Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

LS medium
Medium CTF - GPO Abuse Your team is investigating unusual activity across multiple machines in a corporate domain. Several users report that a new shortcut appeared on their desktops after logging in.…

LS hard
Hard CTF - Domain-Wide Persistence Your incident response team is called in after an alert fires on a domain controller. You pull the following artifacts during your investigation. Impacket log…

LS easy 2
Easy CTF 2 - Registry Trail You are investigating a compromised machine. The user says something feels off every time they log in, but nothing obvious shows on the desktop. You run a registry query…

LS easy 1
Easy CTF 1 - Suspicious Startup Script You are doing a routine review of a Windows workstation after a user reported their machine running slow after every login. You find the following entry in the…

DLL medium
Medium CTF - Privilege Through a Hijacked Load During an incident response, you find the following on a compromised machine: The real lives in . Question What outcome did the attacker achieve by…

DLL hard
Hard CTF - Persistence via Boot-Time Hijack Your team is investigating a machine that keeps beaconing out to an external IP even after malware was supposedly cleaned. You collect the following…

DLL easy 2
Easy CTF 2 - Missing DLL Hunt You are analyzing a process monitor log captured on a workstation. You notice the following entries: The next day, after a complaint about slow performance, you run the…

DLL easy 1
Easy CTF 1 - Wrong Place, Right Name A developer reports that after installing a new application, something feels off. You inspect the application folder and find this: The application loads at…

AS medium
Medium CTF - Malicious Shim Database You discover the following command in PowerShell history: Shortly after, security logs show that a specific executable stopped reporting certain file paths during…

AS hard
Hard CTF - Defense Evasion Scenario During incident response, you observe: A suspicious file in Registry entries pointing to the file An endpoint detection tool failing to detect a known malicious…

AS easy 2
Easy CTF 2 - Hidden Service An analyst notices that a security tool cannot see a specific Windows service, even though it is clearly running when checked manually. Further investigation shows an…

AS easy 1
Easy CTF 1 - Suspicious Compatibility Entry During a routine registry review, you notice a new entry under: The entry references a recently created file located in . Question What does this most…