logo

LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress

ID: db5a4365-8f7c-5497-ba37-8c93f44f245a

STIX ID: report--db5a4365-8f7c-5497-ba37-8c93f44f245a

Feed Name: Huntress Blog

Date Published: 2026-07-08

Date Updated: 2026-07-19

...
...

**Executive summary:** This article explains living-off-the-land (LoTL) abuse—where attackers use legitimate administrative tools (PowerShell, WMI, RMM, built-in accounts) to evade detection—details behavioral indicators to distinguish malicious from routine admin activity (who used the tool, where it ran, process ancestry, command context, and follow-on behavior), highlights potential business impacts (persistence, lateral movement, ransomware, BEC), and recommends improved visibility, stricter controls, and logging to detect and prevent such abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.