Files
BenjiTrapp-MostShittyEDR/solutions.md
T
Der BenjiandClaude Opus 4.6 c37272daa6 Fix 404s: move challenges/solutions to Jekyll collections (_prefix)
Jekyll collections require the underscore-prefixed directory naming
convention (_challenges, _solutions). Move files accordingly, extract
index pages to root with proper permalinks, and fix defaults scope
in _config.yml to use type-based matching.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-07-15 10:14:35 +02:00

2.1 KiB

layout, title, permalink
layout title permalink
default Solutions /solutions/

Challenge Solutions

Spoiler Warning: These solutions explain exactly how to bypass each detection rule. Try the challenges first!

Category 1: Process Name Evasion

  • [01 - Binary Rename]({{ '/solutions/01-binary-rename/' | relative_url }})
  • [02 - Case Sensitivity Exploit]({{ '/solutions/02-case-sensitivity/' | relative_url }})
  • [03 - Copy and Rename]({{ '/solutions/03-copy-and-rename/' | relative_url }})
  • [04 - Unlisted Tool]({{ '/solutions/04-unlisted-tool/' | relative_url }})

Category 2: Command Line Obfuscation

  • [05 - Path Manipulation]({{ '/solutions/05-path-manipulation/' | relative_url }})
  • [06 - Caret Insertion]({{ '/solutions/06-caret-insertion/' | relative_url }})
  • [07 - Environment Variable Substitution]({{ '/solutions/07-env-variable-substitution/' | relative_url }})
  • [08 - Base64 Encoded Commands]({{ '/solutions/08-base64-encoding/' | relative_url }})
  • [09 - The Useless Rule]({{ '/solutions/09-the-useless-rule/' | relative_url }})

Category 3: Process Monitoring Bypass

  • [10 - Timing Attack]({{ '/solutions/10-timing-attack/' | relative_url }})
  • [11 - Pre-Existing Process]({{ '/solutions/11-pre-existing-process/' | relative_url }})
  • [12 - Living Off The Land]({{ '/solutions/12-living-off-the-land/' | relative_url }})
  • [13 - LSASS Without Keywords]({{ '/solutions/13-lsass-without-keywords/' | relative_url }})
  • [14 - Tool Rename for LSASS]({{ '/solutions/14-tool-rename-lsass/' | relative_url }})

Category 4: Execution Evasion

  • [15 - Alternative PowerShell Host]({{ '/solutions/15-alternative-powershell/' | relative_url }})
  • [16 - Elevated Process Evasion]({{ '/solutions/16-elevated-process/' | relative_url }})
  • [17 - 32-Bit Process Evasion]({{ '/solutions/17-32bit-evasion/' | relative_url }})
  • [18 - Unicode Process Names]({{ '/solutions/18-unicode-names/' | relative_url }})

Category 5: Advanced Bypass

  • [19 - Parent PID Spoofing]({{ '/solutions/19-parent-pid-spoofing/' | relative_url }})
  • [20 - The Empty Hash Database]({{ '/solutions/20-empty-hash-database/' | relative_url }})