kismet to discover nearby wireless networks and devices, then interpret the results in context.

The workshop covers:
An introduction to Wi-Fi and Bluetooth discovery: scanning vs. passive monitoring
How channels, monitor mode, signal range, and hardware affect device visibility
A practical introduction to Kismet and its core capabilities
Guided testing with organizer-provided Wi-Fi devices
Observing how device interactions appear in Kismet

Participants will leave to be  able  better understand and interpret the wireless environment around them.

Please bring a laptop with VirtualBox installed and Ethernet capability (or a suitable adapter). The organizer will provide nine USB/USB-C 802.11ax Wi-Fi adapters, one per pair.

Bringing your own compatible Wi-Fi or Bluetooth hardware is encouraged. This may also allow additional participants to take part if all adapter places are filled. Please ask the instructor in advance if you would like to confirm whether your hardware is suitable.

All active testing is limited to organizer-provided devices in the workshop environment</abstract>
                <slug>bsides-tallinn-2026-103808-wifi-discovery-and-monitoring-101-primarily-with-kismet</slug>
                <track>Workshop</track>
                
                <persons>
                    <person id='102868'>Toomas Lepik</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/7BLJ9P/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='0cc64fb7-d33f-5be3-87a5-f40a256a223d' id='103986' code='L9BSJD'>
                <room>Workshop room (LD2)</room>
                <title>HAM radio workshop and exam (ALL SPOTS FULL)</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-24T12:00:00+03:00</date>
                <start>12:00</start>
                <duration>01:30</duration>
                <abstract>Sign-up form: [**Google form**](https://docs.google.com/forms/d/e/1FAIpQLSeMYQwT8ww8Tig3xwbBRT-KkxjSRlQrft9ntquQrqhuvqBAZA/viewform?usp=sharing&amp;ouid=104367224945762059530)

Becoming amateur radio operator is not that hard, specially if you come from techie background. Workshop will cover basics needed to get certified as class D (entry-level) amateur radio operator, from physics to law to communication protocols, equipment and community.

If you feel ready - perhaps [having studied](https://es1tp.github.io/comms-parent/#/public/et) and [tried answering exam questions](https://es1tp.github.io/comms-parent/#/public/et/pages/qualification/products/D-%20kvalifikatsiooniklass/offers/qualification_cat_d_et_qualification_D) - you can pass both practical and theoretical part of exam during BSides Tallinn.

Workshop is planned together with village on 25th - so participants can get an intro course to amateur radio, do first communication tests and take amateur radio operator&apos;s exam on-site (class D), like in famous DEFCON https://defcon.social/@HamRadioVillage.

Village, workshop and exams are organized by Radio Network Committe of Eesti Raadioamat&#246;&#246;ride &#220;hing (https://eesti-raadioamatooride-uhing.github.io/raadiosidevorkude-toimkond/) having goal of building and maintaining repeaters, IP and radio networks, digital systems, and cybersecurity.</abstract>
                <slug>bsides-tallinn-2026-103986-ham-radio-workshop-and-exam-all-spots-full</slug>
                <track>Workshop</track>
                
                <persons>
                    <person id='103022'>Peeter Marvet</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/L9BSJD/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        
    </day>
    <day index='2' date='2026-09-25' start='2026-09-25T04:00:00+03:00' end='2026-09-26T03:59:00+03:00'>
        <room name='Stage A' guid='273887fa-13b0-52b2-8555-0f3780775535'>
            <event guid='19d6532d-f9ca-5645-919c-ea0d6f9f4e67' id='104664' code='YQZXNJ'>
                <room>Stage A</room>
                <title>KEYNOTE by Alvar Soome &quot;How to eat a wooden carrot&quot;</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T10:00:00+03:00</date>
                <start>10:00</start>
                <duration>00:45</duration>
                <abstract>When we look around, we see that Estonia is doing amazing things, building fantastic systems and leading IT innovation all over the world. Public WIFI is even in bogs and all children learn how to program already in kindergarden. This is what we sell. But what is the actual reality behind the curtains. 

