logo

Threat Actors Living Off the Land

ID: 52a81be3-6f39-5dff-94a5-a5d6b59917dc

STIX ID: report--52a81be3-6f39-5dff-94a5-a5d6b59917dc

Feed Name: ReliaQuest Blog

Date Published: 2021-06-23

Date Updated: 2026-04-29

...
...

This blog post describes how modern adversaries leverage scanners, legitimate system tools (PowerShell, bash), and commercial/off-the-shelf offensive frameworks (Mimikatz, Metasploit, Cobalt Strike) to evade detection and persist in environments; it emphasizes the challenges defenders face, outlines common attacker behaviors (e.g., scheduled tasks, registry modification, credential dumping), and recommends mitigations such as patching, service hardening, threat hunting, and blocking known bad infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.