Files
BenjiTrapp-MostShittyEDR/_challenges/07-env-variable-substitution.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.2 KiB

title, difficulty, category, target_rule
title difficulty category target_rule
Challenge 07: Environment Variable Substitution medium Command Line Obfuscation 2

Objective

Execute a suspicious command by hiding keywords inside environment variables.

Scanner Behavior

Rule 2 checks the raw command line string as it appears in the process's PEB. Environment variables like %COMSPEC% or %USERNAME% are stored unexpanded in the command line and only resolved at runtime by cmd.exe.

The EDR does not expand environment variables before checking.

Rules

  • Execute whoami or net user using environment variable substitution
  • The command must execute successfully and show output
  • The raw command line must not contain the keyword

Hints

Hint 1 Environment variables in the command line are not expanded when the EDR reads the PEB.
Hint 2 You can build command strings using substrings of environment variables. %COMSPEC% expands to C:\WINDOWS\system32\cmd.exe.
Hint 3 cmd.exe /c %COMSPEC:~-7,1%%COMSPEC:~-6,1%oami constructs "whoami" from substrings at runtime.