Episode 72: LOLBins & LOLBAS
SHOW NOTES
Attackers don’t always bring their own toolkit — sometimes they use yours. In this episode of SecOps Weekly, Senior Malware Analyst Tony Lambert is joined by Jose Hernandez and Michael Haag from MagicSword to break down Living Off the Land (LOtL) techniques and how adversaries weaponize legitimate system binaries and other native things to stay hidden inside your environment.
TIMESTAMPS
- 00:00: Welcome to SecOps Weekly!
- 03:44: What is Living Off the Land (LOtL)?
- 07:39: LOLOL Farm & LOLBAS projects
- 12:02: LOLCerts & certificate abuse
- 22:23: Why do LOtL things matter?
- 23:15: Detection strategies & insights
- 29:00: Deception deployment
- 29:43: Mac & Linux challenges