Have you looked in Wiz? This is TOR Your goal is to mark yourself as pro Forensic Analysis Look at the geographical data Tell me more about… It’s been a meeting heavy day IR takes priority We need that on the wiki We will automate Does this look malicious? I don’t have access I need some coffee I can set you up with a mentor I’m helping out on-call Did you look at session traffic Do I have access to this? Did you notify SVIC? So who has questions about their ticket? This goes to Level 2 We need these logs in Splunk Compromise IOC Security event not an IR Add more resources Have you looked in Wiz? This is TOR Your goal is to mark yourself as pro Forensic Analysis Look at the geographical data Tell me more about… It’s been a meeting heavy day IR takes priority We need that on the wiki We will automate Does this look malicious? I don’t have access I need some coffee I can set you up with a mentor I’m helping out on-call Did you look at session traffic Do I have access to this? Did you notify SVIC? So who has questions about their ticket? This goes to Level 2 We need these logs in Splunk Compromise IOC Security event not an IR Add more resources
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Have you looked in Wiz?
This is TOR
Your goal is to mark yourself as pro
Forensic Analysis
Look at the geographical data
Tell me more about…
It’s been a meeting heavy day
IR takes priority
We need that on the wiki
We will automate
Does this look malicious?
I don’t have access
I need some coffee
I can set you up with a mentor
I’m helping out on-call
Did you look at session traffic
Do I have access to this?
Did you notify SVIC?
So who has questions about their ticket?
This goes to Level 2
We need these logs in Splunk
Compromise IOC
Security event not an IR
Add more resources