Case 073E4F · Malware & intel · L3 Applied
Living off the land (LOLBins)
Practise as: Explain it · Interview
Interview questionWhat does 'living off the land' mean, and why is it hard for defenders?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Attackers use built-in, signed OS tools instead of dropping custom malware, so fewer files to flag
- Examples: certutil to download, rundll32/regsvr32/mshta to proxy execution, wmic and PowerShell for recon
- Hard because the binaries are legit and used by admins; hash- and signature-based AV will not block them
- Detect via parent-child anomalies (Word spawning powershell), command-line logging (4688, Sysmon 1), AMSI
- Mitigate with WDAC/AppLocker, ASR rules, Constrained Language Mode and removing unneeded tools
If the interviewer pushes back
- How did Volt Typhoon use LOTL techniques against critical infrastructure?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.