This site is in BETA. Labs are still being adjusted and re-structured and may not work as intended.

Resources

BHIS Blog

Current cybersecurity commentary and technical guidance.

Server Analysis

Server Analysis

July 29, 2026

Server Analysis A server is considered compromised when someone gains access or control without authorization. This doesn’t always mean the attacker fully owns the machine - sometimes they only have a…

Permissions Audit

Permissions Audit

July 29, 2026

Permissions Audit Every system has users, and every user has permissions. A permissions audit is how defenders figure out who can access what - and whether that access makes any sense. The goal is…

Network Threat Hunting

Network Threat Hunting

July 29, 2026

Network Threat Hunting Network threat hunting is the practice of actively searching network traffic for signs of malicious behavior instead of waiting for alerts to fire. It focuses on finding…

Memory Analysis

Memory Analysis

July 29, 2026

Memory Analysis When a system gets compromised, attackers leave traces. Not always on disk - sometimes only in memory. Memory analysis (also called memory forensics) is the process of pulling a…

wazuh

wazuh

July 29, 2026

Wazuh Cloud SIEM & XDR Ubuntu & Windows VM The objective of this lab is to deploy Wazuh Agents to a cloud-hosted SIEM environment, configure File Integrity Monitoring (FIM), simulate malicious…

volatilityLab4

volatilityLab4

July 29, 2026

Part1 Part2 Part3 Part4 This is the 4th of 4 parts Setup The commands will be in this template: Your turn Try to find the malware using the commands in the Volatility Documentation and then scroll…

volatilityLab3

volatilityLab3

July 29, 2026

Part1 Part2 Part3 Part4 This is the 3rd of 4 parts Setup The commands will be in this template: Your turn Try to find the malware using the commands in the Volatility Documentation and then scroll…

volatilityLab2

volatilityLab2

July 29, 2026

Part1 Part2 Part3 Part4 This is the 2nd of 4 parts Setup The commands will be in this template: Your turn Try to find the malware using the commands in the Volatility Documentation and then scroll…

volatilityLab1

volatilityLab1

July 29, 2026

Part1 Part2 Part3 Part4 This is the 1st of 4 parts Start In this lab you will be given 4 different linux memory dumps located in , they all have malware inside and your task is to find where is the…

velociraptor

velociraptor

July 29, 2026

Velociraptor In this lab we will be installing and using Velociraptor to look at the various IR artifacts on your computer. Check out their website here: Velociraptor is a free EDR that can help us…

honeybadger

honeybadger

July 29, 2026

HoneyBadger Website Description Used to identify the physical location of a web user with a combination of geolocation techniques using a browser's share location feature, the visible WiFi networks,…

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.

Something went wrong. A browser extension may be interfering with this page. Reload ×