πNew WriteupβοΈ
βββββββββββββββ
πDate: Fri, 21 Apr 2023 11:46:24 GMT
βββββββββββββββ
βοΈTitle: Proof of Concept :: Living of the Land Binaries
βββββββββββββββ
πLink: https://medium.com/p/cddc508e149b
βββββββββββββββ
Tags: #cybersecurity #blue_team #splunk #lolbas #living_of_the_land
βββββββββββββββ
πDate: Fri, 21 Apr 2023 11:46:24 GMT
βββββββββββββββ
βοΈTitle: Proof of Concept :: Living of the Land Binaries
βββββββββββββββ
πLink: https://medium.com/p/cddc508e149b
βββββββββββββββ
Tags: #cybersecurity #blue_team #splunk #lolbas #living_of_the_land
Medium
Proof of Concept :: Living of the Land Binaries
In this write-up Iβm going to explain the working of PoC.bat and the result of itβs executionβββrunning_process.txt followed by itβsβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 23 Aug 2023 00:21:13 GMT
βββββββββββββββ
βοΈTitle: LOLBAS Detection Serie [2]βββMspub.exe + ProtocolHandler.exe + MsoHtmEd.exe
βββββββββββββββ
πLink: https://medium.com/p/356accfc2bff
βββββββββββββββ
Tags: #detection_engineering #lolbas #cybersecurity #threat_hunting #lolbin
βββββββββββββββ
πDate: Wed, 23 Aug 2023 00:21:13 GMT
βββββββββββββββ
βοΈTitle: LOLBAS Detection Serie [2]βββMspub.exe + ProtocolHandler.exe + MsoHtmEd.exe
βββββββββββββββ
πLink: https://medium.com/p/356accfc2bff
βββββββββββββββ
Tags: #detection_engineering #lolbas #cybersecurity #threat_hunting #lolbin
Medium
LOLBAS Detection Serie [2] β Mspub.exe + ProtocolHandler.exe + MsoHtmEd.exe
The LOLBAS serie : https://medium.com/@mthcht/list/lolbas-843ba9de6810
β€· Title: LOTL: LOLBAS SaldΔ±rΔ± Teknikleri ve SIEM ile Δ°zlenmesi
ββββββββββββββββββββββββ
πͺ Author: HΓΌseyin YΓΌcesoy
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 16 Jan 2025 23:23:56 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #siem #blue_team #lolbas #threat_hunting
ββββββββββββββββββββββββ
πͺ Author: HΓΌseyin YΓΌcesoy
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 16 Jan 2025 23:23:56 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #siem #blue_team #lolbas #threat_hunting
Medium
LOTL: LOLBAS SaldΔ±rΔ± Teknikleri ve SIEM ile Δ°zlenmesi
βLOTL ve LOLBAS saldΔ±rΔ± yΓΆntemlerini keΕfedin! SIEM ile bu tehditlere karΕΔ± nasΔ±l korunacaΔΔ±nΔ±zΔ± ΓΆΔrenin ve gΓΌvenliΔi artΔ±rΔ±n.β
β€· Title: Living Off The Land Binaries, Scripts, and Libraries (LOLBAS)
ββββββββββββββββββββββββ
πͺ Author: cybrNK
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 21 Feb 2025 06:32:51 GMT
ββββββββββββββββββββββββ
β Tags: #binaries_options #cybersecurity #script #lolbas #cyber
ββββββββββββββββββββββββ
πͺ Author: cybrNK
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 21 Feb 2025 06:32:51 GMT
ββββββββββββββββββββββββ
β Tags: #binaries_options #cybersecurity #script #lolbas #cyber
Medium
Living Off The Land Binaries, Scripts, and Libraries (LOLBAS)
LOLBAS is commonly used in cyberattacks, including advanced persistent threats (APTs), ransomware attacks, and penetration testing.
