detecting-living-off-the-land-attacks - Detect suspicious Windows LOLBin activity
Detects abuse of legitimate Windows binaries by analyzing process creation, command lines, parent-child relationships, and network activity.
Tags
Updated: 2026-10-07Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Configure LOLBin-focused Sysmon monitoring
- Author Sigma detection rules
- Analyze Sysmon event logs
- Correlate process and network activity
- Validate detection rules
- Tune detection false positives
Inputs
- Windows endpoint telemetry
- Sysmon configuration
- Security process creation logs
- Sigma rule repository
- LOLBAS reference
- Atomic Red Team test cases
Outputs
- LOLBin-focused Sysmon configuration
- Sigma detection rules
- Suspicious execution findings
- Validated detection results
- False-positive tuning guidance
Requirements
- Windows endpoints
- Sysmon v15 or later
- SIEM ingesting specified Sysmon events
- Windows Security event forwarding
- Python 3.8 or later
- Python evtx and pandas packages
- LOLBAS project reference
- Sigma rule repository
