Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

burp suite
Burp Suite Burp Suite Community Edition Ubuntu VM Burp Suite Community Edition is the free version of the industry-standard web application security testing toolkit made by PortSwigger. It sits…
Insider Threat
Insider Threat An insider threat happens when someone who already has legitimate access to an organization uses that access in a way they shouldn’t. This can be intentional (data theft, sabotage) or…
External Service Exploitation
Exploited External Service External service exploitation happens when an attacker gains access to a system by abusing a service that is exposed to the internet These services are not websites only -…
External Password Spray
External Password Spray An external password spray is a login attack where attackers try a small set of common passwords against many accounts from outside the organization. Instead of guessing many…

UCA medium
Medium CTF - Cloud Privilege Escalation You have access to a low-privileged cloud user account created for a junior developer Your goal is to determine how this account can gain higher permissions…

UCA hard
Hard CTF - Full Cloud Environment Takeover An attacker already has user-level access to a cloud account. Security alerts indicate logging was disabled shortly after Your goal is to identify how full…

UCA easy 2
Easy CTF 2 - Exposed API Key A developer pushed a project to a public repository. While reviewing the files, you suspect sensitive cloud credentials were exposed. Your goal is to identify the risky…

UCA easy 1
Easy CTF 1 - Suspicious Cloud Login A SOC analyst notices a successful login to a cloud admin account outside of normal business hours. Your goal is to identify what makes this login suspicious.…

TR medium
Medium CTF - Partner Pivot Scenario A trusted partner has VPN access to a restricted network segment. You notice the following timeline: The partner normally accesses only one application server.…

TR hard
Hard CTF - Supply Chain Access Abuse An investigation begins after unusual cloud activity appears in logs. You observe: The vendor integration is supposed to upload reports only once per day. Question…

TR easy 2
Easy CTF 2 - Service Account Misuse You are checking SIEM alerts related to a service account used by a third-party backup provider. Logs show: This account normally only reads storage snapshots.…

TR easy 1
Easy CTF 1 - Suspicious Vendor Login You are reviewing authentication logs after a partner account triggered an alert. You find the following entries: The vendor normally connects from a fixed…