By Cyber Defense Technologies October 21, 2025 4 min read
Traditional security tools were built to find malicious files: viruses, trojans and other malware with recognizable signatures. Many modern attackers have adapted by avoiding malware almost entirely. Instead, they use the tools that administrators rely on every day. Security practitioners call this "living off the land" (LOTL).
When an attacker runs PowerShell, queries systems with Windows Management Instrumentation (WMI), or configures a port proxy with netsh, their activity can look almost identical to legitimate administration. No malicious file is written to disk. Antivirus has nothing to detect.
The same tools, two purposes
How administrators use them
Everyday operations
- PowerShell and WMI to manage systems
- netsh to configure networking
- ntdsutil to maintain Active Directory
- Remote desktop and remote management for support
How attackers abuse them
Living off the land
- Running commands without dropping malware
- Proxying traffic through compromised hosts
- Copying the Active Directory database to steal credentials
- Moving laterally with legitimate credentials
Why attackers live off the land
- Stealth. Built-in tools are expected on systems, and their use generates little suspicion.
- Availability. The tools are already installed; attackers do not need to bring or hide their own.
- Evasion. Signature-based defenses are designed to detect malicious files, not legitimate tools used for malicious purposes.
- Persistence. Access maintained with valid accounts and native tools can survive for long periods without discovery.
What public advisories describe
In February 2024, CISA, NSA and FBI published advisory AA24-038A describing PRC state-sponsored actors, known as Volt Typhoon, compromising U.S. critical infrastructure organizations and maintaining access for extended periods. The advisory emphasized the actors' heavy reliance on living-off-the-land techniques. Examples described in public reporting on this activity include:
- using built-in command-line tools for discovery of systems, users and network configuration
- extracting the Active Directory database with ntdsutil to obtain credentials
- configuring port proxies with netsh to route traffic through compromised systems
- using valid credentials and remote management features to move between systems
- clearing event logs to cover their tracks
The same agencies, with international partners, released joint guidance on identifying and mitigating living-off-the-land techniques, recognizing that these methods are used widely beyond any single actor.
Why detection is hard
LOTL activity sits inside normal administrative noise. A single PowerShell command, remote session or WMI query means little on its own. Detection requires:
- Visibility: detailed logging of process creation, command lines, PowerShell script content, authentication and network activity
- Context: knowledge of who normally performs administrative tasks, from which systems, at what times, and with which tools
- Correlation: connecting events across systems to see a sequence that indicates intrusion
Building defenses
Log what matters
Enable and centralize:
- process creation events with full command lines
- PowerShell script block and module logging
- authentication events, including remote and service logons
- WMI activity where possible
- network flow data for internal traffic
Protect the logs from tampering, and retain them long enough for investigations of long-dwell intrusions.
Establish baselines
Document normal administrative behavior: which accounts administer which systems, from which workstations, with which tools. Deviations become detection opportunities. For example, domain administrator logons from a standard user workstation, or netsh port proxy configuration on a server that has never needed it, deserve attention.
Restrict administrative tools
Not every user needs every tool. Application control policies can restrict scripting engines and administrative utilities to the people and systems that need them. Constrained language modes and just-in-time administration reduce opportunities further.
Harden identity
Because LOTL attackers depend on valid credentials, identity is central to defense:
- phishing-resistant multifactor authentication for administrators
- dedicated, hardened administrative workstations
- tiered administration, so domain administrator credentials are never exposed on ordinary systems
- monitoring for unusual use of privileged accounts
Hunt proactively
Because LOTL activity rarely triggers alerts on its own, organizations facing capable adversaries should hunt for it: forming hypotheses based on published techniques and searching logs for evidence. The published advisories include specific behaviors to hunt for.
Frequently asked questions
Can we just block PowerShell? Removing or blocking administrative tools entirely usually breaks legitimate operations. Restricting them to authorized users and systems, logging their use thoroughly and alerting on unusual patterns is more practical and effective.
Does endpoint detection and response (EDR) solve this? EDR tools that analyze behavior are much better at spotting LOTL activity than signature-based antivirus, but they still need tuning to your environment, and attackers actively try to evade or disable them. EDR is necessary, not sufficient.
How would we know if we were already compromised? A focused threat hunt using the behaviors described in public advisories is the best way to find out. Look especially at domain controllers, edge devices and systems with administrative access.
What to do this week
- Confirm process creation logging with command lines is enabled on servers and domain controllers.
- Enable PowerShell script block logging.
- Search for netsh port proxy configurations and ntdsutil use on systems where they are not expected.
- Review which accounts can log on to domain controllers.
How CDT can help
CDT's cyber hunt team searches for living-off-the-land activity using techniques drawn from real adversary behavior, and our managed security services build the logging and detections needed to catch it. Purple team exercises test whether your defenses detect these techniques today.