Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

volatilityLab2
Volatility Part 2 Ubuntu VM Part1 Part2 Part3 Part4 This lab should be done as a continuation of the Volatility Documentation This is the 2nd of 4 parts Setup The commands will be in this template:…

volatilityLab1
Volatility For the Ubuntu VM Part1 Part2 Part3 Part4 This lab should be done as a continuation of the Volatility Documentation This is the 1st of 4 parts Start In this lab you will be given 4…

dionaeaLab
Dionaea Ubuntu VM In this lab we will Observe how it captures malicious connection attempts View logs and captured malware samples Understand its modular architecture Let's start Open up a terminal if…
deceptionSystems
Deception Systems The goal of deception technology is to draw cybercriminals to a trap or decoy instead of an organization's real assets. In order to fool the criminal into thinking they have…

beelzebubLab
Beelzebub Ubuntu VM Beelzebub is an advanced honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks. It offers a low code approach for easy…

azureLab
Azure Any VM Setup First things first, create an account here: https://azure.microsoft.com/en-us/pricing/free-services And get your sample logs from here:…
webSecurity
Web Security Overview Web applications are one of the biggest attack surfaces in any organization For SOC analysts, understanding web security means knowing how attacks look in logs, alerts, and…

webLabPart2
SQL Injection Lab Windows VM If you didn't do the 1st Part , go back We have 4 routes : - Vulnerable login - Secure login - View the lab's access logs - Reset DB Going into Microsoft Edge you can…

webLabPart1
SQL Injection Lab Windows VM The objective for this lab is to Understand how SQL Injection works See how it appears in logs See the mitigation ( how a SOC analyst should react ) See the difference…
browser malware lab
Browser Malware Lab — Cookie Stealer + Extension Forensics This document does not contain source code files. You will download the lab folder (ZIP) that includes all scripts and files. Below you will…
browser malware
Browser Malware 1. Overview Browser malware is any malicious code or configuration that abuses a web browser or its ecosystem (extensions, plugins, saved credentials, profiles, web applications, or…
zeek lab
Zeek Lab - Investigating a malicious pcap Objectives Run Zeek over this pcap and inspect Zeek logs. Extract DNS, HTTP and TLS indicators with . Identify suspicious HTTP POSTs and TLS SNI values.…