Detecting Living Off The Land attacks with Wazuh
ID: 6f902560-0b5a-55e5-8af1-92170743e312
STIX ID: report--6f902560-0b5a-55e5-8af1-92170743e312
Feed Name: Bleeping Computer
This Wazuh-sponsored article explains Living Off the Land (LOTL) attack techniques—abuse of native tools like PowerShell, schtasks, WMIC, cron, and SSH—and details how to detect related behaviors using Wazuh’s XDR/SIEM features, including real-time log analysis with custom rules, Security Configuration Assessment, File Integrity Monitoring, command monitoring for resource anomalies, and vulnerability detection to identify initial access attempts, tool abuse, unauthorized configuration changes, and exposure to known CVEs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
