LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
ID: db5a4365-8f7c-5497-ba37-8c93f44f245a
STIX ID: report--db5a4365-8f7c-5497-ba37-8c93f44f245a
Feed Name: Huntress Blog
**Executive summary:** This article explains living-off-the-land (LoTL) abuse—where attackers use legitimate administrative tools (PowerShell, WMI, RMM, built-in accounts) to evade detection—details behavioral indicators to distinguish malicious from routine admin activity (who used the tool, where it ran, process ancestry, command context, and follow-on behavior), highlights potential business impacts (persistence, lateral movement, ransomware, BEC), and recommends improved visibility, stricter controls, and logging to detect and prevent such abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
