mirror of
https://github.com/BenjiTrapp/MostShittyEDR
synced 2026-08-09 12:00:52 +00:00
Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming convention (_challenges, _solutions). Move files accordingly, extract index pages to root with proper permalinks, and fix defaults scope in _config.yml to use type-based matching. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
13629792f7
commit
c37272daa6
+4
-2
@@ -15,10 +15,12 @@ collections:
|
|||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
- scope:
|
- scope:
|
||||||
path: "challenges"
|
path: ""
|
||||||
|
type: "challenges"
|
||||||
values:
|
values:
|
||||||
layout: "challenge"
|
layout: "challenge"
|
||||||
- scope:
|
- scope:
|
||||||
path: "solutions"
|
path: ""
|
||||||
|
type: "solutions"
|
||||||
values:
|
values:
|
||||||
layout: "solution"
|
layout: "solution"
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: "Challenges"
|
title: "Challenges"
|
||||||
|
permalink: /challenges/
|
||||||
---
|
---
|
||||||
|
|
||||||
# EDR Bypass Challenges
|
# EDR Bypass Challenges
|
||||||
@@ -11,25 +12,25 @@ title: "Challenges"
|
|||||||
|
|
||||||
<div class="challenge-grid">
|
<div class="challenge-grid">
|
||||||
|
|
||||||
<a href="01-binary-rename/" class="challenge-card">
|
<a href="{{ '/challenges/01-binary-rename/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>01 - Binary Rename</h3>
|
<h3>01 - Binary Rename</h3>
|
||||||
<p>Rename a blacklisted tool to bypass process name detection</p>
|
<p>Rename a blacklisted tool to bypass process name detection</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="02-case-sensitivity/" class="challenge-card">
|
<a href="{{ '/challenges/02-case-sensitivity/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>02 - Case Sensitivity Exploit</h3>
|
<h3>02 - Case Sensitivity Exploit</h3>
|
||||||
<p>Exploit case-sensitive string comparison in the blacklist</p>
|
<p>Exploit case-sensitive string comparison in the blacklist</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="03-copy-and-rename/" class="challenge-card">
|
<a href="{{ '/challenges/03-copy-and-rename/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>03 - Copy and Rename</h3>
|
<h3>03 - Copy and Rename</h3>
|
||||||
<p>Copy a tool to a new filename to avoid detection</p>
|
<p>Copy a tool to a new filename to avoid detection</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="04-unlisted-tool/" class="challenge-card">
|
<a href="{{ '/challenges/04-unlisted-tool/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>04 - Unlisted Tool</h3>
|
<h3>04 - Unlisted Tool</h3>
|
||||||
<p>Use a tool that isn't in the hardcoded blacklist</p>
|
<p>Use a tool that isn't in the hardcoded blacklist</p>
|
||||||
@@ -41,31 +42,31 @@ title: "Challenges"
|
|||||||
|
|
||||||
<div class="challenge-grid">
|
<div class="challenge-grid">
|
||||||
|
|
||||||
<a href="05-path-manipulation/" class="challenge-card">
|
<a href="{{ '/challenges/05-path-manipulation/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>05 - Path Manipulation</h3>
|
<h3>05 - Path Manipulation</h3>
|
||||||
<p>Use path tricks to confuse the filename check</p>
|
<p>Use path tricks to confuse the filename check</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="06-caret-insertion/" class="challenge-card">
|
<a href="{{ '/challenges/06-caret-insertion/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>06 - Caret Insertion</h3>
|
<h3>06 - Caret Insertion</h3>
|
||||||
<p>Use cmd.exe escape characters to break keyword matching</p>
|
