LOLBAS Fundamentals
Attackers do not always need to drop malware. On every modern Windows system, a full toolkit already exists: signed, trusted, pre-installed, and excluded from most detection policies. This chapter explains what Living Off the Land means, how it works, and why traditional defenses fail against it.
What Is Living Off the Land?
Where the Term Comes From
The phrase "Living Off the Land" entered security research around 2013. Early APT reports began documenting a consistent pattern: advanced actors were completing intrusions without dropping a single custom binary. They used what was already there.
The term stuck because it captures the behavior precisely. A farmer living off the land uses what the environment provides. An attacker doing the same uses what Windows already installed.
Why the Binary Itself Isn't the Problem
The core principle is availability. Every Windows workstation ships with certutil.exe, mshta.exe, regsvr32.exe, rundll32.exe, and dozens of other capable utilities that are signed by Microsoft, trusted by every security product, and present in every environment. An attacker who uses certutil.exe to download a payload introduces no new binary, and that has three concrete consequences for a defender:
- No hash to block. The file matches the Microsoft-signed original.
- No suspicious file to detect. Nothing new touches disk that a scanner could flag.
- No unusual process list entry. The only thing that changed is how a legitimate tool was called.
Why EDR's Usual Signals Don't Fire
Modern EDRs and AV products have strong detection coverage for known malware families, built around recognizing something unusual. LOL techniques sidestep all three of the usual anchors:
| What EDR Normally Looks For | Why It Doesn't Fire Here |
|---|---|
| A file with a malicious hash | The hash matches the Microsoft-signed original |
| A known exploit signature | No exploit runs; the binary's native functionality is used as intended |
| A process with no legitimate business context | The process has been running on every Windows machine for twenty years |
What Attackers Actually Use LOLBins For
Attackers use LOLBins to accomplish three things:
- Execution. Running arbitrary code without dropping a foreign binary.
- Download. Fetching remote payloads through trusted Windows utilities that proxy network requests.
- Persistence. Maintaining access after reboots by embedding persistence in scheduled tasks, COM registrations, or BITS transfer jobs, all managed via built-in tools.
The LOLBAS Project
What the Project Is
The LOLBAS Project (lolbas-project.github.io) is the community-maintained reference catalog for Windows binaries, scripts, and libraries that can be abused for living-off-the-land attacks. Security researchers contribute entries, and the project is maintained on GitHub. It is the first place to check when building detection coverage for LOL techniques.
Anatomy of a Catalog Entry
Each catalog entry follows a consistent structure, read in this order:
The Four Categories
The catalog covers four categories, summarized below. As of 2026 the catalog contains 150+ entries, and researchers continue adding new discoveries.
| Category | Examples | Primary Abuse Goal |
|---|---|---|
| LOLBins | certutil.exe, mshta.exe, regsvr32.exe, rundll32.exe, bitsadmin.exe | Execution, download, proxy execution, persistence |
| LOLScripts | PowerShell (.ps1), VBScript (.vbs), JScript (.js), WSH (.wsf) | Arbitrary code execution via scripting engines |
| LOLLibs | .NET assemblies, COM scriptlets (scrobj.dll), MSXML | Code execution inside trusted process context |
| LOLDrivers | mhyprot2.sys, RTCore64.sys, various signed vendor drivers | EDR/AV termination via BYOVD (ring 0 access) |
Using the Catalog as a Hunt Program
For defenders, the LOLBAS Project functions as a hypothesis generator. Every entry is a potential hunt. The question for each one is: "Has this binary been used in my environment in a way that matches the documented abuse pattern?" Working through the catalog systematically, prioritized by technique prevalence and environment relevance, is a practical hunt program structure.
LOLBin, LOLScript, LOLLib, LOLDriver
The four categories are distinct in how they operate, what they require, and how difficult they are to detect. Understanding the differences matters for prioritizing detection coverage.
LOLBins
LOLBins (Living Off the Land Binaries) are signed Windows executables used for execution proxy, download, or persistence:
| Binary | Documented Abuse |
|---|---|
| certutil.exe | Download cradles and Base64 encode/decode operations |
| mshta.exe | Loading remote HTA files |
| regsvr32.exe | COM scriptlet execution (the Squiblydoo technique) |
| rundll32.exe | Arbitrary DLL loading |
| wscript.exe / cscript.exe | VBScript and JScript execution |
| bitsadmin.exe | BITS-based downloads |
| wmic.exe | Remote process creation |
| installutil.exe | Executing code embedded in .NET assemblies |
The common thread: each binary has a legitimate function that gives it trust, and each has a documented abuse pattern that exploits that trust.
