Files
BenjiTrapp-MostShittyEDR/_challenges/12-living-off-the-land.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.3 KiB

title, difficulty, category, target_rule
title difficulty category target_rule
Challenge 12: Living Off The Land medium Process Monitoring Bypass 2, 3

Objective

Perform reconnaissance and data gathering using only built-in Windows tools that are not detected by the EDR's keyword rules.

Scanner Behavior

Rule 2 checks for specific keywords: whoami, net user, net group, etc. Rule 3 checks for additional recon commands but discards the result. Neither rule covers all Windows built-in tools.

Rules

  • Gather the current username, domain, IP address, and local administrators
  • Use only built-in Windows tools (no third-party software)
  • The EDR must not trigger any SUSPICIOUS_CMDLINE detections

Hints

Hint 1 There are many ways to get the same information. whoami is not the only way to find your username.
Hint 2 PowerShell cmdlets like Get-WmiObject, [Environment]::UserName, or Get-LocalGroupMember achieve the same results but aren't in the keyword list.
Hint 3 echo %USERNAME%, set USERNAME, wmic useraccount list brief - none of these contain "whoami" or "net user".