Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

PA easy 1
Easy CTF 1 - Badge Clone Basics A security guard notices a man standing near the office entrance for about 10 minutes. He holds his phone close to employees as they badge in, never actually entering…

HSTS medium
Medium CTF - Session Hijack You are a security analyst reviewing an incident. A user reported that their account was accessed by someone else, even though they never shared their password. The user…

HSTS hard
Hard CTF - Full MITM Attack You are conducting a post-incident forensic review. An attacker positioned themselves between a victim and the internet on a corporate guest Wi-Fi network. The following is…

HSTS easy 2
Easy CTF 2 - Cookie Grab You are reviewing a Wireshark capture from a compromised network segment. A victim logged into a web application while connected to a rogue access point. You spot the…

HSTS easy 1
Easy CTF 1 - Spotting the Strip You are analyzing HTTP traffic captured on a public Wi-Fi network. A user visited their bank's website, which is supposed to always use HTTPS. You find the following in…
Site Walkthrough
Site Walkthrough A site walkthrough is when the defenders physically go to the location being investigated. They walk through the space, inspect hardware, check logs on-site, and look for anything…
Physical Security Review
Physical Security Review Physical security is what stands between an attacker and the hardware, people, and data inside a building. When people think about hacking, they usually picture someone behind…

SW medium
Medium CTF - Wireless Anomaly Hunt You run a wireless spectrum scan during the walkthrough. The company's authorized access points are all documented in the network inventory. Your scan picks up the…

SW hard
Hard CTF - Full Physical Intrusion Timeline A security alert was triggered at 2:30 AM by an IDS rule. Your team conducts a full site walkthrough the next morning. You pull data from every available…

SW easy 2
Easy CTF 2 - Reading the Badge Logs You are reviewing badge reader logs after a walkthrough flagged an unlocked server room door. The door should require badge access at all times. The log for the…

SW easy 1
Easy CTF 1 - Spotting the Rogue Device During a site walkthrough, you inspect the server room. Everything looks normal at first glance - until you crouch down and check the back of the main switch.…

PSR medium
Medium CTF - Social Engineering Scenario You are reviewing an incident report. A USB drive was found plugged into a workstation in the accounting department. The drive contained a keylogger. CCTV…