LOLScripts
LOLScripts (Living Off the Land Scripts) are the scripting engines and script file formats used to run attacker-controlled code:
- PowerShell is the most widely abused, with documented techniques ranging from simple encoded commands to obfuscated multi-stage loaders.
- VBScript (.vbs) and JScript (.js) files, run through Windows Script Host, are common phishing delivery mechanisms.
- WSH files (.wsf) can combine multiple scripting languages in a single file.
The distinguishing characteristic of LOLScript abuse is that the script interpreter itself is trusted. The interpreter has not changed. The script it runs has.
LOLLibs
LOLLibs (Living Off the Land Libraries) are .NET assemblies and COM components loaded by legitimate processes to execute attacker code. This category is less commonly discussed but increasingly exploited:
- .NET assembly loading. Attackers load malicious .NET assemblies via installutil.exe or regasm.exe, which are themselves LOLBins.
- COM component abuse. Components registered in the user hive (HKCU) can be loaded by trusted processes to execute arbitrary code.
The detection challenge is that the loading process is legitimate, and the library being loaded may not touch disk at all.
LOLDrivers
LOLDrivers (Living Off the Land Drivers) are legitimate but vulnerable signed kernel drivers loaded via BYOVD (Bring Your Own Vulnerable Driver). The technique loads a vulnerable driver with a known exploit to achieve kernel-level code execution. Notable examples:
- mhyprot2.sys, a driver from the game Genshin Impact that several ransomware groups weaponized to terminate EDR processes.
- RTCore64.sys, from an MSI utility.
The driver is legitimately signed, passes code signing validation, and operates at ring 0.
ATT&CK Mapping for LOL Techniques
The T1218 Parent Technique
MITRE ATT&CK organizes LOLBin abuse primarily under T1218, System Binary Proxy Execution (formerly named Signed Binary Proxy Execution). The parent technique covers the general concept of using a signed Windows binary as a proxy to execute code, bypassing defenses that trust signed executables. T1218 currently has 14 named subtechniques, each covering a specific binary or technique family, including:
| Subtechnique | Binary / Method | Key Abuse |
|---|---|---|
| T1218.001 | Compiled HTML File | Execute script via .chm file loaded by hh.exe |
| T1218.004 | InstallUtil | Execute .NET assembly code via AppLocker bypass |
| T1218.005 | MSHTA | Load and execute remote HTA files |
| T1218.007 | Msiexec | Download and install remote MSI packages |
| T1218.008 | Odbcconf | Load arbitrary DLLs via REGSVR action |
| T1218.009 | Regasm / Regsvcs | Execute .NET assembly via COM registration utilities |
| T1218.010 | Regsvr32 (Squiblydoo) | Load remote COM scriptlets via scrobj.dll |
| T1218.011 | Rundll32 | Execute arbitrary code via DLL loading |
| T1218.014 | MMC | Execute code via malicious MMC snap-in |
Related Techniques Outside T1218
Several related techniques fall outside T1218 but are closely associated with LOL tradecraft:
- T1059 (Command and Scripting Interpreter) covers PowerShell (T1059.001), VBScript (T1059.005), and JavaScript/JScript (T1059.007).
- T1197 (BITS Jobs) covers bitsadmin-based downloads and persistence.
- T1105 (Ingress Tool Transfer) covers download cradles including certutil.
- T1140 (Deobfuscate/Decode Files) covers certutil -decode operations.
Why It Sits Under Defense Evasion
Most LOL techniques fall under the Defense Evasion tactic in the ATT&CK matrix. The mechanism is consistent: a technique evades defenses by executing inside the context of a trusted, signed Windows binary. The adversary is not evading detection by being stealthy. They are evading it by being indistinguishable from a legitimate process on first inspection.
The Pyramid of Pain is relevant here. Individual command line arguments sit at the TTP level, which is the hardest layer for an adversary to change. An actor can rotate IP addresses in minutes. They cannot stop using certutil for downloads without rewriting their toolkit. Detections anchored at the TTP level are more durable than those anchored at hashes or IPs.
