IR takes priority We need that on the wiki Compromise IOC We need these logs in Splunk Look at the geographical data Your goal is to mark yourself as pro Tell me more about… I’m helping out on-call Add more resources I can set you up with a mentor So who has questions about their ticket? Security event not an IR Forensic Analysis We will automate I need some coffee Have you looked in Wiz? Do I have access to this? It’s been a meeting heavy day Did you notify SVIC? Does this look malicious? I don’t have access This is TOR This goes to Level 2 Did you look at session traffic IR takes priority We need that on the wiki Compromise IOC We need these logs in Splunk Look at the geographical data Your goal is to mark yourself as pro Tell me more about… I’m helping out on-call Add more resources I can set you up with a mentor So who has questions about their ticket? Security event not an IR Forensic Analysis We will automate I need some coffee Have you looked in Wiz? Do I have access to this? It’s been a meeting heavy day Did you notify SVIC? Does this look malicious? I don’t have access This is TOR This goes to Level 2 Did you look at session traffic
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
IR takes priority
We need that on the wiki
Compromise IOC
We need these logs in Splunk
Look at the geographical data
Your goal is to mark yourself as pro
Tell me more about…
I’m helping out on-call
Add more resources
I can set you up with a mentor
So who has questions about their ticket?
Security event not an IR
Forensic Analysis
We will automate
I need some coffee
Have you looked in Wiz?
Do I have access to this?
It’s been a meeting heavy day
Did you notify SVIC?
Does this look malicious?
I don’t have access
This is TOR
This goes to Level 2
Did you look at session traffic