Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

EA easy 2
Easy CTF 2 - Event Log Review You are reviewing Windows Security Event logs on a server after an after-hours alert. You notice the following sequence of events: Question What does this sequence of…

EA easy 1
Easy CTF 1 - Suspicious Process Hunt You are investigating a Windows workstation after a user reported their machine was acting slow. You pull the running process list using osquery and find the…

CM medium
Medium CTF - Containment Decision You are the lead responder on an active incident. An attacker has been confirmed inside the network for approximately 4 hours. So far you know: The initial access…

CM hard
Hard CTF - Full Incident Reconstruction You are conducting a post-incident review after a major breach. Your job is to reconstruct the timeline and identify where the response failed . Read the…

CM easy 2
Easy CTF 2 - Identifying the Scope Ransomware has been detected on three workstations in the finance department. The IR team lead asks you to help determine the scope of the incident before any…

CM easy 1
Easy CTF 1 - Log Triage Your company's SIEM just fired an alert at 2:14 AM. You pull up the logs and see the following activity on a domain controller: Question Based on these logs alone, what is the…

CELA medium
Medium CTF - Privilege Escalation Trail You are investigating a potential insider threat. A developer account triggered several alerts in your SIEM over two hours. Below is the condensed event…

CELA hard
Hard CTF - Full Cloud Intrusion You are a SOC analyst. It is Friday afternoon. A Falco alert fires, then another, then your SIEM starts correlating events across three different services. You open the…

CELA easy 2
Easy CTF 2 - Noisy API You are reviewing Wazuh alerts for a cloud-connected environment. Over a 10-minute window, you see the following API calls all originating from the same access key: All calls…

CELA easy 1
Easy CTF 1 - Suspicious Login You are analyzing cloud audit logs from your company's AWS environment. A security alert fired overnight. You pull the relevant log entry: John Doe is a developer based…

ADCD medium
Medium CTF – Tracking Attacker Movement You are analyzing activity after a phishing incident. A workstation was compromised, and shortly after you observe: None of these resources are used by real…

ADCD hard
Hard CTF – Deception-Based Detection Scenario During an incident, you see the following timeline: The credentials were intentionally fake and only existed for detection purposes. Question What is the…