Skip Navigation
Get a Demo
 
 
 
 
 
 
 
 
 
Resources Videos
Security operations

SecOps Weekly: Episode 72 – LOLBins & LOLBAS – Off the land, under the radar

SecOps Weekly | 07.14.26

LOLBins & LOLBAS – Off the land, under the radar

MagicSword’s Jose Hernandez and Mike Haag break down how adversaries hijack built-in system tools like LOLBins and LOLBAS to execute attacks, evade detection, and blend in with normal operations.

SHOW NOTES

Attackers don’t always bring their own toolkit — sometimes they use yours. In this episode of SecOps Weekly, Senior Malware Analyst Tony Lambert is joined by Jose Hernandez and Michael Haag from MagicSword to break down Living Off the Land (LOtL) techniques and how adversaries weaponize legitimate system binaries and other native things to stay hidden inside your environment.

TIMESTAMPS

  • 00:00: Welcome to SecOps Weekly!
  • 03:44: What is Living Off the Land (LOtL)?
  • 07:39: LOLOL Farm & LOLBAS projects
  • 12:02: LOLCerts & certificate abuse
  • 22:23: Why do LOtL things matter?
  • 23:15: Detection strategies & insights
  • 29:00: Deception deployment
  • 29:43: Mac & Linux challenges

Security gaps? We got you.

Sign up for our monthly email newsletter for expert insights on MDR, threat intel, and security ops—straight to your inbox.


 
 
Back to Top