(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
No redundant ISP
VPN with weak encryption
Winlogon cache default value
EDR
Missing on endpoint
DNS logging not enabled
unencrypted web management interface
End user
Passwords that never expire
SMB signing
not enabled
Insecure share with PII/PHI
Users are local admins
Wireless PSK older than 2 years
Whitelisted domains in email filter
No drive encryption
Individual user permissions in shares
Application
with > 1000 vulnerabilities
compliance violation
NIPS
disabled
/unconfigured
insecure zone transfers
Adobe Flash
Unpatched Exchange
No SPF record
untrained clickers
No MFA on
365 Admin
No DKIM / DMARC
VM without autostart
Stale users older than 1year
GPO with insecure settings
>20% phish click rate
Computers
not
joined to
AD (or AAD)
Windows XP
critically out-of-date firmware
Teamviewer / VNC
"Domain Users" group as local administrator
LLMNR enabled
Guest SSID but no guest isolation
Segmentation without ACLs
No botnet
filter
No DMZ
(where appropriate)
cpassword
Windows 7
Plain text password discovered in share
Default SNMP Write value
min password length < 12 characters
rogue device
No backup
failure alerts
Windows Server 2003/2008
Telnet
Bypass users in DUO
LM Hash on admin
No Geo-IP blocking
unencrypted backups
password complexity not enforced
legacy configuration
not removed
Inapproprite Firewall rules (not RDP)
inappropriate unconstrained delegation in Active Directory