Open cardosec

Case 073E4F · Malware & intel · L3 Applied

Living off the land (LOLBins)

Practise as: Explain it · Interview

Interview questionWhat does 'living off the land' mean, and why is it hard for defenders?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Attackers use built-in, signed OS tools instead of dropping custom malware, so fewer files to flag
  2. Examples: certutil to download, rundll32/regsvr32/mshta to proxy execution, wmic and PowerShell for recon
  3. Hard because the binaries are legit and used by admins; hash- and signature-based AV will not block them
  4. Detect via parent-child anomalies (Word spawning powershell), command-line logging (4688, Sysmon 1), AMSI
  5. Mitigate with WDAC/AppLocker, ASR rules, Constrained Language Mode and removing unneeded tools

If the interviewer pushes back

  • How did Volt Typhoon use LOTL techniques against critical infrastructure?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.