<p>Use cmd.exe escape characters to break keyword matching</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="07-env-variable-substitution/" class="challenge-card">
|
<a href="{{ '/challenges/07-env-variable-substitution/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>07 - Environment Variable Substitution</h3>
|
<h3>07 - Environment Variable Substitution</h3>
|
||||||
<p>Use environment variables to hide command keywords</p>
|
<p>Use environment variables to hide command keywords</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="08-base64-encoding/" class="challenge-card">
|
<a href="{{ '/challenges/08-base64-encoding/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>08 - Base64 Encoded Commands</h3>
|
<h3>08 - Base64 Encoded Commands</h3>
|
||||||
<p>Encode commands to bypass keyword detection</p>
|
<p>Encode commands to bypass keyword detection</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="09-the-useless-rule/" class="challenge-card">
|
<a href="{{ '/challenges/09-the-useless-rule/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>09 - The Useless Rule</h3>
|
<h3>09 - The Useless Rule</h3>
|
||||||
<p>Discover why reconnaissance commands are never blocked</p>
|
<p>Discover why reconnaissance commands are never blocked</p>
|
||||||
@@ -77,31 +78,31 @@ title: "Challenges"
|
|||||||
|
|
||||||
<div class="challenge-grid">
|
<div class="challenge-grid">
|
||||||
|
|
||||||
<a href="10-timing-attack/" class="challenge-card">
|
<a href="{{ '/challenges/10-timing-attack/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>10 - Timing Attack</h3>
|
<h3>10 - Timing Attack</h3>
|
||||||
<p>Exploit the polling interval to execute undetected</p>
|
<p>Exploit the polling interval to execute undetected</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="11-pre-existing-process/" class="challenge-card">
|
<a href="{{ '/challenges/11-pre-existing-process/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>11 - Pre-Existing Process</h3>
|
<h3>11 - Pre-Existing Process</h3>
|
||||||
<p>Be running before the EDR starts monitoring</p>
|
<p>Be running before the EDR starts monitoring</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="12-living-off-the-land/" class="challenge-card">
|
<a href="{{ '/challenges/12-living-off-the-land/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>12 - Living Off The Land</h3>
|
<h3>12 - Living Off The Land</h3>
|
||||||
<p>Use built-in tools and alternative commands</p>
|
<p>Use built-in tools and alternative commands</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="13-lsass-without-keywords/" class="challenge-card">
|
<a href="{{ '/challenges/13-lsass-without-keywords/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>13 - LSASS Without Keywords</h3>
|
<h3>13 - LSASS Without Keywords</h3>
|
||||||
<p>Dump LSASS without triggering keyword detection</p>
|
<p>Dump LSASS without triggering keyword detection</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="14-tool-rename-lsass/" class="challenge-card">
|
<a href="{{ '/challenges/14-tool-rename-lsass/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>14 - Tool Rename for LSASS</h3>
|
<h3>14 - Tool Rename for LSASS</h3>
|
||||||
<p>Rename dump tools to bypass the dual-condition rule</p>
|
<p>Rename dump tools to bypass the dual-condition rule</p>
|
||||||
@@ -113,25 +114,25 @@ title: "Challenges"
|
|||||||
|
|
||||||
<div class="challenge-grid">
|
<div class="challenge-grid">
|
||||||
|
|
||||||
<a href="15-alternative-powershell/" class="challenge-card">
|
<a href="{{ '/challenges/15-alternative-powershell/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>15 - Alternative PowerShell Host</h3>
