Files
BenjiTrapp-MostShittyEDR/_challenges/05-path-manipulation.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.1 KiB

title, difficulty, category, target_rule
title difficulty category target_rule
Challenge 05: Path Manipulation easy Command Line Obfuscation 1

Objective

Execute a blacklisted process using path tricks to confuse the filename extraction.

Scanner Behavior

The EDR gets the process name from PROCESSENTRY32W.szExeFile, which contains only the executable filename (no path). However, the command line (Rule 2) contains the full command as typed.

Rules

  • Execute a blacklisted tool using the full path or UNC path
  • Explore whether the EDR sees the full path or just the filename
  • Document which rules are path-aware and which are not

Hints

Hint 1 szExeFile from Toolhelp32 only contains the filename, not the full path.
Hint 2 The command line (Rule 2) contains whatever was typed. Can you use path syntax to hide keywords?
Hint 3 Try using the full path: C:\Windows\System32\notepad.exe - is "notepad.exe" still extracted?