Talk With an Expert

No-Budget Living-Off-the-Land Detection

No-Budget Living-Off-the-Land Detection (PDF, 5.21MB)Published: 30 Mar, 2022
Created by:
Mostafa Aly

Adversaries face challenges in executing tools that give them the first entry point into an endpoint; hence they started to increasingly adopt the Living-Off-the-Land (LoL) techniques. The execution of Living off the Land techniques usually goes undetected by traditional endpoint defenses because the files used are part of the Windows Operating System, digitally signed by Microsoft. Moreover, these binaries are vital for the Windows Operating System to operate. More organizations started to depend on Windows Security Event Logging to detect such techniques. This paper explores the detection capabilities of Windows Security Event Logging in addition to PowerShell logging and Microsoft Sysmon logging against the most common Living off the Land techniques. Exploring how this can be accomplished without an extensive budget will be the focus of this paper.