Glossary
Living off the Land
Instead of bringing weapons, attackers use tools already in your house - PowerShell, WMI, cmd. Security tools expect malware, not built-in Windows features being misused. Very hard to detect.
What is Living off the Land?
Attack technique using legitimate, pre-installed system tools instead of malware to avoid detection.
Why Should You Care?
Living off the Land attacks are extremely difficult to detect because defenders rarely monitor or alert on legitimate administrative tools being misused for malicious purposes. Attackers blend in with normal system administration and automation, extending dwell time before discovery. This means your traditional EDR and antivirus defenses may completely miss the attack while the attacker moves laterally, escalates privileges, and exfiltrates data. Security teams must specifically hunt for suspicious uses of these tools rather than relying on signature-based detection.
Is your business exposed?
Real-World Example
An attacker who gains initial access via compromised credentials then uses native Windows PowerShell and built-in administration utilities to enumerate the network, disable security tooling, and move laterally to sensitive systems. Because these activities appear as legitimate administrative work in logs, the intrusion can go undetected until much later—often surfacing only when a backup fails or anomalous network flows are investigated. This pattern recurs across intrusion campaigns targeting industries like financial services and healthcare.
How to Protect Against Living off the Land
- 1.
Enable PowerShell script block logging
- 2.
Monitor legitimate tool usage for anomalies
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required