IR takes priority Security event not an IR I need some coffee I’m helping out on-call Forensic Analysis Compromise IOC This goes to Level 2 Your goal is to mark yourself as pro Add more resources We need that on the wiki I can set you up with a mentor Look at the geographical data This is TOR I don’t have access Do I have access to this? Tell me more about… It’s been a meeting heavy day Have you looked in Wiz? Does this look malicious? Did you notify SVIC? We need these logs in Splunk Did you look at session traffic So who has questions about their ticket? We will automate IR takes priority Security event not an IR I need some coffee I’m helping out on-call Forensic Analysis Compromise IOC This goes to Level 2 Your goal is to mark yourself as pro Add more resources We need that on the wiki I can set you up with a mentor Look at the geographical data This is TOR I don’t have access Do I have access to this? Tell me more about… It’s been a meeting heavy day Have you looked in Wiz? Does this look malicious? Did you notify SVIC? We need these logs in Splunk Did you look at session traffic So who has questions about their ticket? We will automate
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
IR takes priority
Security event not an IR
I need some coffee
I’m helping out on-call
Forensic Analysis
Compromise IOC
This goes to Level 2
Your goal is to mark yourself as pro
Add more resources
We need that on the wiki
I can set you up with a mentor
Look at the geographical data
This is TOR
I don’t have access
Do I have access to this?
Tell me more about…
It’s been a meeting heavy day
Have you looked in Wiz?
Does this look malicious?
Did you notify SVIC?
We need these logs in Splunk
Did you look at session traffic
So who has questions about their ticket?
We will automate