logo

Detecting Malicious Use of LOLBins | Huntress

ID: 20f60919-372a-5efb-b724-5c796d9d633d

STIX ID: report--20f60919-372a-5efb-b724-5c796d9d633d

Feed Name: Huntress Blog

Threat Score
35/100

Date Published: 2024-09-11

Date Updated: 2026-04-28

...
...

This briefing explains how adversaries misuse legitimate system binaries (LOLBins) like net.exe, cmd.exe, and PowerShell to conduct stealthy operations—user creation, privilege escalation, lateral movement, persistence, and data exfiltration—and provides detection heuristics and mitigation advice, including process lineage checks, account-naming convention validation, command-line structure analysis, and examples of observed malicious commands and reused credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.