Why Traditional Defenses Struggle
Four Ways the Usual Approaches Fail
| Defense Approach | Why It Fails Against LOLBins |
|---|---|
| Hash-based detection | The binary is always certutil.exe, signed by Microsoft, with a known-good hash that appears in every threat intelligence feed as benign. Hash lookups are the foundation of most AV and EDR allow/deny decisions, and for LOLBins that foundation is structurally irrelevant. |
| Signature-based behavioral rules | Certutil.exe runs constantly in enterprise environments for certificate operations: verifying OCSP, managing local certificate stores, parsing CRL files. A rule that fires on any certutil execution would generate thousands of alerts per day in a medium-sized organization, and analysts who investigate, find nothing, and investigate again tomorrow eventually stop investigating. |
| Application allowlisting | Regsvr32.exe is on every allowlist because Windows requires it for COM registration, so the entry cannot simply be removed. What it needs is refinement: allow regsvr32 for standard system32 COM paths and DLLs, alert on regsvr32 with a URL in the command line, a distinction basic allowlisting does not provide. |
| Alert-volume tuning | When LOLBin detections are broad and noisy, analysts face a choice between investigating every alert (unsustainable) or tuning the alert volume down (creates gaps). A commonly cited attacker tactic is to intentionally trigger noisy but benign-looking LOLBin activity first, saturating the alert queue before the actual malicious phase begins. |
The Structural Solution: Behavioral Context
A certutil alert that fires only when certutil makes an outbound HTTP request, was not spawned by a WSUS relay or a certificate auto-enrollment service, and is running on a standard user workstation has a fundamentally different false positive profile than a rule on certutil alone. That combination is the indicator, and none of its elements is individually sufficient:
- The binary itself
- The parent process
- Command line flags
- Network behavior
What This Module Covers
Eight chapters build from fundamentals to advanced evasion, with a total time investment of roughly 10 hours. Each chapter stands alone, but the sequence is deliberate: concepts introduced early reappear in the detection and tradecraft chapters later.
- Chapter 1 (this chapter). The vocabulary, the threat model, and the detection problem.
- Chapter 2, LOLBin Catalog. The 12 most abused binaries, their documented commands, their ATT&CK IDs, and the single highest-signal detection pattern for each.
- Chapter 3, LOLScripts, LOLLibs, and LOLDrivers. PowerShell abuse techniques, .NET assembly exploitation, and BYOVD mechanics.
- Chapter 4, Attacker Tradecraft. How threat actors chain multiple LOLBins to build complete attack chains from initial access through persistence and lateral movement without ever dropping a foreign binary.
- Chapter 5, Detection Strategy. Behavioral detection architecture, parent-child process analysis, command line baselining, and building detections that survive production environments.
- Chapter 6, Detection Queries. KQL, SPL, and Sigma detection queries for every major LOLBin covered in the module.
- Chapter 7, Threat Actor Usage. Real-world campaigns: APT29 (Cozy Bear), FIN7, and several ransomware groups have documented LOLBin usage, and understanding how specific actors use these techniques informs detection prioritization.
- Chapter 8, Advanced Evasion. AMSI bypass techniques, script block logging evasion, AppLocker bypass chains, BYOVD in detail, and the hardening controls that raise the cost of LOL attacks.
The full module is approximately 10 hours of content across 8 chapters, with knowledge checks and detection query exercises throughout. The skill range moves from beginner (Chapters 1 and 2) through intermediate (Chapters 3 through 6) to advanced (Chapters 7 and 8). Working through the module sequentially provides the most complete picture, but individual chapters are self-contained enough to be used as references.
Key Takeaways
- Living Off the Land means using pre-installed, signed Windows tools for malicious purposes. No new binary, no new hash, no file to detect.
- The LOLBAS Project (lolbas-project.github.io) maintains the authoritative catalog of abusable Windows binaries, scripts, libraries, and drivers.
- Four categories: LOLBins (executables), LOLScripts (scripting engines), LOLLibs (.NET/COM), LOLDrivers (vulnerable kernel drivers for BYOVD).
- ATT&CK T1218 (System Binary Proxy Execution) covers LOLBin abuse with multiple subtechniques. Related techniques include T1059, T1197, and T1105.
- Traditional hash and signature-based detection cannot catch LOLBin abuse because the binary is always the legitimate Windows file with a valid Microsoft signature.
- Effective LOLBin detection requires behavioral context: the combination of binary, parent process, command line flags, and network behavior is the indicator, not the binary alone.
Knowledge Check
Click an answer to reveal the explanation.
What is the primary reason hash-based detection fails against LOLBin abuse?
Which LOLBin category operates at the kernel level and is used to terminate EDR processes?
Where should you look to find the abuse commands and ATT&CK mappings for a specific Windows binary?