This site is in BETA. Labs are still being adjusted and re-structured and may not work as intended.

Resources

BHIS Blog

Current cybersecurity commentary and technical guidance.

logAnalysis basics

logAnalysis basics

July 29, 2026

Log Analysis Basics Hands-On Lab : Log Analysis Hayabusa Lab Log analysis involves reviewing system and security logs to detect unusual or malicious activity. Each log entry typically includes a…

welcome

welcome

July 29, 2026

Welcome! Future defenders, welcome! The fundamental abilities required to be a successful Security Operations Center (SOC) analyst will be covered in this course. You will participate in practical…

README

README

July 29, 2026

Welcome to the Free Lab Friday Lab Platform! Need 1 lab?? Maybe 2???? Well we've got 200+ so go crazy! This repository contains all lab instructions for the following content: Information Security…

WireGuard CTF

July 29, 2026

WireGuard CTF - Questions & Answers Capture file: wireguard_ctf.pcap Q1. What is the IP address of the WireGuard responder? Filter: wg.type == 1 -> click the first Handshake Initiation -> look at the…

WireGuardLab

WireGuardLab

July 29, 2026

Dissecting WireGuard Traffic Capture file: Topology: Role IP Address UDP Port Initiator (Peer 1) Responder (Peer 2) Both peers use port 51820 - this is a symmetric peer-to-peer setup, not a…

Port Knocking Lab

Port Knocking Lab

July 29, 2026

Port Knocking on the Wire Capture file: Topology Role IP Address MAC Address Notes Knocking client (valid) 10.42.0.7 00:11:22:33:44:55 Completes correct sequence Protected server 192.0.2.55…

port knocking ctf

July 29, 2026

Port Knocking CTF - Questions & Answers Capture file: Q1. What is the IP address of the protected server? Filter and look at the Source column - every RST on the knock ports comes from the same host.…

fragroute lab

fragroute lab

July 29, 2026

IP Packet Fragmentation via Fragroute - Hands-On Lab Capture file: Topology Role IP Address MAC Address Notes Victim / IDS 192.168.20.10 00:11:22:33:44:AA Runs a shallow-inspection IDS/firewall…

fragroute ctf

July 29, 2026

IP Packet Fragmentation via Fragroute - CTF Capture file: Questions Q1. What is the IP address of the host conducting the fragmentation attack? Apply to display all fragmented packets. Examine the…

ospf lab

July 29, 2026

OSPF Packet Analysis Capture file: Topology Role Router-ID IP Address MAC Address Designated Router (DR) 192.168.100.1 192.168.100.1/24 00:00:00:aa:00:01 Backup DR (BDR) 192.168.100.2 192.168.100.2/24…

ospf ctf

July 29, 2026

OSPF Packet Analysis CTF Capture file: Questions Q1. What is the Router-ID advertised in the attacker's spoofed LS Update packet? The attacker's Router-ID is placed in two locations inside the LSU:…

IPSec & IKEv2 CTF

July 29, 2026

IPSec / IKEv2 CTF - Questions & Answers Capture file: Q1. What UDP port carries the IKE_SA_INIT exchange? Filter: - the first two ISAKMP packets are here. Q2. What is the Initiator SPI of the IKE SA?…

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.

Something went wrong. A browser extension may be interfering with this page. Reload ×