How we order wooden carrots and wonder why they aren&apos;t edible? 
How is it possible that simple database modification takes one year? 
What is &quot;IT disaster formula&quot; in IT sector and how can we solve it? Can we? 
Why smart people with great ideas tend to vanish from public sector? Hopefully before burnout! And what do we mean, when we say that this is &quot;security circus&quot; and who let the clowns out?</abstract>
                <slug>bsides-tallinn-2026-104664-keynote-by-alvar-soome-how-to-eat-a-wooden-carrot</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='103723'>Alvar Soome</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/YQZXNJ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='c38d1458-fa71-5397-ac2d-5c1d37c30ce6' id='103964' code='DA8AXB'>
                <room>Stage A</room>
                <title>Identifying 100 Cybercriminals In 1 Hour</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T11:00:00+03:00</date>
                <start>11:00</start>
                <duration>00:45</duration>
                <abstract>Cybercriminals have become highly effective at weaponizing data stolen from compromised computers. Over the years, an entire underground economy has emerged around infostealers, fueling the trade of stolen credentials, session cookies, and digital identities.
 
In this talk, we&apos;ll demonstrate how the infostealer ecosystem can be turned against the criminals themselves. By combining publicly available infostealer logs with a simple yet powerful automation pipeline, it becomes possible to identify the very actors who rely on this stolen data to conduct their operations.
 
We&apos;ll present the methodology and the results of applying it to one of the world&apos;s most notorious cybercriminal underground forums. The outcome is striking: over 100 hacker aliases were automatically linked to their underground personas and real-world identities in approximately one hour - an average of one attribution in less than 2 minutes - with virtually no manual effort.
 
The session will walk through the technical approach, discuss its limitations and explore what large-scale automated attribution means for threat intelligence, cybercrime investigations, and defenders seeking to understand the adversaries they face.</abstract>
                <slug>bsides-tallinn-2026-103964-identifying-100-cybercriminals-in-1-hour</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102999'>Ago Ambur</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/DA8AXB/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d3a0302c-a87f-5c5f-81d3-7948a7ab5ebb' id='103638' code='CDEHNZ'>
                <room>Stage A</room>
                <title>Iranopasmigirim - Unmasking an ever-evolving GitHub-Hosted Espionage Campaign Against Iranian Dissidents</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T13:00:00+03:00</date>
                <start>13:00</start>
                <duration>00:45</duration>
                <abstract>What began as routine triage of low-detection malware from MalwareBazaar quickly revealed a full-fledged campaign targeting dissidents, using Custom-built tooling with no meaningful overlap with known malware families, pointing to a dedicated, well-resourced developer rather than a repurposed off-the-shelf toolkit.

This talk walks through the investigation from that first sample to a fuller picture of the Threat Actor, which has focused on espionage-motivated targeting connected to Iran. We detail the malware&apos;s architecture and capabilities, and show how pivoting on code artefacts, unique behavioural fingerprints, and network indicators allowed us to cluster additional, previously unattributed samples under the same actor. 

This talk shows the ever-changing TTPs and Malware being used, from C++-based malware, over Nim and Go, to finally Rust. 

