logo

When legitimate tools go rogue

ID: 9178692f-ebc3-58cb-a3b9-5d8dde8178ad

STIX ID: report--9178692f-ebc3-58cb-a3b9-5d8dde8178ad

Feed Name: Cisco Talos

Threat Score
70/100

Date Published: 2025-06-18

Date Updated: 2026-04-27

Author: Hazel Burton

...
...

This Talos Incident Response summary explains that attackers increasingly "live off the land" by abusing built-in OS binaries (LOLBins), widely available open-source tools like DonPAPI, credential dumpers (Mimikatz), PsExec, and legitimate RMM/remote-access software to harvest credentials, move laterally, and maintain stealthy persistence; it recommends strong asset management, behavioral baselining, continuous monitoring, and aligning telemetry with current threat intelligence to detect such activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.