This site is in BETA. Labs are still being adjusted and re-structured and may not work as intended.

Resources

BHIS Blog

Current cybersecurity commentary and technical guidance.

evilginx

evilginx

July 29, 2026

Evilginx Lab Goal The goal of this lab is to introduce Evilginx , a reverse-proxy phishing framework that has been used in real-world phishing campaigns. In this lab, we will demonstrate how attackers…

beef

beef

July 29, 2026

Browser Exploitation Framework (BeEF) Ubuntu VM In this lab we will Start the BeEF framework Hook a victim browser using a JavaScript hook Explore what information BeEF collects automatically Execute…

atomic red team

atomic red team

July 29, 2026

This is a lab from John Strand 's Active Defense and Cyber Deception Course: https://www.antisyphontraining.com/product/active-defense-and-cyber-deception-with-john-strand/ Atomic Red Team And…

Dynamic Link Library Hijacking

Dynamic Link Library Hijacking

July 29, 2026

Dynamic Link Library(DLL) Hijacking A DLL (Dynamic Link Library) is a file that contains code and data that multiple programs can use at the same time. Think of it like a shared toolbox - instead of…

NUA medium

NUA medium

July 29, 2026

Medium CTF - Persistence Chain You are a SOC analyst responding to an alert. An EDR product flagged suspicious process activity on a server at 03:12 AM. You pull the process tree and the relevant…

NUA hard

NUA hard

July 29, 2026

Hard CTF - Full Intrusion Timeline You are conducting a post-incident investigation. An alert fired four days after the initial compromise - meaning you are working backward from limited artifacts.…

NUA easy 2

NUA easy 2

July 29, 2026

Easy CTF 2 - Log Hunt You are reviewing Windows Security event logs on a domain controller. The logs were pulled after a threat hunter flagged unusual activity overnight. You find the following log…

NUA easy 1

NUA easy 1

July 29, 2026

Easy CTF 1 - Spot the Account You are reviewing the local user list on a Windows workstation after an alert fired on the endpoint. The machine belongs to a regular employee - no admin work is…

MS medium

MS medium

July 29, 2026

Medium CTF - Registry and Service Abuse During an incident response, you image a compromised workstation and start combing through its registry. You find the following key: You pull the binary and…

MS hard

MS hard

July 29, 2026

Hard CTF - Full Persistence Chain You are responding to an alert on a Windows Server 2019 machine that handles internal file sharing. The SIEM correlated four events across a 20-minute window. Your…

MS easy 2

MS easy 2

July 29, 2026

Easy CTF 2 - Event Log Dig You are reviewing Windows Event Logs on a machine after an alert fired. You find the following entry in the System log: The machine is a standard workstation. No software…

MS easy 1

MS easy 1

July 29, 2026

Easy CTF 1 - Spot the Service A junior analyst is reviewing the services installed on a Windows endpoint that was flagged by the SIEM. They pull the service list and notice this entry among the usual…

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.

Something went wrong. A browser extension may be interfering with this page. Reload ×