(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
compliance violation
LM Hash on admin
PCI violation
No botnet
filter
min password length < 12 characters
No drive encryption
SMB signing
not enabled
Default admin credentials
untrained clickers
NIPS
disabled
/unconfigured
insecure zone transfers
No DKIM / DMARC
Segmentation without ACLs
No backup
failure alerts
Application
with > 1000 vulnerabilities
GPO with insecure settings
Windows XP
Individual user permissions in shares
Windows Server 2003/2008
LLMNR enabled
Guest SSID but no guest isolation
Teamviewer / VNC
unencrypted backups
Unpatched Exchange
Bypass users in DUO
Insecure share with PII/PHI
Whitelisted domains in email filter
No SPF record
Plain text password discovered in share
>20% phish click rate
"Domain Users" group as local administrator
Winlogon cache default value
Unlicensed
hardware or software
Telnet
unencrypted web management interface
rogue device
Users are local admins
legacy configuration
not removed
DNS logging not enabled
Computers
not
joined to
AD (or AAD)
critically out-of-date firmware
VPN with weak encryption
End user
Passwords that never expire
No MFA on
365 Admin
Stale users older than 1year
EDR
Missing on endpoint
inappropriate unconstrained delegation in Active Directory