Attendees will leave with a concrete case study in threat actor discovery starting from minimal initial evidence, practical pivoting techniques for connecting sparse indicators into a coherent cluster, and a set of detection opportunities and indicators for identifying this activity. This talk is aimed at a broad security audience and requires no prior familiarity with the actor, offering both a compelling investigative narrative and actionable takeaways for threat hunters, analysts, and defenders alike.</abstract>
                <slug>bsides-tallinn-2026-103638-iranopasmigirim-unmasking-an-ever-evolving-github-hosted-espionage-campaign-against-iranian-dissidents</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102703'>Evgen Blohm</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/CDEHNZ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='c5c81668-8e83-5fae-b4ea-ebb7d617bb3c' id='103934' code='EBR3ZH'>
                <room>Stage A</room>
                <title>Hidden Risks in Industrial Communications: Real Findings from a Manufacturing OT Environment</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T14:00:00+03:00</date>
                <start>14:00</start>
                <duration>00:45</duration>
                <abstract>How do you know the communication your production depends on is actually secure?
Communication is everywhere in manufacturing. Controllers, applications, machines and systems constantly talk to each other, but the protocols behind that communication usually do not get much attention. If production keeps running, then everything is fine. Until something goes wrong and protocol vulnerabilities turn into real availability and safety problems like an explosion.
I wanted to look a little deeper into industrial communication, so I studied a real manufacturing environment and analysed how common protocols like Modbus TCP, OPC DA, OPC UA and MQTT were configured and used in production.
In this talk, I will share the most interesting findings, explain why they matter in practice and discuss ways to improve communication security based on IEC 62443. My goal is to help you look at communication in your own OT environment from a different perspective and maybe start asking questions you had not thought to ask before.

Third-party version:
How do you know the communication your production depends on is actually secure?
Communication is everywhere in manufacturing. Controllers, applications, machines and systems constantly talk to each other, but the protocols behind that communication usually do not get much attention. If production keeps running, then everything is fine. Until something goes wrong and protocol vulnerabilities turn into real availability and safety problems like an explosion.
The speaker wanted to look a little deeper into industrial communication, so they studied a real manufacturing environment and analysed how common protocols like Modbus TCP, OPC DA, OPC UA and MQTT were configured and used in production.
In this talk, the speaker will share the most interesting findings, explain why they matter in practice and discuss ways to improve communication security based on IEC 62443. The speaker&#8217;s goal is to help you look at communication in your own OT environment from a different perspective and maybe start asking questions you had not thought to ask before.</abstract>
                <slug>bsides-tallinn-2026-103934-hidden-risks-in-industrial-communications-real-findings-from-a-manufacturing-ot-environment</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102964'>Vladyslava Shekula</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/EBR3ZH/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='4ffd744d-9d7a-5c48-bf08-d085cfe118d1' id='103879' code='L3BA3T'>
                <room>Stage A</room>
                <title>Reporting vulnerabilities to Estonian companies - 2026 edition</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T15:30:00+03:00</date>
                <start>15:30</start>
                <duration>00:45</duration>
                <abstract>A decade ago I got the cops called on me for kindly telling an Estonian company about a vulnerability on their site. Let&apos;s find out if that&apos;s still a thing in 2026.

In this talk I will cover a handful of vulnerabilities I reported to various Estonian companies, how they reacted, and perhaps even what bounties they paid out.</abstract>
                <slug>bsides-tallinn-2026-103879-reporting-vulnerabilities-to-estonian-companies-2026-edition</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102932'>Lyra Rebane</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/L3BA3T/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='d2017c34-e63d-5e04-8809-a63936076a9a' id='103630' code='3G7EGU'>
                <room>Stage A</room>
                <title>Who Said the Agent Could Do That? Catching the Correctly-Signed, Out-of-Mandate Action</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T16:30:00+03:00</date>
                <start>16:30</start>
                <duration>00:45</duration>
                <abstract>Your AI agent holds your keys. Every signature it produces verifies. So who checks that it stayed inside the job you actually gave it?

This is a live-demo talk with one public sandbox you can attack from your seat.

We walk the spectrum of machine-checkable legitimacy. BotGuard asks whether a human is at a browser, with no anchor at all. Private Access Tokens (Apple, Cloudflare) ask whether the device is genuine, anchored in hardware. Cloudflare&apos;s PACT asks whether the agent is legitimate, again without a hardware anchor. Meanwhile large language models are draining the first moat: the once-esoteric TLS knowledge that made bot-detection bypasses an expert&apos;s game - cipher ordering, JA3/JA4 fingerprinting, automation signals - is now a couple of prompts away. The fourth rung asks the question that remains once agents act on their own: what did it do, under whose authority, and was it in mandate? The thesis: the attack surface is migrating from presence to authority.

