πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 30 Aug 2023 03:46:00 GMT
βββββββββββββββ
βοΈTitle: LOLBinβββExecution via Diskshadow
βββββββββββββββ
πLink: https://medium.com/p/f6ff681a27a4
βββββββββββββββ
Tags: #mitre_attack_framework #lolbin #cybersecurity #incident_response #detection_engineering
βββββββββββββββ
πDate: Wed, 30 Aug 2023 03:46:00 GMT
βββββββββββββββ
βοΈTitle: LOLBinβββExecution via Diskshadow
βββββββββββββββ
πLink: https://medium.com/p/f6ff681a27a4
βββββββββββββββ
Tags: #mitre_attack_framework #lolbin #cybersecurity #incident_response #detection_engineering
Medium
LOLBin β Execution via Diskshadow
Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS). By default, Diskshadow uses anβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Thu, 05 Oct 2023 18:30:16 GMT
βββββββββββββββ
βοΈTitle: Everybody LOLs, Sometimes.
βββββββββββββββ
πLink: https://medium.com/p/1a5e4a49e898
βββββββββββββββ
Tags: #writeup #defend #state_sponsored_hacking #lolbin
βββββββββββββββ
πDate: Thu, 05 Oct 2023 18:30:16 GMT
βββββββββββββββ
βοΈTitle: Everybody LOLs, Sometimes.
βββββββββββββββ
πLink: https://medium.com/p/1a5e4a49e898
βββββββββββββββ
Tags: #writeup #defend #state_sponsored_hacking #lolbin
Medium
Everybody LOLs, Sometimes.
Understanding state sponsored attacks and LOLBINS. A Case Study.
β€· Title: Benign | TryHackMeβββWalkthrough
ββββββββββββββββββββββββ
πͺ Author: Manivel
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 08 Jan 2025 11:29:58 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #cybersecurity #splunk #tryhackme #benign
ββββββββββββββββββββββββ
πͺ Author: Manivel
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 08 Jan 2025 11:29:58 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #cybersecurity #splunk #tryhackme #benign
Medium
Benign | TryHackMe β Walkthrough
walkthrough Splunk Investigation Challenge on TryHackMe, titled Benign.
β€· Title: Living Off The Land Binaries, Scripts and Libraries
ββββββββββββββββββββββββ
πͺ Author: Temesgen Janbo
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 05 Apr 2025 09:49:17 GMT
ββββββββββββββββββββββββ
β Tags: #soc #detection #cybersecurity #lolbas #lolbin
ββββββββββββββββββββββββ
πͺ Author: Temesgen Janbo
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 05 Apr 2025 09:49:17 GMT
ββββββββββββββββββββββββ
β Tags: #soc #detection #cybersecurity #lolbas #lolbin
Medium
Living Off The Land Binaries, Scripts and Libraries
Imagine an attacker breaking into your internal system without using or developing their own [malicious] tool with out worrying about ifβ¦
β€· Title: Living off the Land Binaries (LOLBins): How Attackers Use Built-In Tools Against You
ββββββββββββββββββββββββ
πͺ Author: Paritosh
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 08 Apr 2025 03:01:58 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #information_technology #hacking #lolbin #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Paritosh
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 08 Apr 2025 03:01:58 GMT
ββββββββββββββββββββββββ
β Tags: #bug_bounty #information_technology #hacking #lolbin #cybersecurity
Medium
Living off the Land Binaries (LOLBins): How Attackers Use Built-In Tools Against You
When you think of cyberattacks, you might imagine shadowy hackers using advanced malware or zero-day exploits. But in reality, manyβ¦
β€· Title: Unpacking an Obfuscated AutoIt Malware Campaign Delivering Lumma Stealer
ββββββββββββββββββββββββ
πͺ Author: Imane Ismail
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 06 May 2025 11:35:58 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #incident_response #lolbin #lumma_steler #malware_triage
ββββββββββββββββββββββββ
πͺ Author: Imane Ismail
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 06 May 2025 11:35:58 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #incident_response #lolbin #lumma_steler #malware_triage
Medium
Unpacking an Obfuscated AutoIt Malware Campaign Delivering Lumma Stealer
Executive Summary
β€· Title: Catching LOLBins in Action: Practical Detection Queries
