Living-Off-the-Land (LotL)
Definition
An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or mshta, rather than introducing new malware. LotL techniques are harder to detect because the executed binaries are legitimate and often whitelisted.
- Abbreviation
- LotL
- Approach
- Uses pre-installed system tools rather than new malware
- Common tools abused
- PowerShell, WMI, certutil, mshta
- Why effective
- Executed binaries are legitimate and often whitelisted
Common questions
Why is living-off-the-land activity harder to detect than traditional malware?+
Because the tools used are already trusted, signed, and whitelisted parts of the operating system, signature-based antivirus has nothing new to flag. Detection instead depends on behavioural analysis, such as noticing PowerShell making unusual network connections or certutil being used to download a file rather than manage certificates.
What kind of evidence helps investigators reconstruct LotL activity after the fact?+
Command-line logging, PowerShell script block logging, Windows Event Logs, and endpoint detection and response telemetry are the main sources, since the executed binaries themselves leave no unusual file artefacts. Timeline correlation across these logs is often needed to distinguish malicious use from routine administrative activity.
Related terms
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Anti-Forensic Technique
- Any action taken by an attacker to destroy, conceal, or alter evidence of their activity. Common examples include log clearing, timestomping, use...
- Credential Dumping
- Extraction of authentication credentials from operating system memory, the Windows SAM database, Active Directory, or credential stores. Tools such as Mimikatz target...
- Credential Stuffing
- An automated attack that replays username-password pairs from previous data breaches against new target services, exploiting the widespread reuse of passwords across...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Privilege Escalation
- A post-access technique in which an attacker who has gained low-level access to a system exploits a vulnerability or misconfiguration to obtain...
- Tactic
- The adversary's high-level objective at a given stage of the attack: for example, Initial Access, Execution, Persistence, Privilege Escalation, or Exfiltration. ATT&CK...
- Technique
- A specific method an adversary uses to achieve a tactic. Each technique has a unique identifier such as T1059 (Command and Scripting...
- Unauthorised Access
- The act of accessing a computer, network, or data store without permission from the owner or without lawful authority. The core element...
Explained in these topics
- Common Attack Techniques and Tactics, Techniques and Procedures
- Hacking and Unauthorised Access OffencesAn intrusion technique in which attackers use tools and executables already present on the victim system, such as PowerShell, WMI, or built-in scripting interp...