logo

Living Off the Land and vulnerable drivers

ID: e9f24a3e-7fbe-5c42-99e9-86a44002f701

STIX ID: report--e9f24a3e-7fbe-5c42-99e9-86a44002f701

Feed Name: ThreatLocker Blog

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

This piece explains the LOTL and BYOVD techniques—how attackers leverage built-in Windows tools and load vulnerable drivers to elevate privileges and evade defenses—then outlines preventive practices such as avoiding untrusted software, employing default-deny allowlisting, and restricting authorized tools’ network/process access. It highlights ThreatLocker capabilities (default blocking of unknown software and Ringfencing to limit actions by approved applications like PowerShell) as practical controls to reduce the risk of these techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.