This site is in BETA. Labs are still being adjusted and re-structured and may not work as intended.

Resources

BHIS Blog

Current cybersecurity commentary and technical guidance.

ISO easy 2

ISO easy 2

July 29, 2026

Easy CTF 2 - Firewall Rule Reconstruction You are reviewing firewall rules on a compromised Linux host that was isolated at the host level. A colleague ran the following commands during the incident:…

ISO easy 1

ISO easy 1

July 29, 2026

Easy CTF 1 - Blocked but Not Gone You are a SOC analyst responding to an alert. A workstation on the internal network has been flagged for suspicious outbound traffic. Your team has already applied a…

FLA medium

FLA medium

July 29, 2026

Medium CTF – Lateral Movement Detection During an investigation, you review firewall logs from an internal segment. You notice this sequence: The source host normally only communicates with a file…

FLA hard

FLA hard

July 29, 2026

Hard CTF – Incident Timeline Reconstruction You are given firewall logs collected during a suspected breach: Host is a public-facing web server. Host is an internal workstation. Question What is the…

FLA easy 2

FLA easy 2

July 29, 2026

Easy CTF 2 – Blocked Traffic Investigation A firewall alert shows repeated blocked outbound connections from an internal workstation. Question What is the most likely explanation? Flags (Choose One)…

FLA easy 1

FLA easy 1

July 29, 2026

Easy CTF 1 – Suspicious Connection Hunt You are reviewing firewall logs after users reported slow network performance. You notice the same external IP contacting many internal hosts within a short…

EPA medium

EPA medium

July 29, 2026

Medium CTF - Credential Dumping Investigation A Wazuh alert fired on a domain controller at 02:14 AM. You pull the relevant logs and find the following sequence of events: No interactive user session…

EPA hard

EPA hard

July 29, 2026

Hard CTF - Full Lateral Movement Chain You are a SOC analyst. An alert fires from your EDR at 03:40 AM. You pull the full timeline for the affected hosts over the last 30 minutes. Timeline Question At…

EPA easy 2

EPA easy 2

July 29, 2026

Easy CTF 2 - Registry Persistence You are investigating a machine that keeps re-infecting itself after the malware file is deleted. You pull the registry hive and find the following entry: The…

EPA easy 1

EPA easy 1

July 29, 2026

Easy CTF 1 - Suspicious Process Hunt You are reviewing endpoint telemetry from a Windows workstation after a user reported their machine was "acting slow." You find the following process tree in your…

EA medium

EA medium

July 29, 2026

Medium CTF - Persistence Mechanism During an incident investigation, you run DeepBlueCLI against the System and Security event logs of a compromised machine. Among other findings, you pull the…

EA hard

EA hard

July 29, 2026

Hard CTF - Full Endpoint Compromise You are handed a Velociraptor hunt report for an endpoint flagged by your SIEM. Your job is to piece together the full attack chain from the evidence below.…

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.

Something went wrong. A browser extension may be interfering with this page. Reload ×