This site is in BETA. Labs are still being adjusted and re-structured and may not work as intended.

Resources

BHIS Blog

Current cybersecurity commentary and technical guidance.

LS medium

LS medium

July 29, 2026

Medium CTF - GPO Abuse Your team is investigating unusual activity across multiple machines in a corporate domain. Several users report that a new shortcut appeared on their desktops after logging in.…

LS hard

LS hard

July 29, 2026

Hard CTF - Domain-Wide Persistence Your incident response team is called in after an alert fires on a domain controller. You pull the following artifacts during your investigation. Impacket log…

LS easy 2

LS easy 2

July 29, 2026

Easy CTF 2 - Registry Trail You are investigating a compromised machine. The user says something feels off every time they log in, but nothing obvious shows on the desktop. You run a registry query…

LS easy 1

LS easy 1

July 29, 2026

Easy CTF 1 - Suspicious Startup Script You are doing a routine review of a Windows workstation after a user reported their machine running slow after every login. You find the following entry in the…

DLL medium

DLL medium

July 29, 2026

Medium CTF - Privilege Through a Hijacked Load During an incident response, you find the following on a compromised machine: The real lives in . Question What outcome did the attacker achieve by…

DLL hard

DLL hard

July 29, 2026

Hard CTF - Persistence via Boot-Time Hijack Your team is investigating a machine that keeps beaconing out to an external IP even after malware was supposedly cleaned. You collect the following…

DLL easy 2

DLL easy 2

July 29, 2026

Easy CTF 2 - Missing DLL Hunt You are analyzing a process monitor log captured on a workstation. You notice the following entries: The next day, after a complaint about slow performance, you run the…

DLL easy 1

DLL easy 1

July 29, 2026

Easy CTF 1 - Wrong Place, Right Name A developer reports that after installing a new application, something feels off. You inspect the application folder and find this: The application loads at…

AS medium

AS medium

July 29, 2026

Medium CTF - Malicious Shim Database You discover the following command in PowerShell history: Shortly after, security logs show that a specific executable stopped reporting certain file paths during…

AS hard

AS hard

July 29, 2026

Hard CTF - Defense Evasion Scenario During incident response, you observe: A suspicious file in Registry entries pointing to the file An endpoint detection tool failing to detect a known malicious…

AS easy 2

AS easy 2

July 29, 2026

Easy CTF 2 - Hidden Service An analyst notices that a security tool cannot see a specific Windows service, even though it is clearly running when checked manually. Further investigation shows an…

AS easy 1

AS easy 1

July 29, 2026

Easy CTF 1 - Suspicious Compatibility Entry During a routine registry review, you notice a new entry under: The entry references a recently created file located in . Question What does this most…

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.

Something went wrong. A browser extension may be interfering with this page. Reload ×