mirror of
https://github.com/BenjiTrapp/MostShittyEDR
synced 2026-08-09 12:00:52 +00:00
Jekyll collections require the underscore-prefixed directory naming convention (_challenges, _solutions). Move files accordingly, extract index pages to root with proper permalinks, and fix defaults scope in _config.yml to use type-based matching. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1.4 KiB
1.4 KiB
title, difficulty, category, target_rule
| title | difficulty | category | target_rule |
|---|---|---|---|
| Challenge 18: Unicode Process Names | hard | Execution Evasion | Architecture |
Objective
Use Unicode characters in process or command names to exploit the EDR's ASCII-only string handling.
Scanner Behavior
The EDR converts wide strings (UTF-16) to ASCII by masking to 7 bits:
proc wcharToStr(arr: openArray[WCHAR]): string =
for c in arr:
if c == 0: break
if int(c) < 128:
result.add(chr(int(c)))
else:
result.add('?') # Non-ASCII becomes '?'
Characters outside the ASCII range are replaced with ?. This breaks pattern matching for names containing Unicode.
Rules
- Create or rename an executable using Unicode characters that resemble ASCII letters (homoglyphs)
- The EDR must misidentify or fail to match the process name
- The executable must still run on Windows
Hints
Hint 1
Unicode has many characters that look like ASCII letters but have different code points. These are called homoglyphs.Hint 2
Cyrillic 'a' (U+0430) looks identical to Latin 'a' (U+0061) but has a different code point. The EDR converts it to '?'.Hint 3
mimik?tz.exe (with a Cyrillic 'a') becomes mimik?tz.exe in the EDR's view, which does not match "mimikatz.exe".