Detecting Living-off-the-Land Attacks in OT Networks
ID: 35c0c017-a106-55f5-a2a2-62300bf5f89b
STIX ID: report--35c0c017-a106-55f5-a2a2-62300bf5f89b
Feed Name: Fidelis Security
Threat Score
This report enumerates malicious TTPs observed in post-compromise activity: encoded PowerShell execution, WMI-based remote execution, scheduled-task persistence, credential extraction via Volume Shadow Copy/NTDS.dit access, fileless in-memory execution, and event-log clearing — several of which are attributed to Volt Typhoon and VOLTZITE. The focus is on detection-evasion techniques and native-tool misuse enabling persistence, credential theft, and forensic anti-analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
