Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.
SNAC Attack
Stale Network Address Configurations (SNAC) Attack Networks change all the time - servers get decommissioned, IPs get reassigned, services move around. The problem is that the old records pointing to…
SMB Abuse
Server Message Block (SMB) Abuse Server Message Block (SMB) is a network protocol used by Windows machines to share files, printers, and other resources across a local network. It is deeply integrated…

responder
This is a lab from John Strand 's Information Security Core Skills Course: https://www.antisyphontraining.com/product/information-security-core-skills-tm/ Responder Both VMs In this lab we are going…
Internal Spearphishing
Internal Spearphishing Most phishing attacks come from outside - random emails, fake domains, obvious scams. Internal spearphishing is different. Here, the attacker already has a foot in the door.…

SNAC medium
Medium CTF - Address Claim You are reviewing firewall logs after a helpdesk ticket comes in - multiple users report that their credentials stopped working after connecting to the internal HR portal.…

SNAC hard
Hard CTF - Full SNAC Chain You are a SOC analyst. A SIEM alert fires at 03:14 AM flagging unusual authentication volume from the service account . You start pulling data across three sources. SIEM…

SNAC easy 2
Easy CTF 2 - Dead Record Recon You are doing a security audit and run a DNS zone dump on your internal domain. You find the following records still present: After checking the asset inventory, none of…

SNAC easy 1
Easy CTF 1 - Spotting the Ghost Your team decommissioned a server called three months ago. The machine was shut down and removed from the rack. During a routine check, a junior analyst notices that…

SMB medium
Medium CTF - Relay Attack You are investigating an incident. The logs show the following sequence of events: No cracking took place. CORP\dbadmin never logged into SERVER-02 directly. Question How did…

SMB hard
Hard CTF - Full Domain Compromise You are performing a post-incident forensic review. The timeline of events is reconstructed below: The svc_backup account was a standard service account with no…

SMB easy 2
Easy CTF 2 - Poisoned Network You are reviewing SIEM alerts from the past hour. One alert stands out: Shortly after, several workstations attempted to authenticate to 192.168.1.99. Question What is…

SMB easy 1
Easy CTF 1 - Captured Hash You are monitoring network traffic on a Windows corporate network. A new machine just joined the network and almost immediately you see the following in your capture: The…