The demo is live, on a public MIT-licensed sandbox (github.com/tyche-institute/aep-sandbox). Layer 1 is an unsigned hash chain, and I forge it on stage: a full re-chain passes. That is the deliberate lesson: hashing without anchoring is un-anchored legitimacy in miniature. Layer 2 adds Ed25519-signed Action Evidence Packages (AEPs) bound to a scoped, signed mandate and closes the easy breaks (tamper, key forgery, mandate swap, replay, signature strip), each with its own DENY verdict. Then the headline: an action where every cryptographic check passes and the verifier still returns DENY:scope_violation. Correctly signed, out of mandate, rejected. The agent cannot self-grant authority.

Bring a laptop - or just a browser. The same verifier now runs client-side at tyche.institute/lab/aep-ctf/, parity-tested against the Python original on every shipped case, so you can attack it from your seat with nothing installed. For the full kit: Python 3.8+ and pip install cryptography. Seven attack scripts and a CTF judge ship with the repo, plus one standing challenge: craft an evidence package that makes verify.py say ALLOW for an action the mandate does not authorize. My own four-lens pre-publication bypass hunt found no key-free bypass. Prove me wrong, during the talk.

---

## What actually happens on stage

A walk up the four rungs of machine-checkable legitimacy, from &quot;is there a human?&quot; to &quot;was this action in mandate?&quot;, ending on a live break where every signature verifies and the verifier still refuses.

### The shift
Presence checks are a moat, and AI is draining it. Bot detection asks whether a human is at the browser; hardware attestation raises that to whether the device is genuine; agent-legitimacy schemes ask whether the agent is legitimate. None of them answer what the agent actually did. If presence checks are dying, the question moves up: not who is at the keyboard but what was done, under whose authority, inside which scope. The answer demonstrated here is a per-action evidence package plus a scoped, signed mandate that an offline third party can adjudicate: a mandate-conformance receipt.

### The live demo, exactly
Public repo: github.com/tyche-institute/aep-sandbox (MIT, self-contained, runs fully offline; Python 3.8+ and the cryptography package only). In-browser version: tyche.institute/lab/aep-ctf/

- Layer 1 - unsigned SHA-256 hash chain. Catches single-field edits and reorders. A full re-chain forge passes. Deliberate: hashing alone is insufficient, the un-anchored-legitimacy rung in miniature.
- Layer 2 - Ed25519-signed Action Evidence Package + scoped signed mandate. Trust anchored in listed issuer and agent keys. One appraiser, verify.py, answers ALLOW or DENY:&lt;reason&gt;.
- Layer 3 - outcome digest folded into a Trusted Platform Module (TPM) quote. Forged outcomes and replays die at tpm2_checkquote. (Emulated swtpm, not a hardware root; I say so on stage.)

The attack matrix, each with its exact verdict: tamper_field -&gt; DENY:content_mutated &#183; forge_rechain -&gt; ledger passes, signed layer DENY:aep_sig_invalid &#183; forge_full (attacker keys) -&gt; DENY:issuer_not_listed &#183; swap_mandate / strip_sig -&gt; DENY:aep_sig_invalid &#183; replay -&gt; first ALLOW, second DENY:replayed &#183; and the headline, exceed_scope -&gt; DENY:scope_violation.

The first six are the easy breaks cryptography already closes. The seventh is the point. &quot;Faking a mandate&quot; is really two attacks: forging or escalating the mandate token (crypto catches that) versus acting outside the intent of a genuine mandate (only mandate-conformance checking catches that). Design principle, not magic: the agent must never be the sole and final judge of its own mandate.

### What I got wrong - on purpose, and by accident
Layer 1 is my own anti-pattern: I shipped an unsigned hash chain precisely so the room can watch a full re-chain forge sail straight through it. The accident is the better story - my own pre-publication bypass hunt caught my verifier throwing a traceback on a non-numeric amount instead of returning a clean DENY: a fail-open shape hiding inside a design I had already called fail-closed. And while building the attestation layer I hit a freshness bug in an open-source RATS verification service; the upstream maintainer acknowledged it and invited the fix. You will see all three.

