When legitimate tools go rogue
ID: 9178692f-ebc3-58cb-a3b9-5d8dde8178ad
STIX ID: report--9178692f-ebc3-58cb-a3b9-5d8dde8178ad
Feed Name: Cisco Talos
This Talos Incident Response summary explains that attackers increasingly "live off the land" by abusing built-in OS binaries (LOLBins), widely available open-source tools like DonPAPI, credential dumpers (Mimikatz), PsExec, and legitimate RMM/remote-access software to harvest credentials, move laterally, and maintain stealthy persistence; it recommends strong asset management, behavioral baselining, continuous monitoring, and aligning telemetry with current threat intelligence to detect such activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
