Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

LOLBins: How Attackers Abuse Trusted OS Tools

Huntress
07/30/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


It lets them compromise your environment without dropping a single piece of malware. My name is Austin Wehrlein, I'm a security operations analyst here in the Huntress SOC. So what exactly are living off the LAN binaries? They're a trusted part of your digital environment, legitimate pre-installed operating system executables like cmd.exe, msbuild.exe, and etc. Attackers love to abuse LUL Bins because this lets them disable defenses, persist within your network, and move through your environment undetected without installing malware. Because the attacker's sketchy behavior looks like it's coming from real system processes, it blends into the noise IT teams are expecting right under the radar. You might be thinking, why not just block or disable LUL Bins since they would make things harder for attackers? Well, they're used by IT teams for many day-to-day tasks, so it would be a nightmare for businesses that rely on these components and also may trigger unnecessary alerts. So, how do attackers pull off attacks by abusing LUL Bins? It turns out, they're used in many parts of the attack path, giving cybercriminals plenty of chances to wreck your systems without being detected. Let's look at a few LUL Bin abuse techniques from our SOC. Command and Control. Attackers abuse LUL Bins to run their own malicious infrastructure in your networks or download additional payloads and transfer malicious tools with PowerShell, CertRetail, and many more. Execution. Attackers run fileless malicious code or commands in LUL Bins to help them do this. These fileless attacks can often go unnoticed since they look like normal sysadmin activity. Credential access. Attackers need credential access to escalate privileges and move laterally. By abusing LUL Bins like reg.exe and PowerShell, attackers can access these safe credentials and password hashes in your network. Impact. Impact is different in every cyber attack depending on the attacker's goals. In this example, let's use ransomware. Here, the goal is for attackers to collect a ransom payment after misusing LUL Bins to encrypt data, disrupt operations, or steal valuable information. Let's go over a few of these LUL Bin abuses. For example, VSSAdmin, which can be used to delete local backups. VCDedit, which can be used to disable recovery efforts. And lastly, PowerShell to clear event logs which will hide the attacker's tracks. Summing it all up, LUL Bins are native executables abused by threat actors to get stealthy access to targeted environments without using malware. LUL Bin abuse easily avoids antivirus detection since it's a legitimate built-in program and executes fileless attacks. This technique can be used in multiple stages of the attack path, increasing opportunities for attackers to slip through the cracks. Behavior-based detection is critical for spotting suspicious LUL Bin activity in your environment, knowing how trusted tools are abused by attackers, and detecting them when they're acting shady in your network. Thinking like an attacker has never been more important. Thanks for watching our quick overview on how attackers take advantage of living off the LAN binaries.

TL;DR

  • LOLBins are legitimate OS executables like PowerShell and cmd.exe that attackers abuse to compromise systems without ever dropping traditional malware.
  • Blocking LOLBins entirely is impractical because IT teams depend on them daily, making behavior-based detection the only viable defense strategy.
  • LOLBin abuse spans the full attack chain — from command-and-control and fileless execution to credential theft, backup deletion, and ransomware deployment.

Summary

Living off the Land Binaries — LOLBins — are legitimate, pre-installed operating system executables such as PowerShell, cmd.exe, certutil.exe, reg.exe, VSSAdmin, and BCDedit that threat actors weaponize to compromise environments without deploying traditional malware. Because these tools are integral to everyday IT operations, blocking them outright would cripple normal business workflows and generate excessive false-positive alerts, making them an ideal cover for attackers. Huntress SOC Analyst Austin Worline explains how LOLBin abuse spans the full attack chain: attackers use them for command-and-control communication and payload delivery, fileless code execution that mimics routine sysadmin activity, credential access to harvest password hashes and escalate privileges, and ransomware-stage impact actions like deleting local backups, disabling recovery options, and clearing event logs to erase forensic evidence. Because malicious activity originates from trusted system processes, it blends seamlessly into expected network noise and evades signature-based antivirus detection. The only reliable countermeasure is behavior-based detection — monitoring how these tools are being used, not just whether they are present — combined with an attacker-minded approach to identifying anomalous patterns before damage is done.

Chapters

0:00 - What Are LOLBins?
0:40 - Why Blocking Isn't the Answer
0:54 - LOLBin Abuse Across the Attack Path
2:07 - Detection and Key Takeaways

Key Quotes

0:05 "It lets them compromise your environment without dropping a single piece of malware."
0:33 "Because the attacker's sketchy behavior looks like it's coming from real system processes, it blends into the noise IT teams are expecting right under the radar."
2:14 "LOLBin abuse easily avoids antivirus detection since it's a legitimate built-in program and executes fileless attacks."
2:26 "Behavior-based detection is critical for spotting suspicious LOLBin activity in your environment, knowing how trusted tools are abused by attackers, and detecting them when they're acting shady in your network."

FAQ

Why can't organizations simply block or disable LOLBins to stop these attacks?

LOLBins like PowerShell and cmd.exe are essential to daily IT operations. Blocking them would disrupt legitimate business workflows and generate a flood of unnecessary alerts, making the cure worse than the disease. The practical answer is behavior-based detection rather than blanket blocking.

At what stages of an attack are LOLBins typically abused?

LOLBins appear across multiple attack phases: command-and-control (downloading payloads via PowerShell or certutil), execution (running fileless malicious code), credential access (harvesting password hashes via reg.exe), and impact (deleting backups with VSSAdmin, disabling recovery with BCDedit, and clearing event logs with PowerShell).

Categories:
  • » Webinar Library » Huntress
  • » Cybersecurity » Endpoint Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Security Operations
  • Endpoint Management
  • Getting Started
  • How-To
  • Living off the Land Binaries
  • LOLBins
  • Fileless attacks
  • PowerShell abuse
  • Behavior-based detection
  • Credential access techniques
  • Ransomware tactics
  • Command and control
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: LOLBins: How Attackers Abuse Trusted OS Tools

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version