Skip to content
SIH Buddyby Ganeev Singh
Dev
All problem statements
SIH26148High risk high rewardacceptance 1/5

Creation of scripts/functions with new programming language to commence Computer & Network forensic analysis without triggering security solutions

National Technical Research Organisation (NTRO) · Blockchain & Cybersecurity · Software

As written this asks for an antivirus-evasion and covert-C2 toolkit, which a student team should not build or demonstrate — if you engage the organisation at all, reframe it toward authorised, allow-listed forensic collection rather than the evasion tradecraft the description details, and confirm scope with them directly.

What it actually is

This problem statement asks for a framework and language whose stated purpose is to run forensic tooling on a system while evading antivirus and endpoint security — explicitly using polymorphic engines, custom encryption, in-memory execution, bring-your-own-vulnerable-driver techniques and domain fronting to route command traffic. Regardless of the defensive framing, the described capability is an offensive malware-development and endpoint-evasion toolkit.

What to build

Not advisable to attempt as specified. The described system — a language and framework that alters control-flow graphs to avoid signature and heuristic detection, combines polymorphic engines with custom encryption and multi-vector in-memory execution, exploits vulnerable drivers to gain kernel access, and hides command-and-control traffic behind domain fronting through trusted CDNs — is a catalogue of the exact techniques used by advanced malware to evade defences and maintain covert control, and building it would produce a weaponisable evasion toolkit rather than a legitimate forensic tool.

Smallest thing that wins the room

Not applicable — a demonstration of the described capability would mean showing malware successfully evading endpoint security and establishing covert command channels, which is the harmful outcome itself.

How crowded this one gets

A guess, projected from the 2025 statements — the last year where both the submission counts and the winners were published.

Quiet70–160 teams expectedroughly 1 in 60–139 wins it

Quieter than 84% of the 226 · #38 of 226 by expected field

Few teams are likely to go here. The best odds on the board come from statements like this.

Why: defence, intelligence and space bodies drew small fields.

This is a guess, not a fact

Nobody has published 2026’s numbers yet. This is an analysed estimate from last year’s pattern, so please do not take it as the truth — check the live counter on the SIH portal before you decide anything. The range covers the middle half of likely outcomes, so one statement in two lands outside it. Entry closes at 500 ideas per statement, so no range goes past that — a statement that reaches the cap fills and shuts rather than drawing an unlimited crowd. The model reads only three things a team can see before choosing — software or hardware, the theme, and what kind of body posted it — and those explain about a quarter of the variation in last year’s field sizes (R² 0.25 on held-out statements). Trust the band more than the number, and the ordering more than either. It cannot see how good your idea is, which is the part that actually decides it.

The scores

The number is the shorthand. The line under it is the reason.

What you will be writing

  • (not advisable to build as specified — describes offensive evasion tradecraft)
  • Endpoint security evasion
  • Offensive tooling
  • Digital forensics

Prior art to read before you start

antivirus and EDR evasion · covert command and control · in-memory execution tradecraft

Analysed by Claude Opus. Every score above is a judgment call with its reasoning attached — kindly cross-check this against the official statement on the SIH portal before your team commits to it.