Do I have access to this? We need that on the wiki Tell me more about… Forensic Analysis I need some coffee Your goal is to mark yourself as pro I can set you up with a mentor This goes to Level 2 Look at the geographical data Add more resources Does this look malicious? We will automate Did you notify SVIC? Security event not an IR This is TOR I’m helping out on-call So who has questions about their ticket? Have you looked in Wiz? IR takes priority Compromise IOC I don’t have access Did you look at session traffic It’s been a meeting heavy day We need these logs in Splunk Do I have access to this? We need that on the wiki Tell me more about… Forensic Analysis I need some coffee Your goal is to mark yourself as pro I can set you up with a mentor This goes to Level 2 Look at the geographical data Add more resources Does this look malicious? We will automate Did you notify SVIC? Security event not an IR This is TOR I’m helping out on-call So who has questions about their ticket? Have you looked in Wiz? IR takes priority Compromise IOC I don’t have access Did you look at session traffic It’s been a meeting heavy day We need these logs in Splunk
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Do I have access to this?
We need that on the wiki
Tell me more about…
Forensic Analysis
I need some coffee
Your goal is to mark yourself as pro
I can set you up with a mentor
This goes to Level 2
Look at the geographical data
Add more resources
Does this look malicious?
We will automate
Did you notify SVIC?
Security event not an IR
This is TOR
I’m helping out on-call
So who has questions about their ticket?
Have you looked in Wiz?
IR takes priority
Compromise IOC
I don’t have access
Did you look at session traffic
It’s been a meeting heavy day
We need these logs in Splunk