mirror of
https://github.com/BenjiTrapp/MostShittyEDR
synced 2026-08-09 12:00:52 +00:00
Jekyll collections require the underscore-prefixed directory naming convention (_challenges, _solutions). Move files accordingly, extract index pages to root with proper permalinks, and fix defaults scope in _config.yml to use type-based matching. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1.1 KiB
1.1 KiB
title, difficulty, category, target_rule
| title | difficulty | category | target_rule |
|---|---|---|---|
| Challenge 05: Path Manipulation | easy | Command Line Obfuscation | 1 |
Objective
Execute a blacklisted process using path tricks to confuse the filename extraction.
Scanner Behavior
The EDR gets the process name from PROCESSENTRY32W.szExeFile, which contains only the executable filename (no path). However, the command line (Rule 2) contains the full command as typed.
Rules
- Execute a blacklisted tool using the full path or UNC path
- Explore whether the EDR sees the full path or just the filename
- Document which rules are path-aware and which are not
Hints
Hint 1
szExeFile from Toolhelp32 only contains the filename, not the full path.
Hint 2
The command line (Rule 2) contains whatever was typed. Can you use path syntax to hide keywords?Hint 3
Try using the full path:C:\Windows\System32\notepad.exe - is "notepad.exe" still extracted?