No backup failure alerts Unlicensed hardware or software inappropriate unconstrained delegation in Active Directory PCI violation Insecure share with PII/PHI Telnet Guest SSID but no guest isolation Segmentation without ACLs No Geo-IP blocking No redundant ISP min password length < 12 characters unencrypted web management interface cpassword SMB signing not enabled No DKIM / DMARC Unpatched Exchange unauthenticated mail relay Wireless PSK older than 2 years Application with > 1000 vulnerabilities critically out-of- date firmware Whitelisted domains in email filter Computers not joined to AD (or AAD) "Domain Users" group as local administrator compliance violation LLMNR enabled legacy configuration not removed NIPS disabled /unconfigured No botnet filter unencrypted backups Windows Server 2003/2008 DNS logging not enabled No drive encryption Inapproprite Firewall rules (not RDP) Adobe Flash LM Hash on admin rogue device No DMZ (where appropriate) VPN with weak encryption >20% phish click rate Stale users older than 1year Winlogon cache default value End user Passwords that never expire Windows XP password spreadsheet No SPF record Default admin credentials EDR Missing on endpoint password complexity not enforced No MFA on 365 Admin Individual user permissions in shares VM without autostart GPO with insecure settings Bypass users in DUO untrained clickers Users are local admins Plain text password discovered in share Teamviewer / VNC Windows 7 Default SNMP Write value insecure zone transfers No backup failure alerts Unlicensed hardware or software inappropriate unconstrained delegation in Active Directory PCI violation Insecure share with PII/PHI Telnet Guest SSID but no guest isolation Segmentation without ACLs No Geo-IP blocking No redundant ISP min password length < 12 characters unencrypted web management interface cpassword SMB signing not enabled No DKIM / DMARC Unpatched Exchange unauthenticated mail relay Wireless PSK older than 2 years Application with > 1000 vulnerabilities critically out-of- date firmware Whitelisted domains in email filter Computers not joined to AD (or AAD) "Domain Users" group as local administrator compliance violation LLMNR enabled legacy configuration not removed NIPS disabled /unconfigured No botnet filter unencrypted backups Windows Server 2003/2008 DNS logging not enabled No drive encryption Inapproprite Firewall rules (not RDP) Adobe Flash LM Hash on admin rogue device No DMZ (where appropriate) VPN with weak encryption >20% phish click rate Stale users older than 1year Winlogon cache default value End user Passwords that never expire Windows XP password spreadsheet No SPF record Default admin credentials EDR Missing on endpoint password complexity not enforced No MFA on 365 Admin Individual user permissions in shares VM without autostart GPO with insecure settings Bypass users in DUO untrained clickers Users are local admins Plain text password discovered in share Teamviewer / VNC Windows 7 Default SNMP Write value insecure zone transfers
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
No backup
failure alerts
Unlicensed
hardware or software
inappropriate unconstrained delegation in Active Directory
PCI violation
Insecure share with PII/PHI
Telnet
Guest SSID but no guest isolation
Segmentation without ACLs
No Geo-IP blocking
No redundant ISP
min password length < 12 characters
unencrypted web management interface
cpassword
SMB signing
not enabled
No DKIM / DMARC
Unpatched Exchange
unauthenticated
mail relay
Wireless PSK older than 2 years
Application
with > 1000 vulnerabilities
critically out-of-date firmware
Whitelisted domains in email filter
Computers
not
joined to
AD (or AAD)
"Domain Users" group as local administrator
compliance violation
LLMNR enabled
legacy configuration
not removed
NIPS
disabled
/unconfigured
No botnet
filter
unencrypted backups
Windows Server 2003/2008
DNS logging not enabled
No drive encryption
Inapproprite Firewall rules (not RDP)
Adobe Flash
LM Hash on admin
rogue device
No DMZ
(where appropriate)
VPN with weak encryption
>20% phish click rate
Stale users older than 1year
Winlogon cache default value
End user
Passwords that never expire
Windows XP
password spreadsheet
No SPF record
Default admin credentials
EDR
Missing on endpoint
password complexity not enforced
No MFA on
365 Admin
Individual user permissions in shares
VM without autostart
GPO with insecure settings
Bypass users in DUO
untrained clickers
Users are local admins
Plain text password discovered in share
Teamviewer / VNC
Windows 7
Default SNMP Write value
insecure zone transfers