All Modules LOLBAS

Living Off the Land · Complete Guide

Eight chapters on LOLBin taxonomy, attacker tradecraft, detection strategy, KQL/Sigma queries, threat actor campaigns, and advanced evasion defense. Built for detection engineers and threat hunters who need to go beyond signatures.

8 CHAPTERS
~10 HRS CONTENT
INTERMEDIATE to ADVANCED SKILL RANGE
JUN 2026 LAST UPDATED
MODULE PROGRESS 0 / 8 chapters complete
LOLBins T1218 LOTL certutil PowerShell KQL Sigma behavioral detection

ALL CHAPTERS

01
BEGINNER 30 min

LOL Fundamentals

What LOLBins are, why they exist, and why signature-based detection fails against them. The LOLBAS Project taxonomy and T1218 subtechnique structure.

taxonomy T1218 LOLBAS
02
INTERMEDIATE 40 min

LOLBin Catalog

Deep reference for certutil, mshta, regsvr32, rundll32, PowerShell, wmic, bitsadmin, and installutil. Abuse patterns, CommandLine indicators, and detection notes per binary.

certutil mshta regsvr32
03
INTERMEDIATE 30 min

LOLScripts, LOLLibs, and LOLDrivers

Beyond executables: how attackers abuse built-in scripts, .NET libraries, and vulnerable kernel drivers. BYOVD attacks and the LOLDrivers catalog.

LOLScripts LOLDrivers BYOVD
04
INTERMEDIATE 35 min

Attacker Tradecraft

Download cradles, execution proxies, persistence mechanisms, lateral movement, and defense evasion patterns. How LOLBins chain together across an intrusion lifecycle.

download cradle lateral movement PPID spoofing
05
INTERMEDIATE 35 min

Detection Strategy

Why behavioral detection beats signature detection for LOLBins. Parent-child process analysis, CommandLine baselining, network-side indicators, and alert triage methodology.

behavioral parent-child baselining
06
INTERMEDIATE 40 min

Detection Queries

Production KQL, SPL, and Sigma rules for certutil, mshta, regsvr32, PowerShell IEX, wmic, bitsadmin, and more. Tuning guidance and false positive management per query.

KQL SPL Sigma
07
ADVANCED 35 min

Threat Actor Campaigns

How APT32, APT34, Lazarus, BlackMatter, LockBit, and Conti use LOLBins. Cobalt Strike stager delivery methods. Attribution signals and translating CTI into hunt hypotheses.

APT ransomware Cobalt Strike
08
ADVANCED 40 min

Advanced Evasion and Defense

AMSI bypass detection, AppLocker/WDAC limitations, EDR evasion via LOLBins, hardening controls, Atomic Red Team validation, and threat-informed defense prioritization.

AMSI WDAC Atomic Red Team

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • Windows OS fundamentals: processes, registry, file system, and signed binary concepts
  • Basic SIEM or query language exposure (KQL, SPL, or similar)
  • Familiarity with MITRE ATT&CK technique structure and T-numbers
  • General understanding of how endpoint security and AV products work

WHAT YOU WILL KNOW AFTER

  • The full LOLBin taxonomy: LOLBins, LOLScripts, LOLLibs, and LOLDrivers
  • How to write behavioral KQL, SPL, and Sigma rules for T1218 subtechniques
  • How APT and ransomware operators use LOLBins across the intrusion lifecycle
  • How to translate CTI reports into hunt hypotheses using actor LOLBin patterns
  • Which hardening controls actually reduce LOTL attack surface and which do not
  • How to validate detection coverage using Atomic Red Team and track coverage gaps

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.

VISITORS