ForensicAnalysisI can setyou upwith amentorIRtakesprioritySecurityevent notan IRDo I haveaccess tothis?We needthese logsin SplunkThisgoes toLevel 2We willautomateAdd moreresourcesI needsomecoffeeI don’thaveaccessHave youlooked inWiz?Does thislookmalicious?Tell memoreabout…Look at thegeographicaldataCompromiseIOCDid younotifySVIC?Your goalis to markyourselfas proIt’s been ameetingheavy dayWe needthat onthe wikiThis isTORSo who hasquestionsabout theirticket?I’mhelpingout on-callDid youlook atsessiontrafficForensicAnalysisI can setyou upwith amentorIRtakesprioritySecurityevent notan IRDo I haveaccess tothis?We needthese logsin SplunkThisgoes toLevel 2We willautomateAdd moreresourcesI needsomecoffeeI don’thaveaccessHave youlooked inWiz?Does thislookmalicious?Tell memoreabout…Look at thegeographicaldataCompromiseIOCDid younotifySVIC?Your goalis to markyourselfas proIt’s been ameetingheavy dayWe needthat onthe wikiThis isTORSo who hasquestionsabout theirticket?I’mhelpingout on-callDid youlook atsessiontraffic

Buzz Phrase Bingo - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. Forensic Analysis
  2. I can set you up with a mentor
  3. IR takes priority
  4. Security event not an IR
  5. Do I have access to this?
  6. We need these logs in Splunk
  7. This goes to Level 2
  8. We will automate
  9. Add more resources
  10. I need some coffee
  11. I don’t have access
  12. Have you looked in Wiz?
  13. Does this look malicious?
  14. Tell me more about…
  15. Look at the geographical data
  16. Compromise IOC
  17. Did you notify SVIC?
  18. Your goal is to mark yourself as pro
  19. It’s been a meeting heavy day
  20. We need that on the wiki
  21. This is TOR
  22. So who has questions about their ticket?
  23. I’m helping out on-call
  24. Did you look at session traffic