ββββββββββββββββββββββββ
πͺ Author: Paritosh
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 07 Jun 2025 07:26:13 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #lolbin #hacking #detection #threat_intelligence
ββββββββββββββββββββββββ
πͺ Author: Paritosh
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 07 Jun 2025 07:26:13 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #lolbin #hacking #detection #threat_intelligence
Medium
Catching LOLBins in Action: Practical Detection Queries
Living-Off-the-Land Binaries (LOLBins) like PowerShell, Certutil, or Rundll32 are legitimate Windows tools that attackers misuse to blendβ¦
β€· Title: Abuse of Legitimate Tools in Cyberattacks (LOLBins and Living-off-the-Land Techniques)
ββββββββββββββββββββββββ
πͺ Author: Akshay Chauhan
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 19 Jun 2025 20:50:39 GMT
ββββββββββββββββββββββββ
β Tags: #malware #cybersecurity #information_security #lolbin
ββββββββββββββββββββββββ
πͺ Author: Akshay Chauhan
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 19 Jun 2025 20:50:39 GMT
ββββββββββββββββββββββββ
β Tags: #malware #cybersecurity #information_security #lolbin
Medium
Abuse of Legitimate Tools in Cyberattacks (LOLBins and Living-off-the-Land Techniques)
Cybercriminals no longer rely only on malware to break into systems. Instead, they exploit legitimate tools like PowerShell, Certutil, andβ¦
β€· Title: When Legitimate Becomes Malicious: A Begginer Guide to LOLBins
ββββββββββββββββββββββββ
πͺ Author: R1cH4t
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 28 Jun 2025 23:11:20 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: R1cH4t
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 28 Jun 2025 23:11:20 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #cybersecurity
Medium
When Legitimate Becomes Malicious: A Begginer Guide to LOLBins
Once an attacker gains initial access to a system whether through phishing, vulnerability exploitation, or stolen credentials the next stepβ¦
β€· Title: LolBins ΰ¦
ΰ§ΰ¦―ΰ¦Ύΰ¦ΰ¦Ύΰ¦ ΰ¦ΰ¦° বিসΰ§ΰ¦€ΰ¦Ύΰ¦°ΰ¦Ώΰ¦€
ββββββββββββββββββββββββ
πͺ Author: Shahriar Galib
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 20 Aug 2025 21:30:17 GMT
ββββββββββββββββββββββββ
β Tags: #spylerbd #malware #lolbin #red_teaming #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Shahriar Galib
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 20 Aug 2025 21:30:17 GMT
ββββββββββββββββββββββββ
β Tags: #spylerbd #malware #lolbin #red_teaming #cybersecurity
Medium
LolBins ΰ¦
ΰ§ΰ¦―ΰ¦Ύΰ¦ΰ¦Ύΰ¦ ΰ¦ΰ¦° বিসΰ§ΰ¦€ΰ¦Ύΰ¦°ΰ¦Ώΰ¦€
How Windows gets stabbed by it's own program!
β€· Title: CyberDefendersβββRhysida Lab (Writeup)
ββββββββββββββββββββββββ
πͺ Author: Muhammed Alaa
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 07 Nov 2025 15:36:26 GMT
ββββββββββββββββββββββββ
β Tags: #cyberdefenders_writeup #lolbin #cybersecurity #ransomware #threat_hunting
ββββββββββββββββββββββββ
πͺ Author: Muhammed Alaa
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 07 Nov 2025 15:36:26 GMT
ββββββββββββββββββββββββ
β Tags: #cyberdefenders_writeup #lolbin #cybersecurity #ransomware #threat_hunting
Medium
CyberDefenders β Rhysida Lab (Writeup)
Lab Link: https://cyberdefenders.org/blueteam-ctf-challenges/rhysida/
β€· Title: VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 15 Dec 2025 00:00:31 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #cmstp.exe #LOLBIN #node_modules #Rust Trojan #steganography #supply chain attack #Typosquatting #VS Code
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 15 Dec 2025 00:00:31 +0000
ββββββββββββββββββββββββ
β Tags: #Malware #cmstp.exe #LOLBIN #node_modules #Rust Trojan #steganography #supply chain attack #Typosquatting #VS Code
Daily CyberSecurity
VS Code Supply Chain Attack: 19 Extensions Used Typosquatting & Steganography to Deploy Rust Trojan
19 malicious VS Code extensions bypassed detection by hiding a Rust trojan in tampered node_modules and a fake banner.png using steganography. The attack uses cmstp.exe (LOLBIN) for execution.
