Detection of Windows LOLBAS Execution from Unexpected Paths
This detection identifies adversary defense evasion via the execution of Living Off the Land Binaries and Scripts (LOLBAS) from non-standard directory locations.
This detection analytic identifies instances where Windows native binaries, identified as part of the LOLBAS project, are executed from file paths outside of standard system directories. Adversaries frequently leverage LOLBAS to execute malicious code, perform reconnaissance, or maintain persistence while evading traditional signature-based security controls. By moving or renaming legitimate system utilities to non-standard locations, such as temporary directories or user-profile folders, attackers attempt to bypass path-based blocklists and application allowlisting policies. This analytic specifically monitors process execution telemetry to flag deviations from known-good installation paths, including directories like System32, SysWOW64, and Program Files, providing visibility into potential defense evasion activity.
Impact
Successful exploitation of LOLBAS binaries allows attackers to blend malicious activity with legitimate system processes, complicating incident response and forensic analysis. Unauthorized execution of these utilities can facilitate lateral movement, privilege escalation, and data exfiltration within an enterprise environment.
Recommendation
Detection engineering teams should implement the provided Sigma rule to monitor for process executions occurring outside of authorized system paths. It is critical to tune this analytic against the specific environment to establish an allowlist for third-party software or legitimate administrative scripts that may utilize binaries from non-standard locations. Ensure Sysmon Event ID 1 or Windows Event ID 4688 is enabled to capture necessary process path telemetry for this detection.
Immediate actions
Deploy the provided detection rule to the SIEM.
Threat Hunt
Identify all process executions from C:\Users\Public\ and C:\ProgramData\.
Data: Process creation logs
Detection coverage 1
Detect Windows LOLBAS Executed Outside Expected Path
mediumDetects the execution of Windows native binaries from non-standard file paths, which may indicate adversary defense evasion.
Detection queries are available on the platform. Get full rules →