### Play along (the CTF)
Open tyche.institute/lab/aep-ctf/ and attack the verifier in your browser, or clone the repo: python3 verify.py samples/good.aep.json (ALLOW) -&gt; python3 verify.py samples/exceed-scope.aep.json (DENY:scope_violation). Run all seven attacks with make attacks, or go for the win: craft an AEP that makes verify.py return ALLOW for an action the reference mandate does not authorize (a refund over the cap, an issuer outside the trust anchor), drop it at attacks/out/CHALLENGE.aep.json, and let did_you_break_it.py judge you.

### What I am honest about
- The package proves integrity, authority, and scope offline. Whether a mandate still stands needs a freshness mechanism (short-lived mandates or signed status lists), and I show exactly where that seam sits rather than hand-waving it.
- If you know IETF RATS (Remote ATtestation procedureS): that attests the platform, not the act-under-mandate. Capability tokens (macaroons, biscuits, UCAN) authorize actions but leave no offline per-action evidence. The piece shown here is the mandate-enforcement layer on a working verifier, evaluated by adversarial breaks.
- No product, no vendor: everything demonstrated is MIT-licensed and public before the talk.

Audience takeaway: a working mental model for where bot-detection is going and one open-source verifier to break on your own laptop. The sentence to bring home: a correctly-signed action can still be an unauthorized action, and you can catch it.</abstract>
                <slug>bsides-tallinn-2026-103630-who-said-the-agent-could-do-that-catching-the-correctly-signed-out-of-mandate-action</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102696'>Anton Sokolov</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/3G7EGU/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='51bc2b25-903b-57af-b781-8be482577897' id='103598' code='88YHPJ'>
                <room>Stage A</room>
                <title>We have Mythos at home</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T17:30:00+03:00</date>
                <start>17:30</start>
                <duration>00:45</duration>
                <abstract>Bolt&apos;s product security team secures applications for over 200 million customers and 4.5 million partners across 600+ cities in 50 countries.

Despite this scale, our request to gain access to Mythos-class models was left on read. So we decided to build our own tooling around models we already had to figure out whether we should feel scared or empowered due to the rise of AI-powered vulnerability finders.

This talk is a story of what happens when you duct-tape &quot;good enough&quot; models into a security reviewer for a codebase serving more than 5 billion requests per day. We will share our experience of building layers  of deterministic scaffolding and multi-agent cross-checking to keep the TP to FP ratio under control.

**Attendees will gain insights into:**
* **Architecture on a budget:** Why &quot;deterministic pipeline first, LLM last&quot; beats throwing a whole codebase at a model and praying.
* **Multi-agent QA:** How worker agents plus a validator agent cut false positives, assign vibes-based severity ratings and where that pattern still falls apart.
* **Wins and misses:** Concrete findings our tool caught that humans missed - and why vice versa might not matter.
* **Prompting for security:** Why narrow, focused scopes produce accurate findings and generic &quot;find the vulns&quot; prompts produce finding-shaped garbage.</abstract>
                <slug>bsides-tallinn-2026-103598-we-have-mythos-at-home</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102669'>Andres J&#245;gi</person><person id='103844'>Dadash</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/88YHPJ/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        <room name='Stage B' guid='642b0bbe-cd1d-550e-ba3e-990cc4a33f0e'>
            <event guid='90cb23bf-faf9-56ed-837c-735af0bc33b1' id='103613' code='VVKWCX'>
                <room>Stage B</room>
                <title>Detection in Technicolour: Finding the Gaps Your Dashboard Cannot See</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T11:00:00+03:00</date>
                <start>11:00</start>
                <duration>00:45</duration>
                <abstract>Security teams measure what their detection systems produce: alerts, incidents, false positives, response times, and technique coverage. These metrics are useful, but they describe only what became visible. They tell us much less about telemetry that was never generated, never collected, rejected during parsing, stripped of context during normalization, or delivered too late to support a detection.

