Have youlooked inWiz?This isTORYour goalis to markyourselfas proForensicAnalysisLook at thegeographicaldataTell memoreabout…It’s been ameetingheavy dayIRtakespriorityWe needthat onthe wikiWe willautomateDoes thislookmalicious?I don’thaveaccessI needsomecoffeeI can setyou upwith amentorI’mhelpingout on-callDid youlook atsessiontrafficDo I haveaccess tothis?Did younotifySVIC?So who hasquestionsabout theirticket?Thisgoes toLevel 2We needthese logsin SplunkCompromiseIOCSecurityevent notan IRAdd moreresourcesHave youlooked inWiz?This isTORYour goalis to markyourselfas proForensicAnalysisLook at thegeographicaldataTell memoreabout…It’s been ameetingheavy dayIRtakespriorityWe needthat onthe wikiWe willautomateDoes thislookmalicious?I don’thaveaccessI needsomecoffeeI can setyou upwith amentorI’mhelpingout on-callDid youlook atsessiontrafficDo I haveaccess tothis?Did younotifySVIC?So who hasquestionsabout theirticket?Thisgoes toLevel 2We needthese logsin SplunkCompromiseIOCSecurityevent notan IRAdd moreresources

Buzz Phrase Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. Have you looked in Wiz?
  2. This is TOR
  3. Your goal is to mark yourself as pro
  4. Forensic Analysis
  5. Look at the geographical data
  6. Tell me more about…
  7. It’s been a meeting heavy day
  8. IR takes priority
  9. We need that on the wiki
  10. We will automate
  11. Does this look malicious?
  12. I don’t have access
  13. I need some coffee
  14. I can set you up with a mentor
  15. I’m helping out on-call
  16. Did you look at session traffic
  17. Do I have access to this?
  18. Did you notify SVIC?
  19. So who has questions about their ticket?
  20. This goes to Level 2
  21. We need these logs in Splunk
  22. Compromise IOC
  23. Security event not an IR
  24. Add more resources