Files
BenjiTrapp-MostShittyEDR/_challenges/09-the-useless-rule.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.5 KiB

title, difficulty, category, target_rule
title difficulty category target_rule
Challenge 09: The Useless Rule easy Command Line Obfuscation 3

Objective

Discover why reconnaissance commands like whoami, net user, ipconfig /all, and systeminfo are never actually blocked by the EDR.

Scanner Behavior

Rule 3 detects reconnaissance commands and creates a detection result. But look at how the analysis engine calls it:

proc analyzeProcess(info: ProcessInfo, cfg: Config): seq[Detection] =
  result = @[]
  result.add ruleProcessBlacklist(enriched)
  result.add ruleSuspiciousKeywords(enriched)

  # WEAKNESS: recon detection runs but result is discarded!
  discard ruleReconDetection(enriched)

  result.add ruleLsassDump(enriched)
  ...

Rules

  • Execute at least 3 different reconnaissance commands
  • Observe the EDR output - are they detected? Are they blocked?
  • Explain why Rule 3 is ineffective

Hints

Hint 1 Read the source code carefully. What does discard do in Nim?
Hint 2 discard evaluates the expression but throws away the return value. The detections are never added to the result list.
Hint 3 Note that "whoami" IS in Rule 2's SuspiciousKeywords list, so it gets caught there. But pure recon commands like "ipconfig /all" or "systeminfo" only match Rule 3, which is discarded.