Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

SE medium
Medium CTF - Credential Abuse Investigation After a phishing campaign, a security analyst reviews authentication logs. They observe: A successful login from a new country The login used valid…

SE hard
Hard CTF - Multi‑Stage Social Engineering Campaign Your team is investigating a suspected compromise. The following timeline is reconstructed: Public employee information is collected from social…

SE easy 2
Easy CTF 2 - Fake Support Request An employee receives a phone call from someone claiming to be from the security team. The caller says: “We detected suspicious activity on your account. Please read…

SE easy 1
Easy CTF 1 - Suspicious Email Analysis A user reports an email that looks like it came from internal IT support. The user says they do not recognize the sender domain. Question Which clue most…

phish medium
Medium CTF – Credential Abuse A user reports unusual logins to their cloud account shortly after clicking a link in an email. You are asked to review authentication logs. Observation Logs show:…

phish hard
Hard CTF – Phish to Network Access A finance employee clicked a link in an email and entered their credentials on a fake login page. A few hours later, suspicious activity is detected on internal…

phish easy 2
Easy CTF 2 – Suspicious Email An employee reports an email that looks like it came from Microsoft. The email warns that the user’s mailbox is full and requires immediate action. Observation Key…

phish easy 1
Easy CTF 1 – Fake Login Page You receive an email claiming to be from your company’s IT department. It asks you to log in to fix an urgent security issue. You click the link and see a page that looks…

IT medium
Medium CTF – Privilege Misuse Investigation During a permissions review, you find that a support engineer account was recently added to the "Domain Admins" group. Event logs show: No change ticket…

IT hard
Hard CTF – Insider Data Exfiltration Case You are investigating a potential insider incident. Network and endpoint logs show: The user submitted a resignation earlier that day. Question Which…

IT easy 2
Easy CTF 2 – Basic Log Correlation You are reviewing SIEM alerts generated during a routine shift. Logs show the following sequence for one user account: No maintenance or admin work was scheduled at…

IT easy 1
Easy CTF 1 – Suspicious User Activity A security analyst reviews login events for an employee account. You see the following timeline: The employee normally works in marketing and has never accessed…