Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

MF medium
Medium CTF - Flash Memory Tampering During an incident response engagement, you collect a memory dump and a firmware dump from a compromised server. You run a hash comparison between the firmware…

MF hard
Hard CTF - Full Firmware Implant Your team is conducting a forensic investigation on a high-value target within a corporate network. The machine belongs to an executive and has been behaving strangely…

MF easy 2
Easy CTF 2 - UEFI Boot Anomaly A technician is investigating a machine that keeps re-infecting itself after full OS reinstalls. They pull the CHIPSEC report and notice the following: The machine had…

MF easy 1
Easy CTF 1 - Firmware String Extraction A security analyst extracts a firmware binary from a workstation that was flagged during routine auditing. They run a basic strings analysis on it and find the…

MDR medium
Medium CTF - Memory Forensics A threat hunter runs a memory dump on a suspected endpoint and uses a tool to list all kernel modules currently loaded. The output shows the following: The last entry has…

MDR hard
Hard CTF - Full Kernel Rootkit Investigation Your SOC receives an alert from an EDR tool that briefly fired on a host before going silent. You pull what logs you can and piece together the following…

MDR easy 2
Easy CTF 2 - Registry Persistence Hunt You are investigating a Windows machine after an alert fired on unusual boot behavior. You pull the registry and find this entry: The file is not present in any…

MDR easy 1
Easy CTF 1 - Spot the Suspicious Driver A junior analyst is reviewing the list of installed drivers on a Windows endpoint that triggered an alert. The system looks clean at first glance, but one entry…

MBP medium
Medium CTF - BeEF Hooked Session During an incident investigation, a memory dump from a victim's browser reveals the following JavaScript snippet running inside an active tab: The victim's browser has…

MBP hard
Hard CTF - Full Plugin Compromise Chain You are an analyst investigating a breach at a financial company. Here is what you have found so far: Timeline of events: Time Event 09:12 User receives a…

MBP easy 2
Easy CTF 2 - Stolen Cookie You are reviewing firewall logs for a workstation that has a suspicious browser extension installed. You notice the following outbound request made by the browser process:…

MBP easy 1
Easy CTF 1 - Suspicious Extension A user reports their browser is behaving strangely. You pull a list of installed Chrome extensions from their machine and find the following entry: The user says they…