β€· Title: Living Off The Land Binaries, Scripts and Libraries
ββββββββββββββββββββββββ
πͺ Author: Temesgen Janbo
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 05 Apr 2025 09:49:17 GMT
ββββββββββββββββββββββββ
β Tags: #soc #detection #cybersecurity #lolbas #lolbin
ββββββββββββββββββββββββ
πͺ Author: Temesgen Janbo
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 05 Apr 2025 09:49:17 GMT
ββββββββββββββββββββββββ
β Tags: #soc #detection #cybersecurity #lolbas #lolbin
Medium
Living Off The Land Binaries, Scripts and Libraries
Imagine an attacker breaking into your internal system without using or developing their own [malicious] tool with out worrying about ifβ¦
β€· Title: Venom Spider Evolves: Arctic Wolf Exposes More_eggs Campaign Targeting HR
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 05 May 2025 00:46:08 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Malware #Arctic Wolf #backdoor #HR Phishing #JavaScript Obfuscation #LOLBAS #Polymorphic Malware #Resume Malware #TA4557
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 05 May 2025 00:46:08 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #Malware #Arctic Wolf #backdoor #HR Phishing #JavaScript Obfuscation #LOLBAS #Polymorphic Malware #Resume Malware #TA4557
Daily CyberSecurity
Venom Spider Evolves: Arctic Wolf Exposes More_eggs Campaign Targeting HR
Arctic Wolf exposes Venom Spiderβs More_eggs campaign, where fake resumes and polymorphic JavaScript target HR to deploy a stealthy backdoor.
β€· Title: XMRig Cryptojacking Surges: New Campaign Uses LOLBAS, Steals Monero Undetected
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 08 Jul 2025 00:19:57 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #Cryptojacking #cybersecurity #G DATA #living_off_the_land #LOLBAS #malware #Monero #powershell #scheduled tasks #Threat Report #XMRig
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 08 Jul 2025 00:19:57 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #Cryptojacking #cybersecurity #G DATA #living_off_the_land #LOLBAS #malware #Monero #powershell #scheduled tasks #Threat Report #XMRig
Daily CyberSecurity
XMRig Cryptojacking Surges: New Campaign Uses LOLBAS, Steals Monero Undetected
XMRig cryptojacking is surging, leveraging LOLBAS techniques, PowerShell, and Scheduled Tasks to mine Monero undetected, with a 45% rally in XMR price driving the attacks.
β€· Title: Detecting Living-off-the-Land (LOLBAS) Attacks with Sigma Rules
ββββββββββββββββββββββββ
πͺ Author: ATNO For Cybersecurity | Hacking
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 31 Jul 2025 18:17:56 GMT
ββββββββββββββββββββββββ
β Tags: #lolbas #cybersecurity #living_off_the_land
ββββββββββββββββββββββββ
πͺ Author: ATNO For Cybersecurity | Hacking
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 31 Jul 2025 18:17:56 GMT
ββββββββββββββββββββββββ
β Tags: #lolbas #cybersecurity #living_off_the_land
Medium
π§ͺ Detecting Living-off-the-Land (LOLBAS) Attacks with Sigma Rules
Letβs talk about something sneakyβ¦
β€· Title: Living Off The Registry: Master AD CS Enumeration with the Native LOLBAS Toolkit
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 06 May 2026 08:38:36 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #Active Directory #AD CS #certreq.exe #certutil.exe #Credential Theft #LOLBAS #NET Framework #Pentesting #PowerShell #red teaming #RSAT #Windows Security
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 06 May 2026 08:38:36 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #Active Directory #AD CS #certreq.exe #certutil.exe #Credential Theft #LOLBAS #NET Framework #Pentesting #PowerShell #red teaming #RSAT #Windows Security
Penetration Testing Tools
Living Off The Registry: Master AD CS Enumeration with the Native LOLBAS Toolkit
Exploit Active Directory Certificate Services using only built-in Windows tools. No 3rd-party binariesβjust certreq, certutil, and native PowerShell power.