Fix 404s: move challenges/solutions to Jekyll collections (_prefix)

Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Der Benji
2026-07-15 10:14:35 +02:00
co-authored by Claude Opus 4.6
parent 13629792f7
commit c37272daa6
44 changed files with 69 additions and 65 deletions
+4 -2
View File
@@ -15,10 +15,12 @@ collections:
defaults:
- scope:
path: "challenges"
path: ""
type: "challenges"
values:
layout: "challenge"
- scope:
path: "solutions"
path: ""
type: "solutions"
values:
layout: "solution"
+21 -20
View File
@@ -1,6 +1,7 @@
---
layout: default
title: "Challenges"
permalink: /challenges/
---
# EDR Bypass Challenges
@@ -11,25 +12,25 @@ title: "Challenges"
<div class="challenge-grid">
<a href="01-binary-rename/" class="challenge-card">
<a href="{{ '/challenges/01-binary-rename/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>01 - Binary Rename</h3>
<p>Rename a blacklisted tool to bypass process name detection</p>
</a>
<a href="02-case-sensitivity/" class="challenge-card">
<a href="{{ '/challenges/02-case-sensitivity/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>02 - Case Sensitivity Exploit</h3>
<p>Exploit case-sensitive string comparison in the blacklist</p>
</a>
<a href="03-copy-and-rename/" class="challenge-card">
<a href="{{ '/challenges/03-copy-and-rename/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>03 - Copy and Rename</h3>
<p>Copy a tool to a new filename to avoid detection</p>
</a>
<a href="04-unlisted-tool/" class="challenge-card">
<a href="{{ '/challenges/04-unlisted-tool/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>04 - Unlisted Tool</h3>
<p>Use a tool that isn't in the hardcoded blacklist</p>
@@ -41,31 +42,31 @@ title: "Challenges"
<div class="challenge-grid">
<a href="05-path-manipulation/" class="challenge-card">
<a href="{{ '/challenges/05-path-manipulation/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>05 - Path Manipulation</h3>
<p>Use path tricks to confuse the filename check</p>
</a>
<a href="06-caret-insertion/" class="challenge-card">
<a href="{{ '/challenges/06-caret-insertion/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>06 - Caret Insertion</h3>
<p>Use cmd.exe escape characters to break keyword matching</p>
</a>
<a href="07-env-variable-substitution/" class="challenge-card">
<a href="{{ '/challenges/07-env-variable-substitution/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>07 - Environment Variable Substitution</h3>
<p>Use environment variables to hide command keywords</p>
</a>
<a href="08-base64-encoding/" class="challenge-card">
<a href="{{ '/challenges/08-base64-encoding/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>08 - Base64 Encoded Commands</h3>
<p>Encode commands to bypass keyword detection</p>
</a>
<a href="09-the-useless-rule/" class="challenge-card">
<a href="{{ '/challenges/09-the-useless-rule/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>09 - The Useless Rule</h3>
<p>Discover why reconnaissance commands are never blocked</p>
@@ -77,31 +78,31 @@ title: "Challenges"
<div class="challenge-grid">
<a href="10-timing-attack/" class="challenge-card">
<a href="{{ '/challenges/10-timing-attack/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>10 - Timing Attack</h3>
<p>Exploit the polling interval to execute undetected</p>
</a>
<a href="11-pre-existing-process/" class="challenge-card">
<a href="{{ '/challenges/11-pre-existing-process/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>11 - Pre-Existing Process</h3>
<p>Be running before the EDR starts monitoring</p>
</a>
<a href="12-living-off-the-land/" class="challenge-card">
<a href="{{ '/challenges/12-living-off-the-land/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>12 - Living Off The Land</h3>
<p>Use built-in tools and alternative commands</p>
</a>
<a href="13-lsass-without-keywords/" class="challenge-card">
<a href="{{ '/challenges/13-lsass-without-keywords/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>13 - LSASS Without Keywords</h3>
<p>Dump LSASS without triggering keyword detection</p>
</a>
<a href="14-tool-rename-lsass/" class="challenge-card">
<a href="{{ '/challenges/14-tool-rename-lsass/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>14 - Tool Rename for LSASS</h3>
<p>Rename dump tools to bypass the dual-condition rule</p>
@@ -113,25 +114,25 @@ title: "Challenges"
<div class="challenge-grid">
<a href="15-alternative-powershell/" class="challenge-card">
<a href="{{ '/challenges/15-alternative-powershell/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>15 - Alternative PowerShell Host</h3>
<p>Execute PowerShell without powershell.exe</p>
</a>
<a href="16-elevated-process/" class="challenge-card">
<a href="{{ '/challenges/16-elevated-process/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>16 - Elevated Process Evasion</h3>
<p>Exploit the EDR's inability to read elevated processes</p>
</a>
<a href="17-32bit-evasion/" class="challenge-card">
<a href="{{ '/challenges/17-32bit-evasion/' | relative_url }}" class="challenge-card">
<span class="badge badge-medium">Medium</span>
<h3>17 - 32-Bit Process Evasion</h3>
<p>Use a 32-bit process to break PEB reading</p>
</a>
<a href="18-unicode-names/" class="challenge-card">
<a href="{{ '/challenges/18-unicode-names/' | relative_url }}" class="challenge-card">
<span class="badge badge-hard">Hard</span>
<h3>18 - Unicode Process Names</h3>
<p>Exploit ASCII-only string handling with Unicode characters</p>
@@ -143,13 +144,13 @@ title: "Challenges"
<div class="challenge-grid">
<a href="19-parent-pid-spoofing/" class="challenge-card">
<a href="{{ '/challenges/19-parent-pid-spoofing/' | relative_url }}" class="challenge-card">
<span class="badge badge-hard">Hard</span>
<h3>19 - Parent PID Spoofing</h3>
<p>Spoof the parent process ID to confuse tracking</p>
</a>
<a href="20-empty-hash-database/" class="challenge-card">
<a href="{{ '/challenges/20-empty-hash-database/' | relative_url }}" class="challenge-card">
<span class="badge badge-easy">Easy</span>
<h3>20 - The Empty Hash Database</h3>
<p>Realize there is no hash-based detection at all</p>
+44
View File
@@ -0,0 +1,44 @@
---
layout: default
title: "Solutions"
permalink: /solutions/
---
# Challenge Solutions
> **Spoiler Warning**: These solutions explain exactly how to bypass each detection rule. Try the challenges first!
