CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

LOLBins: What are they & How to Detect Them

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 900

As cited

Copy frozen at (site build).

threat intel

LOLBins: What are they & How to Detect Them

Living-off-the-Land Binaries (LOLBins) are legitimate system tools that threat actors exploit to carry out malicious activities while evading detection. The article discusses how these binaries pose security risks, outlines detection methods, and covers prevention strategies to mitigate attacks that abuse native operating system utilities.

Why it matters: Security teams need to understand LOLBin abuse techniques to detect anomalous behavior from legitimate processes and implement controls that prevent threat actors from using built-in tools to move laterally or execute payloads.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary