Files
BenjiTrapp-MostShittyEDR/_solutions/07-env-variable-substitution.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.3 KiB

title, difficulty, category
title difficulty category
Solution 07: Environment Variable Substitution medium Command Line Obfuscation

[Back to Challenge]({{ '/challenges/07-env-variable-substitution/' | relative_url }})

Overview

Environment variables in the command line are stored unexpanded. The EDR sees %COMSPEC%, not C:\WINDOWS\system32\cmd.exe.

Solution

:: Build "whoami" from environment variable substrings
:: %COMSPEC% = C:\WINDOWS\system32\cmd.exe

:: Using cmd.exe set and call
cmd.exe /c "set a=who&& set b=ami&& call %a%%b%"

:: Using PowerShell string operations
powershell -c "$a='wh'; $b='oami'; & \"$a$b\""

:: Using variable substring extraction
cmd.exe /V:ON /c "set cmd=whoami&& !cmd!"

Why It Works

The EDR reads the raw command line string from the PEB. Environment variables and command-line variable expressions are stored as-is (unexpanded). They are only expanded at runtime by the shell interpreter.

The EDR has no environment variable resolution engine. It searches for literal keyword strings and misses anything constructed at runtime.

Real-World Relevance

Real EDR products integrate with ETW (Event Tracing for Windows) which logs the expanded command line after variable substitution, or they use ScriptBlock logging for PowerShell which captures the actual executed code.