Resources
BHIS Blog
Current cybersecurity commentary and technical guidance.

BITS hard
Hard CTF - Full Exfil Hunt and Attribution You are investigating a breach at a defense contractor. Three data points have been collected from different sources. Endpoint - PowerShell history on…

BITS easy 2
Easy CTF 2 - Log Analysis: Outbound BITS Traffic You are reviewing firewall logs from a company workstation. You notice the following outbound connection: The IP does not belong to any known Microsoft…

BITS easy 1
Easy CTF 1 - Spot the BITS Job You are reviewing commands run on a compromised Windows endpoint. An analyst pulled the following from the command history: Question What is the attacker trying to do…
Cloud Based Services As Exfil
Cloud-Based Services as Exfil Once an attacker is inside a network, they need to get the data out. The problem for them is that moving files to some unknown server in another country tends to raise…
C2 Basic Terminology & Theory
C2 Basic Terminology & Theory Before starting the hands-on C2 labs, we recommend reading this file first to become familiar with the basic terminology and theory behind C2 tools. Most of these terms…
Backround Intelligent Transfer Service As Exfil
Backround Intelligent Transfer Service(BITS) As Exfil BITS is a built-in Windows service that was designed to transfer files in the background - think Windows Update downloads, or software patches…
card navigation
All cards of the V3 Core Deck Initial Compromise Phishing Compomised Web Server Unauthorized Cloud Access Insider Threat External Password Spray Trusted Relationship Social Engineering Bring Your Own…