Imported from oyi77/1ai-skills (
cybersecurity/_deprecated/hunting-for-living-off-the-land-binaries/SKILL.md). Install upstream withnpx skills add oyi77/1ai-skills --skill hunting-for-living-off-the-land-binaries. Copyright stays with the author (Apache-2.0).
Hunting For Living Off The Land Binaries
Overview
Cybersecurity skill for hunting for living off the land binaries. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for living off the land binaries"
-
"Proactively hunt for adversary abuse of legitimate system binaries (LOLBins) to "
-
When investigating fileless malware campaigns that bypass traditional AV
-
During proactive threat hunts targeting defense evasion techniques
-
When EDR alerts fire on legitimate binaries executing unusual child processes
-
After threat intelligence reports indicate LOLBin abuse in active campaigns
-
During red team/purple team exercises validating detection coverage for T1218
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Access to EDR telemetry (CrowdStrike, Microsoft Defender for Endpoint, SentinelOne)
- SIEM with process creation logs (Sysmon Event ID 1, Windows Security 4688)
- Familiarity with LOLBAS Project (lolbas-project.github.io) reference list
- PowerShell command-line logging enabled (Module Logging, Script Block Logging)
- Network proxy or firewall logs for correlating outbound connections
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Define Detection Scope — Identify the specific techniques or indicators to hunt. Map to MITRE ATT&CK tactics/techniques where applicable.
- Collect Baseline Data — Gather historical logs and establish normal behavior patterns for .
- Build Detection Queries — Write living off the land binaries queries targeting indicators. Use platform-specific query language for optimal performance.
- Execute Hunts — Run queries against the collected data, starting with broad filters and narrowing down.
- Triage Results — Investigate alerts, filter false positives, and validate findings against known-good behavior.
- Document Findings — Record confirmed detections, IOCs, and affected systems. Update detection rules based on findings.
Tools
- living off the land binaries — Primary tool for this skill
- SIEM Platform — Central log aggregation and query execution
- Sigma Rules — Vendor-agnostic detection rule format
- MITRE ATT&CK Navigator — Technique mapping and coverage analysis
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
- All procedures executed completely and documented
- Findings validated against multiple data sources
- False positives identified and filtered
- Results documented with evidence and timestamps
- Recommendations provided with risk-based prioritization
Anti-Rationalization Table
| Rationalization | Reality |
|---|---|
| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |
| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |