mirror of
https://github.com/BenjiTrapp/MostShittyEDR
synced 2026-08-09 12:00:52 +00:00
Jekyll collections require the underscore-prefixed directory naming convention (_challenges, _solutions). Move files accordingly, extract index pages to root with proper permalinks, and fix defaults scope in _config.yml to use type-based matching. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1.5 KiB
1.5 KiB
title, difficulty, category, target_rule
| title | difficulty | category | target_rule |
|---|---|---|---|
| Challenge 20: The Empty Hash Database | easy | Advanced Bypass | 6 |
Objective
Discover that Rule 6 (hash-based detection) is pure security theater with an empty database.
Scanner Behavior
Rule 6 claims to check malware hashes but the database is literally empty:
let KnownMalwareHashes: seq[string] = @[]
proc ruleHashCheck(info: ProcessInfo): seq[Detection] =
result = @[]
for h in KnownMalwareHashes: # iterates over... nothing
discard h
# Always returns empty
Furthermore, even if the database had entries, the result is discarded in the analysis engine:
discard ruleHashCheck(enriched) # result thrown away
Rules
- Run any known malware sample or suspicious binary
- Confirm that Rule 6 never triggers
- Explain the two separate reasons why this rule is useless
Hints
Hint 1
Look at theKnownMalwareHashes constant. How many entries does it have?
Hint 2
Even if you added hashes to the database, look at howruleHashCheck is called in analyzeProcess.
Hint 3
Two bugs: (1) The hash database is empty - zero hashes to compare against. (2) The result ofruleHashCheck is discarded - even if it found something, the detection would be thrown away. This is double security theater.