Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

hayabusa
Hayabusa Ubuntu VM The objective of this lab is to use Hayabusa to analyze Sysmon logs and detect suspicious activity related to process creation, network connections, and authentication events. If…

Elastic Doc Cloud
Elasticsearch is a distributed search and analytics engine, scalable data store, and vector database built on Apache Lucene. It’s optimized for speed and relevance on production-scale workloads. Use…

elastic security
Please go though the documentation and setup for the Cloud Version Elastic Security GOAL Set up and use Elastic SIEM on your system Learn how to ingest logs and visualize them Learn how to use SIEM…

deepbluecli
DeepBlueCLI DeepBlueCLI is a free tool by Eric Conrad that demonstrates some amazing detection capabilities. It also has some checks that are effective for showing how UEBA style techniques can be in…

canarytokens
Canarytokens Any VM First, we will need to navigate to the canarytokens server from a system with Microsoft Word on it: https://www.canarytokens.org/generate# Search for Now, let's create a token Word…

ac hunter
AC Hunter Now, let's play with AC Hunter! Please go to You might be prompted by a warning stating that your connection isn't private. This is Okay . Simply click Advanced and then click Continue The…
Isolation
Isolation When a system gets compromised, the first instinct is to pull the plug. That instinct is right - but the execution matters a lot. Isolation is the act of cutting a compromised system or…
Firewall Log Analysis
Firewall Log Analysis Firewall log analysis is the process of reviewing the records generated by a firewall to understand what is happening on a network. Every connection attempt, blocked packet, or…
Endpoint Security Protection Analysis
Endpoint Security Protection Analysis An endpoint is any device that connects to a network - laptops, workstations, servers, phones. Endpoints are one of the most targeted surfaces in real attacks…
Endpoint Analysis
Endpoint Analysis An endpoint is any device connected to a network - a laptop, a workstation, a server, a phone. When something goes wrong on a network, the endpoint is usually where the story starts…

UEBA medium
Medium CTF - Insider Threat Investigation Your UEBA platform has flagged dan.Constantin , a developer who gave his two-week notice last Monday. His baseline over the past year: Accesses only his…

UEBA hard
Hard CTF - Full Behavioral Attack Chain You are the senior analyst on call. At 03:20, your UEBA platform fires a Critical alert. You have raw data from four entities. Your job is to reconstruct what…