// EVENT

Beat the Breach: Defend, Respond, Survive

You are the blue team. There is a threat actor on the other side, and they are adapting to what you do.

Staff contacts McKay HardyWestley Wagstaff

Beat the Breach: Defend, Respond, Survive illustration
Your team is dropped into a live breach. You are the blue team, and on the other side there is a threat actor doing real things in real time and reacting to your moves. Three and a half hours, dynamic, immersive, and deliberately stressful.
When
Wednesday and Thursday, two sessions each day
Length
3.5 hours per session
Where
Battle Creek, third floor northwest corner
Signup
On-site, capacity limited
Teams
3 to 5 recommended

Run by Hack Labs. This is a live simulation rather than a tabletop walkthrough, and it is as close to a real incident as a conference room gets.

Sessions

Four sessions in total, morning and afternoon on both Wednesday and Thursday. Each one runs three and a half hours and you are expected to stay engaged for the whole block.

Sessions fill fast and capacity is limited, so sign up early in the week rather than the morning of.

How to take part

  1. Sign up on-site at the Beat the Breach table. There is no online form.
  2. Bring a team of three to five, or join one at signup.
  3. Turn up at the Battle Creek room, third floor northwest corner, at your session start time. The simulation uses Battle Creek and the room next to it.

Watching instead

Spectator viewing is available. There is a broadcast feed you can watch without seeing anything that would spoil the scenario for a later session, which makes it worth a look even if you are not playing.

What to bring

  • A laptop with your usual security toolkit.
  • Terminal access and basic incident response tools.
  • A notepad. You will want to take notes.

Skills you need

Basic Linux and terminal skills, plus some understanding of what an incident response process looks like. If you have worked a CTF, you are ready for this.

Experienced responders will find plenty here. The threat actor adapts to what you do, so the scenario does not run on rails.

Questions

Do I need incident response experience?

Not formally. You need to be comfortable in a terminal and have a rough idea of how an incident gets handled. CTF experience is a good marker.

How do I sign up?

At the Beat the Breach table during the conference. Sessions are capacity limited and they fill fast.

Can I watch without playing?

Yes. The broadcast feed is set up for spectators and does not give away the scenario.

Will there be help if something breaks?

Yes. Facilitators and tech experts are on hand throughout.

Can I sign up as a team?

Absolutely. Bring your crew. Whether you are seasoned SOC pros or an assembled team of defenders, teamwork is the point.

Security Briefing

Join the mission log

Occasional emails with training announcements, CFP windows, and what's launching at SAINTCON. No spam, no selling your address. Ever.

By subscribing you agree to the Privacy Policy.