LOLBAS abuse is a recurring technique across real-world intrusions: attackers reach for binaries already trusted on the endpoint (certutil, mshta, rundll32, and similar) to download, execute, or bypass controls without dropping new tooling. This reference covers legitimate use, real attacker syntax, detection logic, and defence guidance for each — no actor attribution, just the binaries and how to catch their abuse.
Category
Sort