Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

DNS hard
Hard CTF - Full DNS C2 Reconstruction Your team responds to an incident at a mid-sized company. You have full packet captures from the affected host over a 2-hour window. You identify the following…

DNS easy 2
Easy CTF 2 - Spotting Tunneled Traffic You are reviewing firewall logs after an alert fires on an internal host. You notice the following pattern over a 30-minute window: Queries are being made every…

DNS easy 1
Easy CTF 1 - DNS Query Analysis A security analyst is reviewing DNS logs from a workstation on the internal network. They notice the following query repeated dozens of times over the last hour: The…

DF medium
Medium CTF - Hunting the Beacon Your SIEM fired an alert on a developer workstation. You pull the relevant logs and find the following: DNS logs: Proxy logs: Endpoint logs: The developer insists they…

DF hard
Hard CTF - Full C2 Takedown Your team has been tracking a suspected intrusion for 48 hours. Here is what you have confirmed so far: A Sliver implant is running on , disguised as a signed Windows…

DF easy 2
Easy CTF 2 - Log Analysis Basics You are reviewing firewall logs after a threat hunting alert fired. One workstation stands out. Here is a snippet of its outbound traffic over a 10-minute window: The…

DF easy 1
Easy CTF 1 - Spot the Front A security analyst is reviewing a packet capture from a workstation that flagged a behavioral alert. They inspect an outbound HTTPS connection and notice the following:…

CBSE medium
Medium CTF - Hunting the Exfil Channel Your SIEM has triggered an alert on a developer's workstation. You pull the correlated events and find the following timeline: The developer has a Python…

CBSE hard
Hard CTF - Silent Drain You are a threat hunter investigating a suspected long-term breach. An internal tip suggested data may have been leaving the network for weeks. No alerts fired during that…

CBSE easy 2
Easy CTF 2 - API Key in the Logs You are analyzing firewall logs after a security alert. You find a series of outbound HTTPS requests from a workstation that belongs to an intern who left the company…

CBSE easy 1
Easy CTF 1 - Spot the Upload You are reviewing endpoint logs on a machine that was flagged for unusual behavior. You notice the following process activity: is a Windows system process. It does not…

BITS medium
Medium CTF - Reconstructing an Exfiltration Timeline You are a defender investigating a potential data breach. The endpoint in question is a finance department laptop. You run the following command…