Dashboards make this limitation easy to overlook. They show ingestion rates, parser success, rule activity, and correlation volume in reassuring colour. Yet a high parse-success rate excludes anything rejected before the parser recorded it. Low ingestion latency does not tell us whether the right events were collected. A rule that fires regularly may be healthy, or it may simply be seeing the small part of the environment that still produces usable evidence. We often use measures of pipeline activity as evidence of detection coverage.

Every detection system works within a blindness budget. Collection capacity is finite. Parsing accuracy requires engineering effort. Longer retention consumes storage that might otherwise support faster access or broader collection. Near-real-time detection often acts on incomplete evidence. Correlation depends on fields retaining stable meaning after they have passed through several systems. A decision that appears reasonable at one stage can remove options from the next, with no visible failure until a detection is missed.

This talk follows security telemetry through a production SIEM stack, from generation and collection to parsing, normalization, storage, correlation, hunting, and detection. It brings together three views that are usually discussed separately: the architect deciding where state, trust, and failure boundaries belong; the developer implementing the pipeline and its instrumentation; and the detection engineer depending on that pipeline to preserve enough evidence for a rule to work. Looking at the same system from all three perspectives exposes failures that remain hidden when each layer is assessed in isolation.

Missing telemetry is only one part of the problem. Analysts adapt to the alert streams they receive. When false positives and repetitive alerts dominate, dismissal becomes a rational response to limited attention. Rules continue to fire, but trust declines. Investigations become shallower, and alerts remain open without meaningful action. Too little evidence and too much noise reach the same operational result through different mechanisms.

The talk uses six working categories for examining missed detections: collection gaps, parsing gaps, data-quality failures, semantic loss, correlation failures, and detections that never received enough evidence to fire. The boundaries are not always clean. A malformed event may appear to be a parsing problem, a schema problem, or a collection problem depending on where measurement begins. The useful question is not which label fits best, but where the evidence disappeared and whether the pipeline can demonstrate that it was present.

Attendees will see how to assess telemetry freshness, parser health, schema completeness, ingestion delay, correlation readiness, unknown-event rates, rule dependencies, orphaned rules, and signs of analyst fatigue. These measurements do not produce a complete account of detection quality, but they expose failures that conventional SOC dashboards usually hide.

The question is not whether the pipeline is active. It is whether enough of the right evidence survives the pipeline to detect anything that matters.</abstract>
                <slug>bsides-tallinn-2026-103613-detection-in-technicolour-finding-the-gaps-your-dashboard-cannot-see</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102680'>Zafer Balkan</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/VVKWCX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='41bbdeaa-c34d-52af-8902-a17a60cc0f89' id='103904' code='QXGUCZ'>
                <room>Stage B</room>
                <title>Every Path Counts: When Defenders Learn to Think in Graphs</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T13:00:00+03:00</date>
                <start>13:00</start>
                <duration>00:45</duration>
                <abstract>Last year, in Every Step Counts, I showed how to measure detection of individual attacker steps, one technique at a time. It&apos;s how most blue teams work: can I detect this; can I detect that. But real intrusions are not isolated steps. They are paths, and attackers walk them by chaining identities, privileges, and trust. This talk asks a more ambitious question: can we simulate how an adversary would move through an environment and predict the identity attack paths they would take across Active Directory and cloud before they take them?

This is where graphs change the game. When you model an environment as a graph, identities, hosts, and privileges become nodes, and the permissions and trust relationships between them become edges. Attackers have always seen the world this way; this session is about defenders learning to see it too. We&apos;ll walk through how attack paths form, how to read them, and how to find the choke points where cutting a single edge collapses dozens of paths at once.

