SlideShare a Scribd company logo
1 of 11
MORTAL KOMBAT
ALL NOOB SAIBOT EDITION
THE STORY SO FAR
Fuzzbuts.com is an up-and-coming cat picture
aggregator site. Their application allows users to
search for cat pictures by cat color, breed, size, and
sassiness.
Fuzzbuts’ claim is that their Deep Purring algorithm
harnesses the ability of real cats to recognize and
hate each other to allow for excellent feline sorting
and discrimination that rivals a Google search.
Fuzzbuts has a security budget of yes, but a small
dev team and a corporate mandate that all IS
spending must be done by consensus.
Fuzzbuts’ CEO is Billi Kottur, a woman not known for
her social graces.
THE OTHER PLAYERS
Minotaur Security Concern - Fuzzbuts is
concerned about someone getting their
proprietary data and stealing their algorithm. In
a fit of good sense, they have hired the
Minotaur Security Concern.
MSC’s goal is to find the most likely attack
vector or vectors and report back to Fuzzbuts.
MSC’s budget is moderate.
The Power Borkers – Generally thought to be a bunch of script kitties living in a
basement somewhere, these folks have nonetheless made a name for themselves
by using the OWASP Top 10 as a shopping list to get into information and systems
and monetize their findings.
The Power Borkers’ goal is to make money, and they think that Fuzzbuts may be a
good target. Their budget is nearly non-existent, but they are unhampered by little
concerns like the law.
Fuzzbutts.com – Were you wondering where that
second “t” was? Fuzzbutts.com has a . . . very
different business model than fuzzbuts.com, but
you can see where someone might get them
confused.
Felix Margarita, CEO of Fuzzbutts.com certainly
thought so, but the U.S. District Court for the
Ninth Circuit disagreed, and Felix lost a mint on
his unsuccessful trademark suit against
fuzzbuts.com. Fuzzbuts CEO Billi Kottur was not a
graceful winner, and after that one-two punch,
Felix is looking for payback.
Fuzzbutts.com’s goal is to damage the finances,
reputation, and general happiness of Billi Kottur.
Their budget isn’t yes, but is definitely maybe.
Fuzzbuts is the
MINOTAUR
POWER BORKERS
FUZZBUTTS.COM
FUZZBUTS
BLUE TEAM RULES
• A “move” is a discrete step that Fuzzbuts will take to harden their systems
before an attack.
• Fuzzbuts gets three moves.
• Fuzzbuts players will confer in a separate Teams chat and will DM me their
three moves when they are ready to go on to the next phase of the game.
• Any move taken by Fuzzbuts must be agreed to unanimously by all Fuzzbut
players.
• For this game, assume your budget is yes but your timeframe for making
changes is up to one month prior to the first red team attack.
RED TEAM RULES
• Minotaur, the Power Borkers, and Fuzzbutt.com are each a separate red team.
• Each red team gets one move.
• Each “move” is a discrete step that each red team will take to further their
goal.
• Each red team will split into a separate Teams chat and will DM me their move
when they are ready to go on to the next phase of the game.
• For this game, red teams can assume up to one years’ worth of planning time
prior to making their attack and can use any resources that would be
reasonable for an organization of their type.
ENDGAME
• Both sides will present
their moves publicly, blue
first, then red.
• The GM will adjudicate
those moves based on
their feasibility,
appropriateness, and the
teams’ arguments.
• Don’t fight the scenario,
don’t be a sore winner or
loser.
AFTERMATH
• What worked?
• What didn’t?
• What would you like to see more of?
• What would you like to see less of?
• How was the timeframe?
• Did this feel like a game?
• Would this be useful to clients?
LEAVE ME,
HUMANS.

