hunting-for-living-off-the-land-binaries - Hunt for adversary abuse of signed system binaries (LOLBins)
Proactively hunts for adversary abuse of signed system binaries (LOLBins) used to execute malicious payloads or evade defense controls.
Tags
Updated: 2026-09-16Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Define hunt hypotheses
- Identify target LOLBins
- Collect process telemetry
- Baseline normal binary behavior
- Identify telemetry anomalies
- Correlate anomalies with logs
- Document findings and rules
Inputs
- EDR telemetry
- SIEM process creation logs
- LOLBAS Project reference list
- PowerShell command-line logs
- Network proxy and firewall logs
Outputs
- Threat hunt report
- IOC lists
- Detection rules
Requirements
- Access to EDR telemetry
- SIEM with process creation logs
- Familiarity with LOLBAS Project
- PowerShell command-line logging enabled
- Access to network logs