## Category 1: Process Name Evasion
- [01 - Binary Rename]({{ '/solutions/01-binary-rename/' | relative_url }})
- [02 - Case Sensitivity Exploit]({{ '/solutions/02-case-sensitivity/' | relative_url }})
- [03 - Copy and Rename]({{ '/solutions/03-copy-and-rename/' | relative_url }})
- [04 - Unlisted Tool]({{ '/solutions/04-unlisted-tool/' | relative_url }})
## Category 2: Command Line Obfuscation
- [05 - Path Manipulation]({{ '/solutions/05-path-manipulation/' | relative_url }})
- [06 - Caret Insertion]({{ '/solutions/06-caret-insertion/' | relative_url }})
- [07 - Environment Variable Substitution]({{ '/solutions/07-env-variable-substitution/' | relative_url }})
- [08 - Base64 Encoded Commands]({{ '/solutions/08-base64-encoding/' | relative_url }})
- [09 - The Useless Rule]({{ '/solutions/09-the-useless-rule/' | relative_url }})
## Category 3: Process Monitoring Bypass
- [10 - Timing Attack]({{ '/solutions/10-timing-attack/' | relative_url }})
- [11 - Pre-Existing Process]({{ '/solutions/11-pre-existing-process/' | relative_url }})
- [12 - Living Off The Land]({{ '/solutions/12-living-off-the-land/' | relative_url }})
- [13 - LSASS Without Keywords]({{ '/solutions/13-lsass-without-keywords/' | relative_url }})
- [14 - Tool Rename for LSASS]({{ '/solutions/14-tool-rename-lsass/' | relative_url }})
## Category 4: Execution Evasion
- [15 - Alternative PowerShell Host]({{ '/solutions/15-alternative-powershell/' | relative_url }})
- [16 - Elevated Process Evasion]({{ '/solutions/16-elevated-process/' | relative_url }})
- [17 - 32-Bit Process Evasion]({{ '/solutions/17-32bit-evasion/' | relative_url }})
- [18 - Unicode Process Names]({{ '/solutions/18-unicode-names/' | relative_url }})
## Category 5: Advanced Bypass
- [19 - Parent PID Spoofing]({{ '/solutions/19-parent-pid-spoofing/' | relative_url }})
- [20 - The Empty Hash Database]({{ '/solutions/20-empty-hash-database/' | relative_url }})
-43
View File
@@ -1,43 +0,0 @@
---
layout: default
title: "Solutions"
---
# Challenge Solutions
> **Spoiler Warning**: These solutions explain exactly how to bypass each detection rule. Try the challenges first!
## Category 1: Process Name Evasion
- [01 - Binary Rename](01-binary-rename/)
- [02 - Case Sensitivity Exploit](02-case-sensitivity/)
- [03 - Copy and Rename](03-copy-and-rename/)
- [04 - Unlisted Tool](04-unlisted-tool/)
## Category 2: Command Line Obfuscation
- [05 - Path Manipulation](05-path-manipulation/)
- [06 - Caret Insertion](06-caret-insertion/)
- [07 - Environment Variable Substitution](07-env-variable-substitution/)
- [08 - Base64 Encoded Commands](08-base64-encoding/)
- [09 - The Useless Rule](09-the-useless-rule/)
## Category 3: Process Monitoring Bypass
- [10 - Timing Attack](10-timing-attack/)
- [11 - Pre-Existing Process](11-pre-existing-process/)
- [12 - Living Off The Land](12-living-off-the-land/)
- [13 - LSASS Without Keywords](13-lsass-without-keywords/)
- [14 - Tool Rename for LSASS](14-tool-rename-lsass/)
## Category 4: Execution Evasion
- [15 - Alternative PowerShell Host](15-alternative-powershell/)
- [16 - Elevated Process Evasion](16-elevated-process/)
- [17 - 32-Bit Process Evasion](17-32bit-evasion/)
- [18 - Unicode Process Names](18-unicode-names/)
## Category 5: Advanced Bypass
- [19 - Parent PID Spoofing](19-parent-pid-spoofing/)
- [20 - The Empty Hash Database](20-empty-hash-database/)