Skip to content
Cyber Defense Technologies

Threat Intelligence

Living off the Land: How Attackers Hide Using Your Own Tools

Some of the most capable threat actors bring almost no malware. They use the administration tools already on your systems. How living-off-the-land techniques work, why they evade traditional defenses, and how to detect them.

By Cyber Defense Technologies October 21, 2025 4 min read

Traditional security tools were built to find malicious files: viruses, trojans and other malware with recognizable signatures. Many modern attackers have adapted by avoiding malware almost entirely. Instead, they use the tools that administrators rely on every day. Security practitioners call this "living off the land" (LOTL).

When an attacker runs PowerShell, queries systems with Windows Management Instrumentation (WMI), or configures a port proxy with netsh, their activity can look almost identical to legitimate administration. No malicious file is written to disk. Antivirus has nothing to detect.

The same tools, two purposes

How administrators use them

Everyday operations

  • PowerShell and WMI to manage systems
  • netsh to configure networking
  • ntdsutil to maintain Active Directory
  • Remote desktop and remote management for support

How attackers abuse them

Living off the land

  • Running commands without dropping malware
  • Proxying traffic through compromised hosts
  • Copying the Active Directory database to steal credentials
  • Moving laterally with legitimate credentials
Examples drawn from public advisories on Volt Typhoon and related activity.

Why attackers live off the land

  • Stealth. Built-in tools are expected on systems, and their use generates little suspicion.
  • Availability. The tools are already installed; attackers do not need to bring or hide their own.
  • Evasion. Signature-based defenses are designed to detect malicious files, not legitimate tools used for malicious purposes.
  • Persistence. Access maintained with valid accounts and native tools can survive for long periods without discovery.

What public advisories describe

In February 2024, CISA, NSA and FBI published advisory AA24-038A describing PRC state-sponsored actors, known as Volt Typhoon, compromising U.S. critical infrastructure organizations and maintaining access for extended periods. The advisory emphasized the actors' heavy reliance on living-off-the-land techniques. Examples described in public reporting on this activity include:

  • using built-in command-line tools for discovery of systems, users and network configuration
  • extracting the Active Directory database with ntdsutil to obtain credentials
  • configuring port proxies with netsh to route traffic through compromised systems
  • using valid credentials and remote management features to move between systems
  • clearing event logs to cover their tracks

The same agencies, with international partners, released joint guidance on identifying and mitigating living-off-the-land techniques, recognizing that these methods are used widely beyond any single actor.

Why detection is hard

LOTL activity sits inside normal administrative noise. A single PowerShell command, remote session or WMI query means little on its own. Detection requires:

  • Visibility: detailed logging of process creation, command lines, PowerShell script content, authentication and network activity
  • Context: knowledge of who normally performs administrative tasks, from which systems, at what times, and with which tools
  • Correlation: connecting events across systems to see a sequence that indicates intrusion

Building defenses

Log what matters

Enable and centralize:

  • process creation events with full command lines
  • PowerShell script block and module logging
  • authentication events, including remote and service logons
  • WMI activity where possible
  • network flow data for internal traffic

Protect the logs from tampering, and retain them long enough for investigations of long-dwell intrusions.

Establish baselines

Document normal administrative behavior: which accounts administer which systems, from which workstations, with which tools. Deviations become detection opportunities. For example, domain administrator logons from a standard user workstation, or netsh port proxy configuration on a server that has never needed it, deserve attention.

Restrict administrative tools

Not every user needs every tool. Application control policies can restrict scripting engines and administrative utilities to the people and systems that need them. Constrained language modes and just-in-time administration reduce opportunities further.

Harden identity

Because LOTL attackers depend on valid credentials, identity is central to defense:

  • phishing-resistant multifactor authentication for administrators
  • dedicated, hardened administrative workstations
  • tiered administration, so domain administrator credentials are never exposed on ordinary systems
  • monitoring for unusual use of privileged accounts

Hunt proactively

Because LOTL activity rarely triggers alerts on its own, organizations facing capable adversaries should hunt for it: forming hypotheses based on published techniques and searching logs for evidence. The published advisories include specific behaviors to hunt for.

Frequently asked questions

Can we just block PowerShell? Removing or blocking administrative tools entirely usually breaks legitimate operations. Restricting them to authorized users and systems, logging their use thoroughly and alerting on unusual patterns is more practical and effective.

Does endpoint detection and response (EDR) solve this? EDR tools that analyze behavior are much better at spotting LOTL activity than signature-based antivirus, but they still need tuning to your environment, and attackers actively try to evade or disable them. EDR is necessary, not sufficient.

How would we know if we were already compromised? A focused threat hunt using the behaviors described in public advisories is the best way to find out. Look especially at domain controllers, edge devices and systems with administrative access.

What to do this week

  • Confirm process creation logging with command lines is enabled on servers and domain controllers.
  • Enable PowerShell script block logging.
  • Search for netsh port proxy configurations and ntdsutil use on systems where they are not expected.
  • Review which accounts can log on to domain controllers.

How CDT can help

CDT's cyber hunt team searches for living-off-the-land activity using techniques drawn from real adversary behavior, and our managed security services build the logging and detections needed to catch it. Purple team exercises test whether your defenses detect these techniques today.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.