Files
BenjiTrapp-MostShittyEDR/_challenges/10-timing-attack.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.3 KiB

title, difficulty, category, target_rule
title difficulty category target_rule
Challenge 10: Timing Attack medium Process Monitoring Bypass Architecture

Objective

Execute a blacklisted command that completes before the EDR's next polling cycle.

Scanner Behavior

The EDR monitors processes by polling with CreateToolhelp32Snapshot at a fixed interval:

Sleep(DWORD(cfg.pollInterval))  # Default: 500ms

A process that starts AND exits between two polls is never seen by the EDR.

Rules

  • Execute a blacklisted tool or suspicious command
  • The process must complete before the EDR detects it
  • The command must produce output proving it ran
  • Use the default 500ms polling interval

Hints

Hint 1 The default poll interval is 500ms. Any process that starts and exits in under 500ms might slip through.
Hint 2 Simple commands like whoami, ipconfig, net user typically complete in milliseconds.
Hint 3 The key is that CreateToolhelp32Snapshot is a point-in-time snapshot. A short-lived process between snapshots is invisible. Try running commands via cmd /c which exits quickly.