Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.
Cleartext Passwords in Files
Cleartext Passwords in Files When passwords are stored as plain text inside files on a system - no hashing, no encryption, nothing - they become a free gift to any attacker who manages to get a…
Access Token Manipulation
Access Token Manipulation When you log into a system, it does not keep asking for your password on every request. Instead, it gives you a token - a small piece of data that says "this person is…
Supply Chain Attack
Supply Chain Attack A supply chain attack happens when an attacker does not target your systems directly - they go after the software or tools you already trust. Instead of breaking down your front…
Physical Access
Physical Access Physical access attacks happen when an attacker gets into a place they should not be - a server room, an office, a data center, or anywhere they can touch hardware directly. Unlike…
Exploitation Of Missing HSTS
Exploitation of Missing HTTP Strict Transport Security (HSTS) When you visit a website over HTTPS, your browser and the server agree to keep the connection encrypted. HSTS is a security header that…

SCA medium
Medium CTF - Hunting SUNBURST Indicators You are a threat hunter at a company that ran SolarWinds Orion version 2020.2. Leadership wants to know if the environment was compromised by SUNBURST. You…

SCA hard
Hard CTF - Full Supply Chain Compromise Simulation You are the lead incident responder. A Fortune 500 company has called you in after their SOC noticed unusual activity. You need to reconstruct the…

SCA easy 2
Easy CTF 2 - Log Analysis: Something Phoned Home You are reviewing DNS query logs from a workstation that recently ran an enterprise software update. The logs show normal traffic - except for one…

SCA easy 1
Easy CTF 1 - Spotting the Tampered Update Your company uses an enterprise IT management platform. The security team flagged an alert after the latest update was pushed to all endpoints. You pull the…

PA medium
Medium CTF - Impersonation Investigation Your company's receptionist receives a call in the morning from someone claiming to be from the building's HVAC maintenance company. They say a technician will…

PA hard
Hard CTF - Full Facility Breach You are a security analyst conducting a post-incident review. Over three days, your team has pieced together the following timeline: Day 1 - Monday, 09:10 AM An unknown…

PA easy 2
Easy CTF 2 - Tailgate Trace You are reviewing badge access logs after an incident. The logs show the following for a restricted door: A USB keylogger was found plugged into a workstation inside that…