Eight chapters on LOLBin taxonomy, attacker tradecraft, detection strategy, KQL/Sigma queries, threat actor campaigns, and advanced evasion defense. Built for detection engineers and threat hunters who need to go beyond signatures.
What LOLBins are, why they exist, and why signature-based detection fails against them. The LOLBAS Project taxonomy and T1218 subtechnique structure.
Deep reference for certutil, mshta, regsvr32, rundll32, PowerShell, wmic, bitsadmin, and installutil. Abuse patterns, CommandLine indicators, and detection notes per binary.
Beyond executables: how attackers abuse built-in scripts, .NET libraries, and vulnerable kernel drivers. BYOVD attacks and the LOLDrivers catalog.
Download cradles, execution proxies, persistence mechanisms, lateral movement, and defense evasion patterns. How LOLBins chain together across an intrusion lifecycle.
Why behavioral detection beats signature detection for LOLBins. Parent-child process analysis, CommandLine baselining, network-side indicators, and alert triage methodology.
Production KQL, SPL, and Sigma rules for certutil, mshta, regsvr32, PowerShell IEX, wmic, bitsadmin, and more. Tuning guidance and false positive management per query.
How APT32, APT34, Lazarus, BlackMatter, LockBit, and Conti use LOLBins. Cobalt Strike stager delivery methods. Attribution signals and translating CTI into hunt hypotheses.
AMSI bypass detection, AppLocker/WDAC limitations, EDR evasion via LOLBins, hardening controls, Atomic Red Team validation, and threat-informed defense prioritization.
WHAT YOU SHOULD KNOW
WHAT YOU WILL KNOW AFTER
H3AD-SEC tools that pair directly with this module's content.
KQL/Sigma/XQL detection query arsenal organized by MITRE ATT&CK technique. Includes T1218 subtechnique coverage.
ATT&CK-driven hypothesis platform. Build and track LOLBin hunt hypotheses from CTI reports using the ABLE framework.
Pivot graph for threat investigations. Map LOLBin execution chains to IOCs, actors, and infrastructure during active hunts.
Threat query packs by campaign and CVE. Structured hunt packs ready to deploy for LOLBin-heavy actor campaigns.