Using ‘Living-off-the-land’ (LOLBins) means attackers are using pre-installed tools to carry out their work. This makes it more difficult for defenders to detect attacks and researchers to identify the attackers behind the campaign. LoLBins are used by different actors combined with fileless malware and legitimate cloud services to improve chances of staying undetected. In this post, we will take a look at the use of LOLBins through the lense of Cisco’s product telemetry. We’ll also walk through the most frequently abused Windows system binaries and measure their usage.”]
Source: https://blog.talosintelligence.com/2019/11/hunting-for-lolbins.html