More Related Content

Recently uploaded

Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Design and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data ScienceDesign and Development of a Provenance Capture Platform for Data Science
Design and Development of a Provenance Capture Platform for Data Science
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
JohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptxJohnPollard-hybrid-app-RailsConf2024.pptx
JohnPollard-hybrid-app-RailsConf2024.pptx
 
JavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate GuideJavaScript Usage Statistics 2024 - The Ultimate Guide
JavaScript Usage Statistics 2024 - The Ultimate Guide
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Navigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern EnterpriseNavigating Identity and Access Management in the Modern Enterprise
Navigating Identity and Access Management in the Modern Enterprise
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
WSO2 Micro Integrator for Enterprise Integration in a Decentralized, Microser...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

Featured

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 

Fuzzbuts TTX

  • 1. MORTAL KOMBAT ALL NOOB SAIBOT EDITION
  • 2. THE STORY SO FAR Fuzzbuts.com is an up-and-coming cat picture aggregator site. Their application allows users to search for cat pictures by cat color, breed, size, and sassiness. Fuzzbuts’ claim is that their Deep Purring algorithm harnesses the ability of real cats to recognize and hate each other to allow for excellent feline sorting and discrimination that rivals a Google search. Fuzzbuts has a security budget of yes, but a small dev team and a corporate mandate that all IS spending must be done by consensus. Fuzzbuts’ CEO is Billi Kottur, a woman not known for her social graces.
  • 3. THE OTHER PLAYERS Minotaur Security Concern - Fuzzbuts is concerned about someone getting their proprietary data and stealing their algorithm. In a fit of good sense, they have hired the Minotaur Security Concern. MSC’s goal is to find the most likely attack vector or vectors and report back to Fuzzbuts. MSC’s budget is moderate.
  • 4. The Power Borkers – Generally thought to be a bunch of script kitties living in a basement somewhere, these folks have nonetheless made a name for themselves by using the OWASP Top 10 as a shopping list to get into information and systems and monetize their findings. The Power Borkers’ goal is to make money, and they think that Fuzzbuts may be a good target. Their budget is nearly non-existent, but they are unhampered by little concerns like the law.
  • 5. Fuzzbutts.com – Were you wondering where that second “t” was? Fuzzbutts.com has a . . . very different business model than fuzzbuts.com, but you can see where someone might get them confused. Felix Margarita, CEO of Fuzzbutts.com certainly thought so, but the U.S. District Court for the Ninth Circuit disagreed, and Felix lost a mint on his unsuccessful trademark suit against fuzzbuts.com. Fuzzbuts CEO Billi Kottur was not a graceful winner, and after that one-two punch, Felix is looking for payback. Fuzzbutts.com’s goal is to damage the finances, reputation, and general happiness of Billi Kottur. Their budget isn’t yes, but is definitely maybe.
  • 6. Fuzzbuts is the MINOTAUR POWER BORKERS FUZZBUTTS.COM FUZZBUTS
  • 7. BLUE TEAM RULES • A “move” is a discrete step that Fuzzbuts will take to harden their systems before an attack. • Fuzzbuts gets three moves. • Fuzzbuts players will confer in a separate Teams chat and will DM me their three moves when they are ready to go on to the next phase of the game. • Any move taken by Fuzzbuts must be agreed to unanimously by all Fuzzbut players. • For this game, assume your budget is yes but your timeframe for making changes is up to one month prior to the first red team attack.
  • 8. RED TEAM RULES • Minotaur, the Power Borkers, and Fuzzbutt.com are each a separate red team. • Each red team gets one move. • Each “move” is a discrete step that each red team will take to further their goal. • Each red team will split into a separate Teams chat and will DM me their move when they are ready to go on to the next phase of the game. • For this game, red teams can assume up to one years’ worth of planning time prior to making their attack and can use any resources that would be reasonable for an organization of their type.
  • 9. ENDGAME • Both sides will present their moves publicly, blue first, then red. • The GM will adjudicate those moves based on their feasibility, appropriateness, and the teams’ arguments. • Don’t fight the scenario, don’t be a sore winner or loser.
  • 10. AFTERMATH • What worked? • What didn’t? • What would you like to see more of? • What would you like to see less of? • How was the timeframe? • Did this feel like a game? • Would this be useful to clients?