Skip to content
Threat Feed

Tag

LOLBAS

13 briefs RSS
medium advisory

Detection of Anomalous Network Activity from LOLBAS Binaries

This brief details a detection strategy for identifying unauthorized outbound network connections initiated by native Windows Living Off the Land Binaries and Scripts (LOLBAS) often used for C2 and payload delivery.

Windows lolbas defense-evasion network-security
1r 3t
medium advisory

Detection of LOLBAS Network Connections on Uncommon Ports

An analytic identification of Living Off the Land Binaries and Scripts (LOLBAS) initiating public network connections over non-standard destination ports, indicating potential staging or command-and-control activity.

Windows LOLBAS network-anomaly defense-evasion windows-endpoint
1r 3t
medium advisory

Abuse of print.exe for Unauthorized File Transfer

Attackers can leverage the legitimate Windows print.exe utility to perform unauthorized remote file copying, facilitating data staging and exfiltration.

living-off-the-land LOLBAS file-transfer
1r 1t
high advisory

Detection of CMSTP App Paths Registry Modification

Adversaries leverage the Microsoft Connection Manager Profile Installer (CMSTP) via registry modifications to achieve arbitrary code execution or bypass User Account Control (UAC).

execution persistence privesc lolbas
1r 1t
high advisory

Svchost LOLBAS Execution Process Spawn

This brief details the detection of `svchost.exe` spawning Living Off The Land Binaries and Scripts (LOLBAS) processes, indicating potential malicious code execution, privilege escalation, or persistence attempts by adversaries within a Windows environment.

Windows lolbas execution persistence lateral-movement system-binary-proxy-execution
1r 2t
high advisory

Suspicious Download From File-Sharing Website Via Bitsadmin

This threat brief details the detection of adversaries leveraging the legitimate Windows Background Intelligent Transfer Service (BITSAdmin) utility to download malicious payloads from suspicious file-sharing and cloud storage domains, a technique commonly employed by ransomware groups and APTs for ingress tool transfer and stealthy execution.

living-off-the-land lolbas payload-delivery ingress-tool-transfer command-and-control windows
1r 4t 35i
medium advisory

Suspicious Execution via Windows Command Debugging Utility

Adversaries can abuse the Windows command line debugging utility cdb.exe to execute commands or shellcode from non-standard paths, evading traditional security measures.

Microsoft Defender XDR +5 lolbas defense-evasion windows
2r 2t
medium advisory

Suspicious Execution via Windows Command Debugging Utility (cdb.exe)

Adversaries can abuse the Windows command line debugging utility cdb.exe, specifically when executed from non-standard paths with specific command-line arguments (-cf, -c, -pd), to execute commands or shellcode for defense evasion.

Windows defense-evasion lolbas
2r 2t
high advisory

Suspicious MSHTML/MSHTA Network Execution Without Direct URL

This analytic detects the anomalous execution of mshta.exe or rundll32.exe invoking mshtml.dll without a direct HTTP/HTTPS URL in the command line, potentially indicating obfuscated script execution by threat actors for initial access or payload staging while evading static detections.

Windows mshta mshtml rundll32 lolbas defense-evasion initial-access network-execution
2r 2t
high advisory

Suspicious MSBuild Execution from Non-Standard Path

Detection of msbuild.exe execution from a non-standard path, indicating potential attempts to evade detection and execute malicious code.

Splunk Enterprise +2 msbuild lolbas living-off-the-land defense-evasion
3r 2t
high advisory

HTML Help Executable Spawning Child Processes

The execution of hh.exe (HTML Help) spawning a child process indicates the use of a Compiled HTML Help (CHM) file to execute potentially malicious Windows script code.

Microsoft Windows html-help chm lolbas process-creation
2r 1t
low advisory

Windows Delayed Execution via Ping Followed by Malicious Utilities

Adversaries may use ping to delay execution of malicious commands, scripts, or binaries to evade detection, often observed during malware installation.

Windows execution defense-evasion ping lolbas
2r 14t
medium advisory

Windows Update Client DLL Loading Abuse

Adversaries abuse the Windows Update Auto Update Client (wuauclt.exe) to load arbitrary DLLs from user-writable locations, achieving defense evasion and execution of malicious code.

Windows defense-evasion execution lolbas
2r 2t