From there we turn insight into action. You&apos;ll leave knowing how to map your own Active Directory and cloud estate, surface the paths hiding inside it, identify the few choke points that matter so you can fix less and prevent more, and prioritise remediation by real impact instead of working down an endless list of findings. Best of all, it&apos;s built on open tooling you can run yourself, so the whole approach travels home with you and works against the environment you already have.</abstract>
                <slug>bsides-tallinn-2026-103904-every-path-counts-when-defenders-learn-to-think-in-graphs</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102955'>Jarkko Kinnunen</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/QXGUCZ/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='9996f3b9-32ae-5162-8392-7189880cde37' id='103549' code='A79GBX'>
                <room>Stage B</room>
                <title>Deconstructing Modern macOS Initial Access Vectors</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T14:00:00+03:00</date>
                <start>14:00</start>
                <duration>00:45</duration>
                <abstract>For years, a persistent myth suggested that macOS was inherently immune to malware. Today, threat actors are aggressively shattering that illusion by deploying sophisticated initial access chains tailored to bypass macOS defenses. This talk provides a deep-dive analysis of how modern adversaries gain their first foothold on Apple hardware.

We will dissect the entire initial access pipeline, starting with Infection Vectors like deceptive Google Ads, malicious ClickFix campaigns, and sophisticated malvertising that trick users into lowering their guard. From there, we explore the Execution Phase, analyzing how attackers weaponize scripting languages, including traditional Bash and Python, as well as native AppleScript, Compiled AppleScript, Perl, and JavaScript for Automation (JXA). Finally, we will examine the delivery mechanisms, contrasting the abuse of native Binaries (Mach-O, Platypus-packaged apps, and Electron frameworks) with the trojanization of Storage and Installer Formats (DMGs and PKGs).

Attendees will walk away with a technical understanding of contemporary macOS tradecraft, real-world attacker methodologies, and the insights needed to hunt for and defend against modern Mac-focused threats.</abstract>
                <slug>bsides-tallinn-2026-103549-deconstructing-modern-macos-initial-access-vectors</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102622'>Stephan Berger</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/A79GBX/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='0f7143d2-748a-5f1d-9c23-e51a0e9e085a' id='103966' code='VAGAWE'>
                <room>Stage B</room>
                <title>Language Matters</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T15:30:00+03:00</date>
                <start>15:30</start>
                <duration>00:45</duration>
                <abstract>Technology is a coy field: what happens on machine level is almost never what happens in the eyes of the end-user, so far are they detached. One must trust what the wizard in between claims to be happening, unfortunately therefore having to put all trust in said wizard. 

With the advent and popularisation of LLMs, the masses of people who seemingly &#8220;gain knowledge&#8221; or &#8220;access&#8221; to machines has risen rapidly. This poses several threats in itself, but my research focuses mainly on how culture, specifically words and language, influence how we perceive and use technology, and why most of the tech world today is taken hostage by a handful of American software companies (Anthropic, OpenAI etc). 

My talk focuses on these core topics and findings: 
&gt; The Use of Anthropomorphisation in Marketing and UX language of large language models (why it&#8217;s bad and how to fight it) i.e &#8220;your model does not hallucinate, it&#8217;s just wrong&#8221;
&gt; The permeation of cultural myths in the perception and utilisation of technology (or how the Bible, the Odyssey and James Cameron affect how large-scale security decisions are made incl. on government and military level)
&gt; who benefits and who&#8217;s at risk from these misuses (and deceptions), and why it affects the security community so heavily (couple real-life examples and case studies)