|
<h3>15 - Alternative PowerShell Host</h3>
|
||||||
<p>Execute PowerShell without powershell.exe</p>
|
<p>Execute PowerShell without powershell.exe</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="16-elevated-process/" class="challenge-card">
|
<a href="{{ '/challenges/16-elevated-process/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>16 - Elevated Process Evasion</h3>
|
<h3>16 - Elevated Process Evasion</h3>
|
||||||
<p>Exploit the EDR's inability to read elevated processes</p>
|
<p>Exploit the EDR's inability to read elevated processes</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="17-32bit-evasion/" class="challenge-card">
|
<a href="{{ '/challenges/17-32bit-evasion/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-medium">Medium</span>
|
<span class="badge badge-medium">Medium</span>
|
||||||
<h3>17 - 32-Bit Process Evasion</h3>
|
<h3>17 - 32-Bit Process Evasion</h3>
|
||||||
<p>Use a 32-bit process to break PEB reading</p>
|
<p>Use a 32-bit process to break PEB reading</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="18-unicode-names/" class="challenge-card">
|
<a href="{{ '/challenges/18-unicode-names/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-hard">Hard</span>
|
<span class="badge badge-hard">Hard</span>
|
||||||
<h3>18 - Unicode Process Names</h3>
|
<h3>18 - Unicode Process Names</h3>
|
||||||
<p>Exploit ASCII-only string handling with Unicode characters</p>
|
<p>Exploit ASCII-only string handling with Unicode characters</p>
|
||||||
@@ -143,13 +144,13 @@ title: "Challenges"
|
|||||||
|
|
||||||
<div class="challenge-grid">
|
<div class="challenge-grid">
|
||||||
|
|
||||||
<a href="19-parent-pid-spoofing/" class="challenge-card">
|
<a href="{{ '/challenges/19-parent-pid-spoofing/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-hard">Hard</span>
|
<span class="badge badge-hard">Hard</span>
|
||||||
<h3>19 - Parent PID Spoofing</h3>
|
<h3>19 - Parent PID Spoofing</h3>
|
||||||
<p>Spoof the parent process ID to confuse tracking</p>
|
<p>Spoof the parent process ID to confuse tracking</p>
|
||||||
</a>
|
</a>
|
||||||
|
|
||||||
<a href="20-empty-hash-database/" class="challenge-card">
|
<a href="{{ '/challenges/20-empty-hash-database/' | relative_url }}" class="challenge-card">
|
||||||
<span class="badge badge-easy">Easy</span>
|
<span class="badge badge-easy">Easy</span>
|
||||||
<h3>20 - The Empty Hash Database</h3>
|
<h3>20 - The Empty Hash Database</h3>
|
||||||
<p>Realize there is no hash-based detection at all</p>
|
<p>Realize there is no hash-based detection at all</p>
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
---
|
||||||
|
layout: default
|
||||||
|
title: "Solutions"
|
||||||
|
permalink: /solutions/
|
||||||
|
---
|
||||||
|
|
||||||
|
# Challenge Solutions
|
||||||
|
|
||||||
|
> **Spoiler Warning**: These solutions explain exactly how to bypass each detection rule. Try the challenges first!
|
||||||
|
|
||||||
|
## Category 1: Process Name Evasion
|
||||||
|
|
||||||
|
- [01 - Binary Rename]({{ '/solutions/01-binary-rename/' | relative_url }})
|
||||||
|
- [02 - Case Sensitivity Exploit]({{ '/solutions/02-case-sensitivity/' | relative_url }})
|
||||||
|
- [03 - Copy and Rename]({{ '/solutions/03-copy-and-rename/' | relative_url }})
|
||||||
|
- [04 - Unlisted Tool]({{ '/solutions/04-unlisted-tool/' | relative_url }})
|
||||||
|
|
||||||
|
## Category 2: Command Line Obfuscation
|
||||||
|
|
||||||
|
- [05 - Path Manipulation]({{ '/solutions/05-path-manipulation/' | relative_url }})
|
||||||
|
- [06 - Caret Insertion]({{ '/solutions/06-caret-insertion/' | relative_url }})
