mirror of
https://github.com/BenjiTrapp/MostShittyEDR
synced 2026-08-09 12:00:52 +00:00
Jekyll collections require the underscore-prefixed directory naming convention (_challenges, _solutions). Move files accordingly, extract index pages to root with proper permalinks, and fix defaults scope in _config.yml to use type-based matching. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1.5 KiB
1.5 KiB
title, difficulty, category, target_rule
| title | difficulty | category | target_rule |
|---|---|---|---|
| Challenge 09: The Useless Rule | easy | Command Line Obfuscation | 3 |
Objective
Discover why reconnaissance commands like whoami, net user, ipconfig /all, and systeminfo are never actually blocked by the EDR.
Scanner Behavior
Rule 3 detects reconnaissance commands and creates a detection result. But look at how the analysis engine calls it:
proc analyzeProcess(info: ProcessInfo, cfg: Config): seq[Detection] =
result = @[]
result.add ruleProcessBlacklist(enriched)
result.add ruleSuspiciousKeywords(enriched)
# WEAKNESS: recon detection runs but result is discarded!
discard ruleReconDetection(enriched)
result.add ruleLsassDump(enriched)
...
Rules
- Execute at least 3 different reconnaissance commands
- Observe the EDR output - are they detected? Are they blocked?
- Explain why Rule 3 is ineffective
Hints
Hint 1
Read the source code carefully. What doesdiscard do in Nim?
Hint 2
discard evaluates the expression but throws away the return value. The detections are never added to the result list.
Hint 3
Note that "whoami" IS in Rule 2'sSuspiciousKeywords list, so it gets caught there. But pure recon commands like "ipconfig /all" or "systeminfo" only match Rule 3, which is discarded.