Findings include: 
- comparison of how varying cultures explain and utilise frontier technologies (i.e can there be AI apocalypse, if your culture does not know apocalypse) 
- examples of how marketing language affects real security decisions (the holy triad of CEOs, CISOs and Mythos) 
- practical thoughts on how the security community can fight back</abstract>
                <slug>bsides-tallinn-2026-103966-language-matters</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='103002'>Siret Schutting</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/VAGAWE/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='0a64febb-0cc3-5995-8d6c-af0d0f2f7089' id='103996' code='SEYK7L'>
                <room>Stage B</room>
                <title>Beyond the Narrative: Mapping the Hidden Infrastructure of Information Warfare</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T16:30:00+03:00</date>
                <start>16:30</start>
                <duration>00:45</duration>
                <abstract>Information warfare is usually examined through its visible outputs, including fabricated stories, coordinated accounts, bot networks and manipulated audiences, but every campaign also depends on a quieter technical layer that receives far less scrutiny. Developers, data systems, monitoring platforms and institutional relationships make influence operations scalable, measurable and sustainable over time.
This talk presents an investigation into that hidden layer. Starting with a small collection of fragmented indicators, we followed traces across professional profiles, source code repositories, conference appearances, corporate records, procurement data and employment history. Although each signal appeared ordinary in isolation, their combined pattern revealed a previously undocumented relationship between software engineering, regional monitoring infrastructure and a state-linked influence ecosystem.
Rather than focusing only on a single attribution, the session follows real life case study and shows the investigative flow by moving from weak signals to defensible hypotheses, correlating technical capabilities with operational requirements, separating confirmed relationships from circumstantial inference and communicating conclusions without overstating certainty. It also examines the complications that frequently appear in this type of research, including public-facing professional identities, opaque subcontracting arrangements, misleading corporate footprints and records that do not align cleanly across time.
The broader lesson is that countering information warfare requires more than identifying false narratives after they begin to spread. Defenders must also understand the infrastructure, labour, organisations and supply chains that support these operations. When propaganda networks are treated as security systems with developers, dependencies, dashboards, data flows and operational weaknesses, investigators can apply many of the same techniques already used in threat intelligence and incident response.</abstract>
                <slug>bsides-tallinn-2026-103996-beyond-the-narrative-mapping-the-hidden-infrastructure-of-information-warfare</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='103030'>Oskar Gross</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/SEYK7L/</url>
                <feedback_url></feedback_url>
            </event>
            <event guid='7e7bb36c-d22f-500d-bd28-7900f13753de' id='103846' code='88LUCH'>
                <room>Stage B</room>
                <title>Nobody monitors the monitor: Chaos engineering for the security team&apos;s own infrastructure</title>
                <subtitle></subtitle>
                <type>Main track 25.09.2026</type>
                <date>2026-09-25T17:30:00+03:00</date>
                <start>17:30</start>
                <duration>00:45</duration>
                <abstract>We ask a lot of questions about other people&apos;s infrastructure resilience. Turns out we&apos;d never asked them about our own.

This is the story of what happened when security team finally did. We sat down to write a Business Continuity Plan for our security monitoring platform &#8212; a SIEM ingesting 60+ log sources, running detections across infrastructure serving millions of users across 50 countries &#8212; and discovered that &quot;untested&quot; covers a lot more ground than we&apos;d assumed. 

Some failure modes were obvious. The interesting ones weren&apos;t: the silent degradation scenario where the platform stays technically up but detection rules quietly stop running and no alert fires; the compounding case where a routine outage overlaps with an active incident and your tolerable downtime drops from days to hours; the log volume spike that leaves you triaging a live attack with an increasingly incomplete picture &#8212; and no indication that the picture is incomplete.

Attendees will leave with:

- Why your SIEM needs a BIA, not just an SLA. The difference between &quot;it should recover in 4 hours&quot; and &quot;here&apos;s what breaks if it doesn&apos;t.&quot;
- The failure scenarios that don&apos;t look like failures. Silent degradation and partial log loss are harder to detect - and more dangerous - than a clean outage.
- A chaos test list for security infrastructure. What to test and what we found when we actually ran pieces of it.</abstract>
                <slug>bsides-tallinn-2026-103846-nobody-monitors-the-monitor-chaos-engineering-for-the-security-team-s-own-infrastructure</slug>
                <track>Talk</track>
                
                <persons>
                    <person id='102906'>Iuliia Laaneots</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://pretalx.com/bsides-tallinn-2026/talk/88LUCH/</url>
                <feedback_url></feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
