LOLBAS abuse is a recurring technique across real-world intrusions: attackers reach for binaries already trusted on the endpoint (certutil, mshta, rundll32, and similar) to download, execute, or bypass controls without dropping new tooling. This reference covers legitimate use, real attacker syntax, detection logic, and defence guidance for each — no actor attribution, just the binaries and how to catch their abuse.
Category
Sort
Twelve hunt scenarios: five cover the core categories in this reference, four extend or split those categories as they grew (a second proxy-execution wave, UAC bypass split out from AppLocker/WDAC bypass, Alternate-Data-Stream staging, and Shadow Copy credential extraction), and three chain across categories to trace a fuller intrusion pattern. Each pairs a hypothesis with the data sources to pull and an ordered sequence of binaries to check. Click any step to jump straight to that binary's detection queries.