(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Winlogon cache default value
Default admin credentials
compliance violation
No drive encryption
GPO with insecure settings
Windows 7
EDR
Missing on endpoint
Individual user permissions in shares
SMB signing
not enabled
untrained clickers
Application
with > 1000 vulnerabilities
LLMNR enabled
Unpatched Exchange
VM without autostart
unencrypted backups
Windows Server 2003/2008
unauthenticated
mail relay
Computers
not
joined to
AD (or AAD)
rogue device
Telnet
No DMZ
(where appropriate)
No MFA on
365 Admin
password complexity not enforced
password spreadsheet
min password length < 12 characters
unencrypted web management interface
cpassword
Inapproprite Firewall rules (not RDP)
LM Hash on admin
Bypass users in DUO
Segmentation without ACLs
insecure zone transfers
critically out-of-date firmware
Adobe Flash
Plain text password discovered in share
legacy configuration
not removed
>20% phish click rate
Stale users older than 1year
Guest SSID but no guest isolation
No DKIM / DMARC
Unlicensed
hardware or software
Users are local admins
End user
Passwords that never expire
No SPF record
Windows XP
DNS logging not enabled
No Geo-IP blocking
"Domain Users" group as local administrator
Teamviewer / VNC
Whitelisted domains in email filter
Default SNMP Write value
Insecure share with PII/PHI
No backup
failure alerts
Wireless PSK older than 2 years
NIPS
disabled
/unconfigured
VPN with weak encryption
No redundant ISP
No botnet
filter
PCI violation
inappropriate unconstrained delegation in Active Directory