This site is in BETA. Labs are still being adjusted and re-structured and may not work as intended.

Resources

BHIS Blog

Current cybersecurity commentary and technical guidance.

SRH medium

SRH medium

July 29, 2026

Medium CTF - Tracing the Execution Chain During an incident response, you collect the following sequence of events from Windows Event Logs and Sysmon on a compromised server: You also find the WMI…

SRH hard

SRH hard

July 29, 2026

Hard CTF - Full Attack Reconstruction You are the lead responder on a compromised domain-joined workstation. You have collected the following evidence: Excerpt from PowerShell Script Block Logging…

SRH easy 2

SRH easy 2

July 29, 2026

Easy CTF 2 - Registry Investigation You are given read access to the registry of a compromised machine. Navigating to: You find the following under the binary value (parsed for readability): You check…

SRH easy 1

SRH easy 1

July 29, 2026

Easy CTF 1 - Spot the Modified Service A junior analyst is reviewing a Windows workstation after a user reported strange behavior. They pull the current recovery configuration for the Windows Update…

MER medium

MER medium

July 29, 2026

Medium CTF - Log the Attacker You are a SOC analyst. Your SIEM fired an alert for unusual mailbox activity on the account . You pull the full event timeline for that account over the past 24 hours:…

MER hard

MER hard

July 29, 2026

Hard CTF - Full Inbox Takeover You are investigating a suspected Business Email Compromise (BEC) at a mid-sized company. The CFO's account ( ) was reportedly used to approve a fraudulent wire transfer…

MER easy 2

MER easy 2

July 29, 2026

Easy CTF 2 - Forwarding Gone Wrong You are reviewing a Microsoft 365 audit log after a finance employee reported that a vendor "never received" an invoice they sent last week. You find this entry in…

MER easy 1

MER easy 1

July 29, 2026

Easy CTF 1 - Spot the Rule A user calls the help desk saying they never received a password reset email they requested. You log into the admin panel and pull up their mailbox rules. You find this rule…

DM medium

DM medium

July 29, 2026

Medium CTF - WMI Event Subscription Analysis During a threat hunt, you query WMI event subscriptions on a server using PowerShell: You get back the following: You also find a linked pointing to: The…

DM hard

DM hard

July 29, 2026

Hard CTF - Logic Bomb Investigation A recently terminated employee's workstation has been flagged. SIEM alerts showed no malicious activity during their employment. A forensic image of the machine was…

DM easy 2

DM easy 2

July 29, 2026

Easy CTF 2 - Registry Persistence Hunt You are analyzing a suspicious endpoint. A colleague exported the following registry key for you to review: The file has a creation date from six days ago. It…

DM easy 1

DM easy 1

July 29, 2026

Easy CTF 1 - Suspicious Scheduled Task You are doing a routine review of a Windows workstation that was flagged by endpoint analysis. You run the following command to list scheduled tasks: Among the…

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.

Something went wrong. A browser extension may be interfering with this page. Reload ×