Adobe Flash cpassword No MFA on 365 Admin Winlogon cache default value unencrypted web management interface Segmentation without ACLs Wireless PSK older than 2 years "Domain Users" group as local administrator insecure zone transfers NIPS disabled /unconfigured Stale users older than 1year password complexity not enforced No Geo-IP blocking Windows Server 2003/2008 Insecure share with PII/PHI unauthenticated mail relay inappropriate unconstrained delegation in Active Directory Computers not joined to AD (or AAD) End user Passwords that never expire GPO with insecure settings critically out-of- date firmware Windows 7 SMB signing not enabled No backup failure alerts No redundant ISP LLMNR enabled Plain text password discovered in share Default SNMP Write value Telnet PCI violation >20% phish click rate Individual user permissions in shares Unlicensed hardware or software Unpatched Exchange rogue device Guest SSID but no guest isolation Windows XP No SPF record DNS logging not enabled LM Hash on admin Inapproprite Firewall rules (not RDP) Teamviewer / VNC No DKIM / DMARC untrained clickers VM without autostart Application with > 1000 vulnerabilities Whitelisted domains in email filter legacy configuration not removed No botnet filter Default admin credentials VPN with weak encryption EDR Missing on endpoint Users are local admins unencrypted backups password spreadsheet compliance violation min password length < 12 characters No drive encryption Bypass users in DUO No DMZ (where appropriate) Adobe Flash cpassword No MFA on 365 Admin Winlogon cache default value unencrypted web management interface Segmentation without ACLs Wireless PSK older than 2 years "Domain Users" group as local administrator insecure zone transfers NIPS disabled /unconfigured Stale users older than 1year password complexity not enforced No Geo-IP blocking Windows Server 2003/2008 Insecure share with PII/PHI unauthenticated mail relay inappropriate unconstrained delegation in Active Directory Computers not joined to AD (or AAD) End user Passwords that never expire GPO with insecure settings critically out-of- date firmware Windows 7 SMB signing not enabled No backup failure alerts No redundant ISP LLMNR enabled Plain text password discovered in share Default SNMP Write value Telnet PCI violation >20% phish click rate Individual user permissions in shares Unlicensed hardware or software Unpatched Exchange rogue device Guest SSID but no guest isolation Windows XP No SPF record DNS logging not enabled LM Hash on admin Inapproprite Firewall rules (not RDP) Teamviewer / VNC No DKIM / DMARC untrained clickers VM without autostart Application with > 1000 vulnerabilities Whitelisted domains in email filter legacy configuration not removed No botnet filter Default admin credentials VPN with weak encryption EDR Missing on endpoint Users are local admins unencrypted backups password spreadsheet compliance violation min password length < 12 characters No drive encryption Bypass users in DUO No DMZ (where appropriate)
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Adobe Flash
cpassword
No MFA on
365 Admin
Winlogon cache default value
unencrypted web management interface
Segmentation without ACLs
Wireless PSK older than 2 years
"Domain Users" group as local administrator
insecure zone transfers
NIPS
disabled
/unconfigured
Stale users older than 1year
password complexity not enforced
No Geo-IP blocking
Windows Server 2003/2008
Insecure share with PII/PHI
unauthenticated
mail relay
inappropriate unconstrained delegation in Active Directory
Computers
not
joined to
AD (or AAD)
End user
Passwords that never expire
GPO with insecure settings
critically out-of-date firmware
Windows 7
SMB signing
not enabled
No backup
failure alerts
No redundant ISP
LLMNR enabled
Plain text password discovered in share
Default SNMP Write value
Telnet
PCI violation
>20% phish click rate
Individual user permissions in shares
Unlicensed
hardware or software
Unpatched Exchange
rogue device
Guest SSID but no guest isolation
Windows XP
No SPF record
DNS logging not enabled
LM Hash on admin
Inapproprite Firewall rules (not RDP)
Teamviewer / VNC
No DKIM / DMARC
untrained clickers
VM without autostart
Application
with > 1000 vulnerabilities
Whitelisted domains in email filter
legacy configuration
not removed
No botnet
filter
Default admin credentials
VPN with weak encryption
EDR
Missing on endpoint
Users are local admins
unencrypted backups
password spreadsheet
compliance violation
min password length < 12 characters
No drive encryption
Bypass users in DUO
No DMZ
(where appropriate)