Skip to content
Threat Feed
medium advisory

Detection of Windows LOLBAS Execution from Unexpected Paths

This detection identifies adversary defense evasion via the execution of Living Off the Land Binaries and Scripts (LOLBAS) from non-standard directory locations.

This detection analytic identifies instances where Windows native binaries, identified as part of the LOLBAS project, are executed from file paths outside of standard system directories. Adversaries frequently leverage LOLBAS to execute malicious code, perform reconnaissance, or maintain persistence while evading traditional signature-based security controls. By moving or renaming legitimate system utilities to non-standard locations, such as temporary directories or user-profile folders, attackers attempt to bypass path-based blocklists and application allowlisting policies. This analytic specifically monitors process execution telemetry to flag deviations from known-good installation paths, including directories like System32, SysWOW64, and Program Files, providing visibility into potential defense evasion activity.

Impact

Successful exploitation of LOLBAS binaries allows attackers to blend malicious activity with legitimate system processes, complicating incident response and forensic analysis. Unauthorized execution of these utilities can facilitate lateral movement, privilege escalation, and data exfiltration within an enterprise environment.

Recommendation

Detection engineering teams should implement the provided Sigma rule to monitor for process executions occurring outside of authorized system paths. It is critical to tune this analytic against the specific environment to establish an allowlist for third-party software or legitimate administrative scripts that may utilize binaries from non-standard locations. Ensure Sysmon Event ID 1 or Windows Event ID 4688 is enabled to capture necessary process path telemetry for this detection.


Immediate actions

Deploy the provided detection rule to the SIEM.

Detection Engineering 48h

Threat Hunt

Identify all process executions from C:\Users\Public\ and C:\ProgramData\.

T1036 medium medium confidence hunt now

Data: Process creation logs

Detection coverage 1

Detect Windows LOLBAS Executed Outside Expected Path

medium

Detects the execution of Windows native binaries from non-standard file paths, which may indicate adversary defense evasion.

sigma tactics: defense_evasion techniques: T1036.005, T1218.011 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →