Files
BenjiTrapp-MostShittyEDR/_challenges/20-empty-hash-database.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.5 KiB

title, difficulty, category, target_rule
title difficulty category target_rule
Challenge 20: The Empty Hash Database easy Advanced Bypass 6

Objective

Discover that Rule 6 (hash-based detection) is pure security theater with an empty database.

Scanner Behavior

Rule 6 claims to check malware hashes but the database is literally empty:

let KnownMalwareHashes: seq[string] = @[]

proc ruleHashCheck(info: ProcessInfo): seq[Detection] =
  result = @[]
  for h in KnownMalwareHashes:  # iterates over... nothing
    discard h
  # Always returns empty

Furthermore, even if the database had entries, the result is discarded in the analysis engine:

discard ruleHashCheck(enriched)  # result thrown away

Rules

  • Run any known malware sample or suspicious binary
  • Confirm that Rule 6 never triggers
  • Explain the two separate reasons why this rule is useless

Hints

Hint 1 Look at the KnownMalwareHashes constant. How many entries does it have?
Hint 2 Even if you added hashes to the database, look at how ruleHashCheck is called in analyzeProcess.
Hint 3 Two bugs: (1) The hash database is empty - zero hashes to compare against. (2) The result of ruleHashCheck is discarded - even if it found something, the detection would be thrown away. This is double security theater.