This site is in BETA. Labs are still being adjusted and re-structured and may not work as intended.

Resources

BHIS Blog

Current cybersecurity commentary and technical guidance.

Kerberoasting

Kerberoasting

July 29, 2026

Kerberoasting Kerberoasting is an Active Directory attack technique that targets service accounts It does not rely on malware or exploits. Instead, it abuses how Kerberos authentication is designed to…

Internal Password Spray

Internal Password Spray

July 29, 2026

Internal Password Spray A password spray attack is when an attacker tries a small set of commonly used passwords across a large number of accounts. Instead of hammering one account with hundreds of…

Credential Harvesting

Credential Harvesting

July 29, 2026

Credential Harvesting When attackers get into a network, one of the first things they go after is credentials - usernames and passwords. Not because they need one account, but because one account…

Broadcast Multicast Protocol Poisoning

Broadcast Multicast Protocol Poisoning

July 29, 2026

Broadcast / Multicast Protocol Poisoning Networks rely on broadcast and multicast protocols to do things like resolve hostnames, find services, and route traffic. The problem is that these protocols…

Unauthorized Cloud Access

Unauthorized Cloud Access

July 29, 2026

Unauthorized Cloud Access When an attacker accesses SaaS platforms or cloud infrastructure without authorization, it is known as unauthorized cloud access. Cloud servers, storage, identities, and…

Trusted Relationship

Trusted Relationship

July 29, 2026

Compromised Trusted Relationship A trusted relationship issue happens when attackers abuse access that already exists between an organization and a third party - for example a vendor, contractor, or…

Social Engineering

Social Engineering

July 29, 2026

Social Engineering Social engineering is when an attacker targets people instead of systems . Instead of breaking technical defenses directly, they convince someone to help them - often without the…

Phishing

Phishing

July 29, 2026

Phishing Phishing is an attack in which users are duped into divulging login information, opening infected files, or clicking on malicious links. It typically arrives via email, but it can also arrive…

sqlmap

sqlmap

July 29, 2026

SQLMap Ubuntu VM Lab Goal The goal of this lab is to introduce sqlmap , a tool used to automate the detection and exploitation of SQL injection vulnerabilities. In this lab you will Understand the…

SocialEngineerToolkit

SocialEngineerToolkit

July 29, 2026

Social Engineering Toolkit (SET) Ubuntu VM In this lab we will Clone a real website to create a credential harvester Send a simulated phishing payload using SET's built-in tools Understand how…

Shodan

Shodan

July 29, 2026

Shodan Goal: Learn what Shodan can do using the web interface In this lab you will Understand what Shodan is and how it works Use the Shodan web UI to search the internet Read service banners and…

scoutsuite

scoutsuite

July 29, 2026

ScoutSuite For the Ubuntu VM Lab Objective The objective of this lab is to use Scout Suite to audit an AWS cloud environment and identify critical security misconfigurations related to Identity Access…

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.

Something went wrong. A browser extension may be interfering with this page. Reload ×