|
||||||
|
- [07 - Environment Variable Substitution]({{ '/solutions/07-env-variable-substitution/' | relative_url }})
|
||||||
|
- [08 - Base64 Encoded Commands]({{ '/solutions/08-base64-encoding/' | relative_url }})
|
||||||
|
- [09 - The Useless Rule]({{ '/solutions/09-the-useless-rule/' | relative_url }})
|
||||||
|
|
||||||
|
## Category 3: Process Monitoring Bypass
|
||||||
|
|
||||||
|
- [10 - Timing Attack]({{ '/solutions/10-timing-attack/' | relative_url }})
|
||||||
|
- [11 - Pre-Existing Process]({{ '/solutions/11-pre-existing-process/' | relative_url }})
|
||||||
|
- [12 - Living Off The Land]({{ '/solutions/12-living-off-the-land/' | relative_url }})
|
||||||
|
- [13 - LSASS Without Keywords]({{ '/solutions/13-lsass-without-keywords/' | relative_url }})
|
||||||
|
- [14 - Tool Rename for LSASS]({{ '/solutions/14-tool-rename-lsass/' | relative_url }})
|
||||||
|
|
||||||
|
## Category 4: Execution Evasion
|
||||||
|
|
||||||
|
- [15 - Alternative PowerShell Host]({{ '/solutions/15-alternative-powershell/' | relative_url }})
|
||||||
|
- [16 - Elevated Process Evasion]({{ '/solutions/16-elevated-process/' | relative_url }})
|
||||||
|
- [17 - 32-Bit Process Evasion]({{ '/solutions/17-32bit-evasion/' | relative_url }})
|
||||||
|
- [18 - Unicode Process Names]({{ '/solutions/18-unicode-names/' | relative_url }})
|
||||||
|
|
||||||
|
## Category 5: Advanced Bypass
|
||||||
|
|
||||||
|
- [19 - Parent PID Spoofing]({{ '/solutions/19-parent-pid-spoofing/' | relative_url }})
|
||||||
|
- [20 - The Empty Hash Database]({{ '/solutions/20-empty-hash-database/' | relative_url }})
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
---
|
|
||||||
layout: default
|
|
||||||
title: "Solutions"
|
|
||||||
---
|
|
||||||
|
|
||||||
# Challenge Solutions
|
|
||||||
|
|
||||||
> **Spoiler Warning**: These solutions explain exactly how to bypass each detection rule. Try the challenges first!
|
|
||||||
|
|
||||||
## Category 1: Process Name Evasion
|
|
||||||
|
|
||||||
- [01 - Binary Rename](01-binary-rename/)
|
|
||||||
- [02 - Case Sensitivity Exploit](02-case-sensitivity/)
|
|
||||||
- [03 - Copy and Rename](03-copy-and-rename/)
|
|
||||||
- [04 - Unlisted Tool](04-unlisted-tool/)
|
|
||||||
|
|
||||||
## Category 2: Command Line Obfuscation
|
|
||||||
|
|
||||||
- [05 - Path Manipulation](05-path-manipulation/)
|
|
||||||
- [06 - Caret Insertion](06-caret-insertion/)
|
|
||||||
- [07 - Environment Variable Substitution](07-env-variable-substitution/)
|
|
||||||
- [08 - Base64 Encoded Commands](08-base64-encoding/)
|
|
||||||
- [09 - The Useless Rule](09-the-useless-rule/)
|
|
||||||
|
|
||||||
## Category 3: Process Monitoring Bypass
|
|
||||||
|
|
||||||
- [10 - Timing Attack](10-timing-attack/)
|
|
||||||
- [11 - Pre-Existing Process](11-pre-existing-process/)
|
|
||||||
- [12 - Living Off The Land](12-living-off-the-land/)
|
|
||||||
- [13 - LSASS Without Keywords](13-lsass-without-keywords/)
|
|
||||||
- [14 - Tool Rename for LSASS](14-tool-rename-lsass/)
|
|
||||||
|
|
||||||
## Category 4: Execution Evasion
|
|
||||||
|
|
||||||
- [15 - Alternative PowerShell Host](15-alternative-powershell/)
|
|
||||||
- [16 - Elevated Process Evasion](16-elevated-process/)
|
|
||||||
- [17 - 32-Bit Process Evasion](17-32bit-evasion/)
|
|
||||||
- [18 - Unicode Process Names](18-unicode-names/)
|
|
||||||
|
|
||||||
## Category 5: Advanced Bypass
|
|
||||||
|
|
||||||
- [19 - Parent PID Spoofing](19-parent-pid-spoofing/)
|
|
||||||
- [20 - The Empty Hash Database](20-empty-hash-database/)
|
|
||||||
Reference in New Issue
Block a user