β€· Title: Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 15 Dec 2025 00:11:49 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
ββββββββββββββββββββββββ
πͺ Author: Ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 15 Dec 2025 00:11:49 +0000
ββββββββββββββββββββββββ
β Tags: #Cybercriminals #DLL Sideloading #EDR Bypass #IAB #initial access broker #LOLBIN #ransomware #SentinelOne #Storm_0249
Daily CyberSecurity
Storm-0249 Abuses EDR Process via DLL Sideloading to Cloak Ransomware Access
Storm-0249 IAB abuses the SentinelOne EDR process via DLL sideloading to evade detection. The group uses LoLBin tools for fileless execution and sells access to ransomware groups like LockBit.
β€· Title: Boogeyman 3 Capstone (TryHackMe): Full Kill Chain Analysis from Initial Access to Domain Compromise
ββββββββββββββββββββββββ
πͺ Author: OwlPharaoh
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 08 Jan 2026 16:21:41 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #lolbin #boogeyman #cyber_kill_chain #tryhackme
ββββββββββββββββββββββββ
πͺ Author: OwlPharaoh
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 08 Jan 2026 16:21:41 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #lolbin #boogeyman #cyber_kill_chain #tryhackme
Medium
Boogeyman 3 Capstone (TryHackMe): Full Kill Chain Analysis from Initial Access to Domain Compromise
Overview
β€· Title: Surge in βClickFixβ Fileless Attacks Leveraging LOLBins on Windows
ββββββββββββββββββββββββ
πͺ Author: Yeshu Wanjari
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 12 Jan 2026 09:23:00 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #hacking #security_operation_center #clickfix #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Yeshu Wanjari
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 12 Jan 2026 09:23:00 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #hacking #security_operation_center #clickfix #cybersecurity
Medium
Surge in βClickFixβ Fileless Attacks Leveraging LOLBins on Windows
Security analysts have observed a sharp rise in βClickFixβ-style campaigns since late 2024, with activity peaking in 2026, wherein phishingβ¦
β€· Title: How Attackers Use Certutil to Download and Decode Malware
ββββββββββββββββββββββββ
πͺ Author: wassim A
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 22 Feb 2026 00:05:11 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #cybersecurity #hacking #technology #information_security
ββββββββββββββββββββββββ
πͺ Author: wassim A
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 22 Feb 2026 00:05:11 GMT
ββββββββββββββββββββββββ
β Tags: #lolbin #cybersecurity #hacking #technology #information_security
Medium
How Attackers Use Certutil to Download and Decode Malware
Hello everyone,
β€· Title: Microsoftβs Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks
ββββββββββββββββββββββββ
πͺ Author: Deeba Ahmed
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 21 May 2026 10:18:11 +0000
ββββββββββββββββββββββββ
β Tags: #Security #Malware #Microsoft #Cyber Attack #Cybersecurity #Fileless #LOLBIN #MSHTA #Vulnerability
ββββββββββββββββββββββββ
πͺ Author: Deeba Ahmed
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 21 May 2026 10:18:11 +0000
ββββββββββββββββββββββββ
β Tags: #Security #Malware #Microsoft #Cyber Attack #Cybersecurity #Fileless #LOLBIN #MSHTA #Vulnerability
Hackread
Microsoftβs Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks
Despite Internet Explorerβs retirement, hackers are abusing the legacy MSHTA utility in stealthy fileless malware attacks targeting Windows users.