What does living off the land mean?¶
Living off the land means using legitimate tools and features already available in an environment to carry out unauthorised activity. Instead of introducing a distinctive malicious program, an offender may use command shells, scripting engines, system utilities, cloud consoles or management tools.
No new malware file is required, but the activity can still leave evidence in commands, process relationships, accounts and resulting changes.
Legitimate components can perform harmful actions¶
Administrators routinely use the same components for support, deployment and diagnostics. Their names or signatures therefore say little about purpose on their own. What matters is the way they were used: the command, source session, target, timing, permissions and effect.
For example, a built-in archive tool may be routine when packaging logs for support. The same tool run by an unusual account immediately before a large outbound transfer may form part of a materially different sequence.
Living-off-the-land activity may include:
- interpreters running scripts or encoded commands;
- administrative utilities changing accounts or security settings;
- scheduled tasks or services creating persistence;
- remote services moving between systems; and
- cloud or endpoint-management features collecting or deploying data.
Behavioural records become more important¶
Signed binaries and standard services may not trigger file-reputation alerts. Preserve process lineage, command-line arguments, scripts, shell history, scheduled jobs and management-platform records before short retention periods or later remediation remove them.
The absence of a new executable is not evidence that nothing happened. Equally, the presence of a powerful system utility is not proof of malicious intent. A defensible conclusion comes from the surrounding sequence and authorisation evidence.
Key takeaway
Assess what a legitimate component did, who or what invoked it, and what followed; neither an approved tool nor the absence of malware determines whether the activity was authorised.