mirror of
https://github.com/BenjiTrapp/MostShittyEDR
synced 2026-08-09 12:00:52 +00:00
Jekyll collections require the underscore-prefixed directory naming convention (_challenges, _solutions). Move files accordingly, extract index pages to root with proper permalinks, and fix defaults scope in _config.yml to use type-based matching. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1.2 KiB
1.2 KiB
title, difficulty, category, target_rule
| title | difficulty | category | target_rule |
|---|---|---|---|
| Challenge 07: Environment Variable Substitution | medium | Command Line Obfuscation | 2 |
Objective
Execute a suspicious command by hiding keywords inside environment variables.
Scanner Behavior
Rule 2 checks the raw command line string as it appears in the process's PEB. Environment variables like %COMSPEC% or %USERNAME% are stored unexpanded in the command line and only resolved at runtime by cmd.exe.
The EDR does not expand environment variables before checking.
Rules
- Execute
whoamiornet userusing environment variable substitution - The command must execute successfully and show output
- The raw command line must not contain the keyword
Hints
Hint 1
Environment variables in the command line are not expanded when the EDR reads the PEB.Hint 2
You can build command strings using substrings of environment variables.%COMSPEC% expands to C:\WINDOWS\system32\cmd.exe.
Hint 3
cmd.exe /c %COMSPEC:~-7,1%%COMSPEC:~-6,1%oami constructs "whoami" from substrings at runtime.