Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

ADCD easy 2
Easy CTF 2 – Finding the Canary A document containing a hidden tracking link (a canary token) was placed on an internal file share. Later, an alert appears: No employee should access this token from…

ADCD easy 1
Easy CTF 1 – First Interaction with a Decoy You are reviewing alerts from a deception platform. A fake SSH server was deployed inside the network. It is not used by any real employees. The alert…
Crisis Management
Crisis Management When a cybersecurity incident hits, the technical side is only half the battle. The other half is knowing what to do, who does what, and how fast you can contain the damage. That is…
Cloud Event Log Analysis
Cloud Event Log Analysis Cloud systems generate logs for everything - logins, API calls, file access, configuration changes, network connections. When something goes wrong, those logs are often the…
Active Defense And Cyber Deception
Active Defense and Cyber Deception Active defense and cyber deception focus on guiding attackers into controlled environments instead of only trying to block them. Defenders create systems that look…

uboatrat
UBoatRAT - BITS Job Abuse, Dead-Drop Resolution, and One-Shot Beacon Analysis Windows VM · Ubuntu VM Objective In this lab, you will reconstruct a restricted, benign simulation of UBoatRAT-style…

sliver
Sliver C2 Lab Goal The goal of this lab is to introduce Sliver C2 Framework . We will demonstrate how a Command and Control framework operates with the use of Sliver . In this lab you will Learn the…

mythic
Mythic C2 Framework - AWS Deployment Ubuntu VM (management) · AWS EC2 (Mythic Server) · Windows VM (target) In this lab we will Deploy a Mythic C2 server on AWS EC2 using a CloudFormation template…

leviathan
Leviathan: Initial Access & BITS Exfiltration Windows & Ubuntu VMs The objective of this lab is to use the Leviathan Framework to gain initial access to a target Windows machine, and then use the…

havok
Havoc Framework Ubuntu VM, Windows VM & AWS Cloud The objective of this lab is to establish a modern Command & Control (C2) infrastructure using a cloud-based backend (AWS EC2). You will learn how to…

gost
Gost Windows VM The objective of this lab is to use Gost to establish an encrypted WebSocket (WSS) tunnel over port 443, bypassing simulated egress firewall rules to exfiltrate sensitive data. You…
HTTP As Exfil
HTTP As Exfil HTTP exfiltration happens when an attacker uses normal web traffic to move stolen data out of a compromised system. Instead of using obvious malicious channels, they blend into regular…