Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

PA easy 2
Easy CTF 2 - Stale Credentials You are running an AD audit and export a list of all enabled user accounts. Among the results: Question Why is this account a security risk even though it has never been…

PA easy 1
Easy CTF 1 - Find the Overprivileged Account You are reviewing Active Directory group memberships after a routine audit request. You pull the following data: Question What is the most critical finding…

NTH medium
Medium CTF – Lateral Movement Discovery You are analyzing east-west network traffic after an alert from a domain controller. You find this pattern: Question What does this activity MOST likely…

NTH hard
Hard CTF – Data Exfiltration Investigation During a hunt focused on outbound traffic, you observe the following: No backup jobs are scheduled at this time, and the destination has never been contacted…

NTH easy 2
Easy CTF 2 – Basic C2 Detection While reviewing DNS logs, you notice one endpoint making thousands of DNS queries with long random-looking subdomains. Example: Each query is unique and appears every…

NTH easy 1
Easy CTF 1 – Suspicious Connection Hunt You are reviewing basic network flow logs from a small office network. One internal workstation suddenly starts making repeated connections every 60 seconds to…

MA medium
Medium CTF - Injected Process You are investigating a memory image from a compromised endpoint. The SOC received an alert about unusual outbound traffic, but no new processes were found on disk. You…

MA hard
Hard CTF - Full Memory Investigation A hospital workstation was taken offline after the EDR flagged unusual behavior at 02:14 AM. No one was supposed to be logged in at that time. You receive a full…

MA easy 2
Easy CTF 2 - String Extraction You dump the memory of a suspicious process and run against it. Among the output, you find the following lines: The process that owns this memory region is . Question…

MA easy 1
Easy CTF 1 - Process Hunt You are analyzing a memory image from a Windows workstation flagged by the SIEM. You run in Volatility and get the following output (trimmed): Question One of the processes…

ISO medium
Medium CTF - Lateral Movement Interrupted You are analyzing a security incident. The timeline below was reconstructed from SIEM logs: Question What does the 08:52 event tell you about the state of the…

ISO hard
Hard CTF - Containment Under Fire You are the on-call SOC analyst at 02:30. An EDR alert fires on a domain controller (DC01). You begin investigating and collect the following data points within the…