So who has questions about their ticket? I need some coffee I can set you up with a mentor I’m helping out on-call Look at the geographical data I don’t have access This goes to Level 2 Forensic Analysis Add more resources Did you look at session traffic We will automate It’s been a meeting heavy day Your goal is to mark yourself as pro Do I have access to this? IR takes priority Compromise IOC Security event not an IR Does this look malicious? Did you notify SVIC? Tell me more about… Have you looked in Wiz? We need that on the wiki This is TOR We need these logs in Splunk So who has questions about their ticket? I need some coffee I can set you up with a mentor I’m helping out on-call Look at the geographical data I don’t have access This goes to Level 2 Forensic Analysis Add more resources Did you look at session traffic We will automate It’s been a meeting heavy day Your goal is to mark yourself as pro Do I have access to this? IR takes priority Compromise IOC Security event not an IR Does this look malicious? Did you notify SVIC? Tell me more about… Have you looked in Wiz? We need that on the wiki This is TOR We need these logs in Splunk
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
So who has questions about their ticket?
I need some coffee
I can set you up with a mentor
I’m helping out on-call
Look at the geographical data
I don’t have access
This goes to Level 2
Forensic Analysis
Add more resources
Did you look at session traffic
We will automate
It’s been a meeting heavy day
Your goal is to mark yourself as pro
Do I have access to this?
IR takes priority
Compromise IOC
Security event not an IR
Does this look malicious?
Did you notify SVIC?
Tell me more about…
Have you looked in Wiz?
We need that on the wiki
This is TOR
We need these logs in Splunk