Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

ISO easy 2
Easy CTF 2 - Firewall Rule Reconstruction You are reviewing firewall rules on a compromised Linux host that was isolated at the host level. A colleague ran the following commands during the incident:…

ISO easy 1
Easy CTF 1 - Blocked but Not Gone You are a SOC analyst responding to an alert. A workstation on the internal network has been flagged for suspicious outbound traffic. Your team has already applied a…

FLA medium
Medium CTF – Lateral Movement Detection During an investigation, you review firewall logs from an internal segment. You notice this sequence: The source host normally only communicates with a file…

FLA hard
Hard CTF – Incident Timeline Reconstruction You are given firewall logs collected during a suspected breach: Host is a public-facing web server. Host is an internal workstation. Question What is the…

FLA easy 2
Easy CTF 2 – Blocked Traffic Investigation A firewall alert shows repeated blocked outbound connections from an internal workstation. Question What is the most likely explanation? Flags (Choose One)…

FLA easy 1
Easy CTF 1 – Suspicious Connection Hunt You are reviewing firewall logs after users reported slow network performance. You notice the same external IP contacting many internal hosts within a short…

EPA medium
Medium CTF - Credential Dumping Investigation A Wazuh alert fired on a domain controller at 02:14 AM. You pull the relevant logs and find the following sequence of events: No interactive user session…

EPA hard
Hard CTF - Full Lateral Movement Chain You are a SOC analyst. An alert fires from your EDR at 03:40 AM. You pull the full timeline for the affected hosts over the last 30 minutes. Timeline Question At…

EPA easy 2
Easy CTF 2 - Registry Persistence You are investigating a machine that keeps re-infecting itself after the malware file is deleted. You pull the registry hive and find the following entry: The…

EPA easy 1
Easy CTF 1 - Suspicious Process Hunt You are reviewing endpoint telemetry from a Windows workstation after a user reported their machine was "acting slow." You find the following process tree in your…

EA medium
Medium CTF - Persistence Mechanism During an incident investigation, you run DeepBlueCLI against the System and Security event logs of a compromised machine. Among other findings, you pull the…

EA hard
Hard CTF - Full Endpoint Compromise You are handed a Velociraptor hunt report for an endpoint flagged by your SIEM. Your job is to piece together the full attack chain from the evidence below.…