logo

Detecting Living-off-the-Land Attacks in OT Networks

ID: 35c0c017-a106-55f5-a2a2-62300bf5f89b

STIX ID: report--35c0c017-a106-55f5-a2a2-62300bf5f89b

Feed Name: Fidelis Security

Threat Score
85/100

Date Published: 2026-03-05

Date Updated: 2026-04-27

Author: Sarika Sharma

...
...

This report enumerates malicious TTPs observed in post-compromise activity: encoded PowerShell execution, WMI-based remote execution, scheduled-task persistence, credential extraction via Volume Shadow Copy/NTDS.dit access, fileless in-memory execution, and event-log clearing — several of which are attributed to Volt Typhoon and VOLTZITE. The focus is on detection-evasion techniques and native-tool misuse enabling persistence, credential theft, and forensic anti-analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.