Detecting Malicious Use of LOLBins, Pt. II | Huntress
ID: 11943064-fc1f-59f2-8831-971e7036ae32
STIX ID: report--11943064-fc1f-59f2-8831-971e7036ae32
Feed Name: Huntress Blog
The report examines how Windows “living off the land” binaries (LOLBins) like finger.exe, curl.exe, and certutil.exe are used and demonstrates that malicious activity is often detectable by comparing command-line usage against environment baselines. It highlights sparse legitimate use of finger.exe versus widespread curl.exe activity and showcases anomalous PowerShell-spawned curl/certutil executions, including an incident where certutil, launched via encoded PowerShell under sqlservr.exe (from FortiClient EMS), attempted to install a rogue ScreenConnect instance but was blocked. It recommends leveraging SIEM/EDR telemetry—particularly PowerShell Event ID 600 command lines—and focusing on command-line uniqueness to surface suspicious executions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
