Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

SRH medium
Medium CTF - Tracing the Execution Chain During an incident response, you collect the following sequence of events from Windows Event Logs and Sysmon on a compromised server: You also find the WMI…

SRH hard
Hard CTF - Full Attack Reconstruction You are the lead responder on a compromised domain-joined workstation. You have collected the following evidence: Excerpt from PowerShell Script Block Logging…

SRH easy 2
Easy CTF 2 - Registry Investigation You are given read access to the registry of a compromised machine. Navigating to: You find the following under the binary value (parsed for readability): You check…

SRH easy 1
Easy CTF 1 - Spot the Modified Service A junior analyst is reviewing a Windows workstation after a user reported strange behavior. They pull the current recovery configuration for the Windows Update…

MER medium
Medium CTF - Log the Attacker You are a SOC analyst. Your SIEM fired an alert for unusual mailbox activity on the account . You pull the full event timeline for that account over the past 24 hours:…

MER hard
Hard CTF - Full Inbox Takeover You are investigating a suspected Business Email Compromise (BEC) at a mid-sized company. The CFO's account ( ) was reportedly used to approve a fraudulent wire transfer…

MER easy 2
Easy CTF 2 - Forwarding Gone Wrong You are reviewing a Microsoft 365 audit log after a finance employee reported that a vendor "never received" an invoice they sent last week. You find this entry in…

MER easy 1
Easy CTF 1 - Spot the Rule A user calls the help desk saying they never received a password reset email they requested. You log into the admin panel and pull up their mailbox rules. You find this rule…

DM medium
Medium CTF - WMI Event Subscription Analysis During a threat hunt, you query WMI event subscriptions on a server using PowerShell: You get back the following: You also find a linked pointing to: The…

DM hard
Hard CTF - Logic Bomb Investigation A recently terminated employee's workstation has been flagged. SIEM alerts showed no malicious activity during their employment. A forensic image of the machine was…

DM easy 2
Easy CTF 2 - Registry Persistence Hunt You are analyzing a suspicious endpoint. A colleague exported the following registry key for you to review: The file has a creation date from six days ago. It…

DM easy 1
Easy CTF 1 - Suspicious Scheduled Task You are doing a routine review of a Windows workstation that was flagged by endpoint analysis. You run the following command to list scheduled tasks: Among the…