In the vein of old school Choose Your Own Adventures, this is a custom created story that leads the audience through an incident response including technical and business considerations. The audience votes through a live poll on decision points in the story including detection, identification, response, remediation, and threat hunting for like compromises. Communication with the appropriate stakeholders and your team is key throughout the phases. The core "story" will be the majority of the session, but will generate significant discussion and Q&A. After the talk, we will release a free tool that will allow the audience to continue to play and learn on their own through the different decision points.
"I created this exercise (and corresponding tool) as a new way to engage an audience to teach Blue Team concepts in process, organizational considerations, and technical techniques beyond the standard Powerpoint lecture. It has been play-tested with over 1000 players and found that it works well from beginner to expert level in facilitating discussion and insights."