BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsides-tallinn-2026//talk//TMCQPB
BEGIN:VTIMEZONE
TZID:Europe/Helsinki
BEGIN:DAYLIGHT
DTSTART:20250924T000000
TZNAME:EEST
TZOFFSETFROM:+0300
TZOFFSETTO:+0300
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T040000
RDATE:20261025T040000
TZNAME:EET
TZOFFSETFROM:+0300
TZOFFSETTO:+0200
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T040000
RDATE:20270328T040000
TZNAME:EEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0300
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:(FULL) Gotta Contain 'Em All: Collaborative Incident Response Trai
 ning Through Gaming - Klaus Agnoletti
DTSTART;TZID=Europe/Helsinki:20260924T093000
DTEND;TZID=Europe/Helsinki:20260924T113000
DTSTAMP:20260926T112157Z
UID:pretalx-bsides-tallinn-2026-TMCQPB@pretalx.com
DESCRIPTION:Sign-up form: [**Google forms**](https://docs.google.com/forms
 /d/e/1FAIpQLSdtdi-PcGMdEWRj0-EARLu4UMCQt_2hxAyRkJkJ6R_Oe_LyFw/viewform?usp
 =sharing&ouid=104367224945762059530)\n\nIncident response isn't just about
  knowing your tools - it's about coordinating under pressure\, communicati
 ng when things go sideways\, and making calls with incomplete information.
  Traditional training focuses on isolated techniques\, missing the collabo
 rative reality of actual incidents. And most tabletop exercises? Painfully
  dull. Participants zone out\, give checkbox answers\, and leave having le
 arned little.\n\nThis workshop introduces Malware & Monsters (https://malw
 areandmonsters.com)\, a framework that turns IR training into something pe
 ople actually enjoy. Think tabletop role-playing meets creature-collection
  mechanics\, where teams "hunt and contain" digital threats through story-
 driven gameplay.\nGame-based learning works - research shows it beats trad
 itional instruction for skill building and retention. M&M makes participan
 ts actively discover concepts instead of sitting through lectures. Scenari
 os include organizational pressures\, evolving threats\, and stakeholder d
 rama\, turning abstract security concepts into tangible problems.\n\nYou'l
 l experience the full methodology: learn the mechanics\, build custom scen
 arios based on real malware families (mapped to MITRE ATT&CK)\, and run li
 ve simulations. Participants take specialized roles - Hunter\, Analyst\, F
 orensicator\, Communicator\, Coordinator\, or Researcher - experiencing ho
 w security functions actually collaborate during incidents.\n\nThe framewo
 rk includes legacy malmons from malware history—because history always r
 epeats itself\, and understanding past threats reveals patterns in current
  attacks. The "type effectiveness" system teaches strategic thinking about
  matching defenses to threats. Evolution mechanics show how attacks escala
 te when containment fails.\n\nParticipants walk away with ready-to-use mat
 erials and facilitation techniques for training that actually works.\n\nBe
 st of all? M&M is free to play in most cases.
LOCATION:Workshop room (LD1) 9:30-15:00
URL:https://pretalx.com/bsides-tallinn-2026/talk/TMCQPB/
END:VEVENT
END:VCALENDAR
